Ransomware group
Sinobi ransomware: victims and leak site activity
The Sinobi ransomware group has listed 274 victims on its leak site since July 2025; its latest post is from 8 May 2026. Most affected countries: United States, India and United Kingdom. Most targeted sector: Manufacturing.
Total posts
274
First seen
2025-07-05
Latest post
2026-05-08
Countries hit
26
About Sinobi
Sinobi is a private vetted-affiliate RaaS group that emerged in mid-2025, believed to be a rebrand of the Lynx/INC ransomware lineage, claiming 176 victims by end of 2025 through double-extortion attacks primarily against mid-market US organizations via compromised SonicWall VPN credentials.
Most targeted countries
- United States 205
- India 12
- United Kingdom 10
- Canada 7
- Italy 5
- Spain 3
- France 3
- China 2
- Denmark 2
- Argentina 1
Most targeted sectors
- Manufacturing 65
- Professional Services 47
- Healthcare 38
- Technology 32
- Retail & E-Commerce 24
- Financial Services 15
- Hospitality 10
- Agriculture and Food Production 9
- Education 8
- Energy & Utilities 8