Ransomware group
Spacebears ransomware: victims and leak site activity
The Spacebears ransomware group has listed 156 victims on its leak site since April 2024; its latest post is from 5 September 2026. Most affected countries: United States, Italy and Germany. Most targeted sector: Professional Services.
Total posts
156
First seen
2024-04-29
Latest post
2026-09-05
Countries hit
45
About Spacebears
Space Bears is a double-extortion ransomware group that emerged in April 2024, distinguished by a professional "corporate" aesthetic on its leak site, leveraging Phobos RaaS infrastructure and targeting small-to-medium organizations in manufacturing, technology, and healthcare across the US and Europe.
Most targeted countries
- United States 44
- Italy 12
- Germany 9
- Spain 8
- Brazil 7
- Canada 5
- Australia 4
- Switzerland 4
- United Kingdom 4
- India 4
Most targeted sectors
- Professional Services 34
- Technology 28
- Manufacturing 26
- Healthcare 21
- Retail & E-Commerce 14
- Transportation 8
- Agriculture and Food Production 6
- Financial Services 6
- Hospitality 5
- Energy & Utilities 3