Ransomware group
Threeam ransomware: victims and leak site activity
The Threeam ransomware group has listed 91 victims on its leak site since September 2023; its latest post is from 30 August 2026. Most affected countries: United States, United Kingdom and Australia. Most targeted sector: Professional Services.
About Threeam
A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.
>
> The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim. Source: https://github.com/crocodyli/ThreatActors-TTPs
- Also known as
- 3Am
- Leak site (Tor)
- http://threeamkelxicjsaf2czjyz2lc4q3ngqkxhhlexyfcp2o6raw4rphyad.onion/show-posts
Most targeted countries
- United States 38
- United Kingdom 6
- Australia 5
- Germany 5
- Mexico 4
- Brazil 3
- Argentina 2
- France 2
- Belgium 1
- Canada 1
Most targeted sectors
- Professional Services 19
- Healthcare 17
- Manufacturing 17
- Agriculture and Food Production 9
- Technology 7
- Government & Defense 4
- Hospitality 3
- Retail & E-Commerce 3
- Transportation 3
- Education 2