Ransomware group

Cephalus ransomware: victims and leak site activity

The Cephalus ransomware group has listed 19 victims on its leak site since August 2025; its latest post is from 29 August 2025. Most affected countries: United States, United Kingdom and Ireland. Most targeted sector: Professional Services.

Total posts 19
First seen 2025-08-26
Latest post 2025-08-29
Countries hit 5

About Cephalus

Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.

Leak site
http://46.17.42.64

Cephalus victims per year

19 2025

All 19 victims

Search every post in the full table.
Victim Country Sector Discovered
One-LUX United Kingdom Retail & E-Commerce
Shropdoc United Kingdom Healthcare
Shelbourne Accountants Ireland Financial Services
Delta Information Systems United States Technology
Colorado Health Network Inc United States Healthcare
Texas Pregnancy Care Network United States Healthcare
wilderlawfirm United States Professional Services
CoCo Yachts Netherlands Manufacturing
txpregnancy.org - Fake Abortion Clinics Exposed United States Healthcare
Town of Vienna, VA United States Government & Defense
Lewis Baach Kaufmann Middlemiss PLLC United States Professional Services
Lee & Associates United States Professional Services
Sherman, Silverstein, Kohl, Rose & Podolsky, P.A. United States Professional Services
Guerrero Mears LLP United States Professional Services
LPL Financial United States Financial Services
K Strategies Marketing and Public Relations United States Professional Services
BAR Architects & Interiors Professional Services
SystemExec Co., Ltd. Japan Technology
CareSTL Health United States Healthcare