Arkana

Dark since June 9, 2025
6 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Mar 2025 first victim we recorded
Jun 9, 2025 most recent victim posted
2 leak sites tracked

Data as of August 16, 2026.

What industries Arkana targets

Sector identified for 1 of 6 victims.

Technology1

Where the victims are located

Country identified for 1 of 6 victims.

United States1

Every Arkana victim

VictimSectorCountryPosted
Synopsys synopsys.comTechnologyNot identifiedJun 9, 2025
Ticketmaster ticketmaster.comNot identifiedNot identifiedJun 9, 2025
INFINOX infinox.comNot identifiedNot identifiedMay 29, 2025
Anglo American angloamerican.comNot identifiedUnited StatesMay 22, 2025
Oregon Surveillance Network oregonsurveillancenetwork.comNot identifiedNot identifiedMar 27, 2025
WOW! Internet wowway.comNot identifiedNot identifiedMar 26, 2025

Browse recent data breaches for more.

Arkana leak sites

Addresses we've seen Arkana publish victims from. Any .onion address needs the Tor Browser.

  • arkanabb66ee4nsdji6la2bu6bwqe3dbtsyf3rxrv6vhiehod7utagad.onion
  • ransomwvbabemdnwl7lzgeenyfmmhskaed6jcruwhkvapsia76vttzyd.onion

Arkana questions

Is Arkana still active?

Not for over a year. The last victim we recorded was June 9, 2025. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has Arkana claimed?

Arkana has named 6 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Arkana first appear?

The first victim we recorded for Arkana was posted on March 26, 2025. That's when the group entered our collection, which isn't necessarily when it started operating.

Has Arkana already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.