About
Written by ThreatCluster from 47 storiesConti is a ransomware group that operates an extortion-based model, pairing encryption with publicized data leaks and using leaked internal communications as leverage, including a 2022 leak of more than 300,000 internal messages. Victims include more than 1,000 attacks worldwide, extorting over $150 million, with targets spanning government and critical infrastructure, notably a Costa Rica government operation and reports of local councils and organizations targeted globally. A recurring pattern across the reporting is that internal disputes and public leaks have not halted operations; for example, in August 2026 Conti launched a massive attack on Costa Rica amidst Ukraine-related internal conflict.
Recent victims
View all →No recent victims.