Skip to content

donutleaks

Inactive

14 tracked victims · First seen Aug 24, 2022 · Last seen Jul 24, 2024

About

Aggregated threat-intel description

Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.

Sectors: Technology, Healthcare, Manufacturing · Countries: US, ES, IR

Recent victims

View all →
VictimSectorCountryPostedStatus
Jack "Designer" Sparrow.Not FoundJul 24, 2024
Industrial BolseraManufacturingESJul 24, 2024
KickDown ESET company. No overpayments at 0% (renamed and update)TechnologyJul 21, 2024
ESET. PREMIUM.TechnologyJul 20, 2024
all-mode.comTransportation/LogisticsJul 18, 2024
labline.itHealthcareITJul 17, 2024
valleylandtitleco.com - UPDBusiness ServicesJul 15, 2024
valleylandtitleco.comBusiness ServicesJul 3, 2024
Patriot MachineManufacturingUSMay 19, 2024
Pittsburgh’s Trusted Orthopaedic SurgeonsHealthcareUSMay 17, 2024
Good MorningHospitality and TourismUSApr 5, 2024
voidinteractive.net you are welcome in our chatTechnologyIRMar 14, 2024
Watsonclinic.comHealthcareUSMar 9, 2024
DOD contractors you are welcome in our chat.GovernmentUSFeb 5, 2024

All ransomware groups · Dark web intelligence