Ransomware group

Kawa4096 ransomware: victims and leak site activity

The Kawa4096 ransomware group has listed 17 victims on its leak site since June 2025; its latest post is from 29 July 2025. Most affected countries: United States, Japan and Germany. Most targeted sector: Healthcare.

Total posts 17
First seen 2025-06-27
Latest post 2025-07-29
Countries hit 3

About Kawa4096

Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.

Also known as
KaWaLocker
Leak site (Tor)
http://kawasa2qo7345dt7ogxmx7qmn6z2hnwaoi3h5aeosupozkddqwp6lqqd.onion

Kawa4096 victims per year

17 2025

All 17 victims

Search every post in the full table.
Victim Country Sector Discovered
********.org United States
**********.net United States
**********.com United States
icmconv.com United States Technology
carestlhealth.org United States Healthcare
sbamh.org United States Healthcare
gatewaycsb.org United States Government & Defense
heimhaus.de Germany Retail & E-Commerce
tokiomarine-nichido.co.jp Japan Financial Services
www.ogr-jp.com Japan Other
www.malonebailey.com United States Financial Services
**********-*******.co.jp Japan
*************.org
Morningsideservices United States Healthcare
******.de Germany
******.com United States
******.org United States