Skip to content

benzona

Inactive

13 tracked victims · First seen Nov 26, 2025 · Last seen Jan 30, 2026

About

Aggregated threat-intel description

Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.

Sectors: Healthcare, Manufacturing, Hospitality and Tourism · Countries: RO, FR, GT

Recent victims

View all →
VictimSectorCountryPostedStatus
casamedica.com.gtHealthcareGTJan 30, 2026
empreinte-hotel.comHospitality and TourismFRJan 22, 2026
*a*ame*i*a.com.g*Not FoundJan 22, 2026
ccbrt.orgHealthcareTZJan 17, 2026
em***int*-ho***.comNot FoundJan 17, 2026
taminsho.comNot FoundIRDec 22, 2025
platinumone.inTechnologyINDec 6, 2025
SUNNYGO.COM.TWNot FoundTWDec 3, 2025
suzuki-ploiesti.roManufacturingRONov 26, 2025
poliserv.roNot FoundRONov 26, 2025
mazda-ploiesti.roManufacturingRONov 26, 2025
dacia-ploiesti.roNot FoundRONov 26, 2025
sevci.orgNot FoundCINov 26, 2025

All ransomware groups · Dark web intelligence