Ransomware group

ShadowByt3$ ransomware: victims and leak site activity

The ShadowByt3$ ransomware group has listed 19 victims on its leak site since February 2026; its latest post is from 10 September 2026. Most affected countries: United States, United Kingdom and India. Most targeted sector: Education.

Total posts 19
First seen 2026-02-25
Latest post 2026-09-10
Countries hit 7

About ShadowByt3$

ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

Leak site (Tor)
http://sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onion

ShadowByt3$ victims per year

19 2026

All 19 victims

Search every post in the full table.
Victim Country Sector Discovered
John Engel Team United States Professional Services
Ben Leeds Properties United Kingdom Other
BayView Real Estate United States Retail & E-Commerce
Bayview Real Estate WARNING United States Retail & E-Commerce
Sinar Mas Agribusiness and Food Golden Agri-Resources) Indonesia Agriculture and Food Production
A-Plus Software Limited United Kingdom Technology
Knottingham Trent University United Kingdom Education
TINYpulse NINTENDO BREACH Japan Technology
Nintendo Company Japan Technology
Lead Company (Leadership Boulevard) Professional Services
Cropwise (Syngenta Group) Switzerland Agriculture and Food Production
Hotelogix Company India Hospitality
StarBucks Company United States Hospitality
PowerCampus India Education
Stride Learning United States Education
Amplify Technology United Kingdom Technology
University Of Georgia United States Education
Hotelogix Singapore Hospitality
UMSA Education