Skip to content
Leak site of bravox, captured by ThreatCluster

bravox

Active

25 tracked victims · First seen May 15, 2025 · Last seen Sep 20, 2026

About

Aggregated threat-intel description

BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the RAMP underground forum, targeting primarily US-based organizations in healthcare and retail while applying strict affiliate vetting requirements including proof of access or a financial deposit.

Sectors: Technology, Healthcare, Agriculture and Food Production · Countries: US, CH, CA

Recent victims

View all →
VictimSectorCountryPostedStatus
TOWILLTechnologyUSSep 20, 2026
SCHMIDTNot FoundUSSep 1, 2026
MooresRetail & E-CommerceGBAug 17, 2026
Elettrica SystemEnergy & UtilitiesITAug 10, 2026
Verona 83Not FoundITAug 10, 2026
MEDICOSHealthcareFRAug 7, 2026
MITC AGOtherCHAug 6, 2026
A&A SafetyOtherUSJul 25, 2026
PB Fiduciaire SAFinancial ServicesCHJul 7, 2026
MetaTechnologyBRJun 23, 2026
SELECT WINESAgriculture and Food ProductionCAJun 18, 2026
CCS GLOBAL TECHTechnologyUSJun 12, 2026
Grupo MauáManufacturingBRMay 31, 2026
AcademyHealthHealthcareUSMay 29, 2026
Emek ElektrikEnergyTRMay 23, 2026
Salvation ArmyConsumer ServicesCAMay 23, 2026
Rivadeneyra TreviñoNot FoundMXMay 12, 2026
AculabTechnologyGBApr 6, 2026
UMBERG TREUHAND AGNot FoundCHMar 11, 2026
SorecoNot FoundCHMar 2, 2026
OEC BretagneNot FoundFRFeb 16, 2026
Hood River DentalHealthcareUSFeb 11, 2026
WVPCANot FoundUSFeb 11, 2026
SPECNot FoundUSFeb 11, 2026
FUSION HILLNot FoundUSFeb 11, 2026

All ransomware groups · Dark web intelligence