Skip to content
Leak site of blackout, captured by ThreatCluster

blackout

Active

12 tracked victims · First seen Feb 26, 2024 · Last seen Jul 19, 2026

About

Aggregated threat-intel description

Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.

Sectors: Healthcare, Technology, Business Services · Countries: GR, FR, GB

Recent victims

View all →
VictimSectorCountryPostedStatus
yano.tokyoTechnologyJPJun 1, 2024published
www.miatech.netTechnologyUSJul 19, 2026
bluebellgroup.comProfessional ServicesHong KongJun 1, 2024listed
nedamaritime.grTransportation/LogisticsGRDec 10, 2024
cdc-biodiversite.frGovernmentFRSep 29, 2024
antaeustravel.comHospitality and TourismGRAug 22, 2024
luzan5.comNot FoundJul 14, 2024
badel1862.hrBusiness ServicesHRJul 3, 2024
mcmtelecom.comBusiness ServicesMay 29, 2024
ht-hospitaltechnik.deHealthcareDEApr 18, 2024
ch-armentieres.frHealthcareFRFeb 26, 2024
metal7.comManufacturingCAFeb 26, 2024

All ransomware groups · Dark web intelligence