Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us
Search v2
before

Prefix a filter with + to require it, or - to exclude it — e.g. +country:us only shows US victims, -country:us hides them. Mix several with free-text words; everything is combined with AND (so hospital +country:us -group:lockbit3 means: text "hospital", country is US, group is not lockbit3). Repeating + on the same field is OR'd together (+country:us +country:ca → US or Canada); repeating - excludes all of them. Wrap multi-word values in quotes, e.g. +sector:"public sector". infostealer and press take a bare +/- with no value: +infostealer / -infostealer filter on infostealer data, while +press searches press articles only and -press hides press coverage; before:/after: take a date directly with no +/- prefix, as shown below.

+country:only this country — opens a picker
-country:exclude this country — opens a picker
+group:lockbit3only this group
-group:lockbit3exclude this group
+website:example.comonly this website
+sector:only this sector — opens a picker
-sector:exclude this sector — opens a picker
+infostealerhas infostealer data
-infostealerno infostealer data
+presssearch press articles only
-presshide press coverage
after:2025-01-01discovered/attacked on or after
before:2026-01-01discovered/attacked on or before
2 victims matched
Logo
Discovered: 2026-07-20 (7d ago)
Employee data breach at a major manufacturing company.…
Logo
Discovered: 2024-12-18 (1y ago)  ·  Attack est.: 2024-12-05
Bath Fitter is a company specializing in bathroom remodeling, particularly known for its custom acry…
Press Coverage 1
Bath Fitter Distributing Inc.
2024-12-05

Bath Fitter a été victime d'une cyberattaque entre le 4 et le 5 décembre 2024, au cours de laquelle un acteur malveillant s'est fait passer pour un technicien informatique afin d'infiltrer le réseau, y déployer un ransomware et potentiellement exfiltrer des données. Une notification provisoire a été envoyée aux employés le 26 décembre 2024, et l’enquête, finalisée le 7 mars 2025, a révélé que d’anciens employés pourraient également être concernés. L’entreprise a depuis pris des mesures pour contenir l’incident et informe désormais officiellement toutes les personnes potentiellement touchées. Une telle attaque a été revendiquée le 18 décembre 2024 sous la bannière de Black Basta.

Read article