Skip to content

conti

Inactive

0 tracked victims · First seen Jul 31, 2020 · Last seen Jun 7, 2022

About

Written by ThreatCluster from 47 stories

Conti is a ransomware group that operates an extortion-based model, pairing encryption with publicized data leaks and using leaked internal communications as leverage, including a 2022 leak of more than 300,000 internal messages. Victims include more than 1,000 attacks worldwide, extorting over $150 million, with targets spanning government and critical infrastructure, notably a Costa Rica government operation and reports of local councils and organizations targeted globally. A recurring pattern across the reporting is that internal disputes and public leaks have not halted operations; for example, in August 2026 Conti launched a massive attack on Costa Rica amidst Ukraine-related internal conflict.

Recent victims

View all →
No recent victims.

All ransomware groups · Dark web intelligence