Ransomware group
Embargo ransomware: victims and leak site activity
The Embargo ransomware group has listed 41 victims on its leak site since April 2024; its latest post is from 9 September 2026. Most affected countries: United States, Singapore and Australia. Most targeted sector: Technology.
Total posts
41
First seen
2024-04-21
Latest post
2026-09-09
Countries hit
14
About Embargo
Embargo is a Rust-based ransomware-as-a-service group that emerged in April 2024, primarily targeting US healthcare, manufacturing, and business services organizations using double extortion, assessed as a potential successor to BlackCat/ALPHV with over $34 million in ransom proceeds.
Most targeted countries
- United States 26
- Singapore 2
- Australia 1
- Brazil 1
- Germany 1
- France 1
- United Kingdom 1
- Hungary 1
- India 1
- Jordan 1
Most targeted sectors
- Technology 11
- Healthcare 7
- Manufacturing 5
- Professional Services 5
- Financial Services 3
- Transportation 3
- Government & Defense 2
- Hospitality 2
- Agriculture and Food Production 1
- Energy & Utilities 1