Skip to content

hunters

Inactive

25 tracked victims · First seen Sep 9, 2021 · Last seen May 27, 2025

About

Aggregated threat-intel description

In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold, along with its website and older versions developed in Golang and C (although this purchase has only been reported by the actors without concrete evidence). The buyer of this new source code was the group Hunters International, who claimed to have fixed the bugs in the Ransomware Hive that were responsible for preventing file decryption in some cases. The group also stated that file encryption would not be their primary focus; instead, they would use data theft as a method to pressure victims during extortion attempts.

Sectors: Business Services, Manufacturing, Technology · Countries: US, CA, GB

Recent victims

View all →
VictimSectorCountryPostedStatus
WARNINGNot FoundSep 30, 2026
Final statement re PSANot FoundSep 24, 2026
Fresenius Medical CareHealthcareDESep 22, 2026
PSA - READ THIS NOWNot FoundSep 22, 2026
Note to Cl0p-_-Not FoundSep 20, 2026
Qi****Not FoundSep 17, 2026
Kimberly-ClarkManufacturingUSSep 13, 2026
State of Florida DMVGovernment & DefenseUSSep 7, 2026
Medela.comHealthcareCHSep 7, 2026
Neogen CorporationAgriculture and Food ProductionUSAug 29, 2026
McKesson CorporationHealthcareUSAug 28, 2026
Elekta ABHealthcareSEAug 28, 2026
Jack Henry & AssociatesFinancial ServicesUSAug 28, 2026
CyrusOne, LLC.TechnologyUSAug 23, 2026
ReliaQuest, LLCTechnologyUSAug 23, 2026
NovoCure LimitedHealthcareILAug 22, 2026
BOK FinancialFinancial ServicesUSAug 22, 2026
Cyrus******TechnologyAug 20, 2026
Logitech/ StreamlabsTechnologyCHAug 18, 2026
MetabaseTechnologyUSAug 14, 2026
Sharecare, Inc.HealthcareUSAug 14, 2026
Carhartt, Inc.Retail & E-CommerceUSAug 14, 2026
Cook Medical LLCHealthcareUSAug 14, 2026
Baxter International, Inc.HealthcareUSAug 14, 2026
Ali** **********TechnologyAug 9, 2026

All ransomware groups · Dark web intelligence