Ransomware group
Warlock ransomware: victims and leak site activity
The Warlock ransomware group has listed 78 victims on its leak site since June 2025; its latest post is from 6 November 2025. Most affected countries: United States, United Kingdom and Japan. Most targeted sector: Technology.
About Warlock
The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta. Both are RaaS and have a long list of known and unknown affiliates. Having said that, this is possibly an affiliate (likely a cybergroup) of both of those groups. The Alliance & Association would technically be Encryptor Sharing, but this is realistically more of an "Old Affiliate" that created their own ransomware encryptor and operation.
Most targeted countries
- United States 15
- United Kingdom 5
- Japan 5
- Russia 5
- Poland 3
- Canada 2
- Denmark 2
- France 2
- India 2
- Netherlands 2
Most targeted sectors
- Technology 29
- Professional Services 7
- Manufacturing 6
- Financial Services 4
- Energy & Utilities 3
- Retail & E-Commerce 3
- Agriculture and Food Production 2
- Government & Defense 2
- Healthcare 2
- Education 1