Ransomware group
Cicada3301 ransomware: victims and leak site activity
The Cicada3301 ransomware group has listed 75 victims on its leak site since June 2024; its latest post is from 4 September 2025. Most affected countries: United States, United Kingdom and Canada. Most targeted sector: Professional Services.
Total posts
75
First seen
2024-06-20
Latest post
2025-09-04
Countries hit
15
About Cicada3301
Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 using Rust-based ransomware targeting Windows, Linux, and ESXi systems, suspected to be a successor of BlackCat/ALPHV and running an affiliate program with 20% commissions.
Most targeted countries
- United States 42
- United Kingdom 6
- Canada 4
- Brazil 3
- Spain 3
- France 3
- Japan 3
- Singapore 3
- Switzerland 2
- United Arab Emirates 1
Most targeted sectors
- Professional Services 30
- Manufacturing 10
- Technology 10
- Hospitality 5
- Healthcare 4
- Retail & E-Commerce 4
- Transportation 4
- Financial Services 3
- Education 2
- Agriculture and Food Production 1