AuditTeam

Active
7 victims named on the leak site
2 in the last 30 days
7 in the last 12 months
Apr 2026 first victim we recorded
Sep 7, 2026 most recent victim posted
2 leak sites tracked

Data as of September 14, 2026.

What industries AuditTeam targets

Sector identified for 6 of 7 victims.

Technology2
Government1
Retail1
Real Estate1
Manufacturing1

Where the victims are located

Country identified for 6 of 7 victims.

Russia2
South Korea1
Philippines1
Turkey1
India1

Every AuditTeam victim

VictimSectorCountryPosted
Mansarovar Group mansarovargroup.netReal EstateIndiaSep 7, 2026
Demidov Steel Group demidovsteel.ruManufacturingRussiaAug 27, 2026
I-SYS i-sys.ruTechnologyRussiaJun 25, 2026
Mopas Online Supermarket mopas.com.trRetailTurkeyMay 25, 2026
Ministry of Finance and Budget finances.gouv.snGovernmentNot identifiedMay 18, 2026
Joy City joycity.comTechnologySouth KoreaApr 8, 2026
Kawasaki Motors Philippines kawasaki.phNot identifiedPhilippinesApr 8, 2026

Browse recent data breaches for more.

AuditTeam leak sites

Addresses we've seen AuditTeam publish victims from. Any .onion address needs the Tor Browser.

  • 6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion
  • cjg2avmzoly7k6mw7xobnyre354jxro4qegkoazhsmigdk2j3aziexyd.onion

AuditTeam questions

Is AuditTeam still active?

Yes. AuditTeam posted its most recent victim on September 7, 2026. That's 2 victims in the last 30 days.

How many victims has AuditTeam claimed?

AuditTeam has named 7 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did AuditTeam first appear?

The first victim we recorded for AuditTeam was posted on April 8, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does AuditTeam target?

Technology accounts for the most victims we can classify, with 2. Government follows at 1. We could identify a sector for 6 of 7 victims, so treat this as the shape of the targeting rather than a full census.

Has AuditTeam already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.