Bashe

Active
108 victims named on the leak site
1 in the last 30 days
58 in the last 12 months
Nov 2024 first victim we recorded
Jul 27, 2026 most recent victim posted
10 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

33.3% of Bashe victims whose domain we can identify (36 of 108) had employee credentials leak in the 12 months before Bashe named them as a victim.

We don't know whether any of these credentials were how Bashe gained initial access.

What industries Bashe targets

Sector identified for 80 of 108 victims.

Financial Services18
Government13
Education8
Technology8
Construction7
Manufacturing7
Retail4
Energy3

Where the victims are located

Country identified for 69 of 108 victims.

United Kingdom5
Indonesia5
France5
Brazil5
Thailand4
India3
United Arab Emirates3
United States3

Most recent Bashe victims

VictimSectorCountryPosted
Metrabyte Cloud metrabyte.cloudNot identifiedThailandJul 27, 2026
Azarestan Business Development Group azarestan.comConstructionNot identifiedJul 7, 2026
D.G. Khan Cement dgcement.comConstructionNot identifiedJul 7, 2026
Vicente Trapani vicentetrapani.comManufacturingArgentinaJul 7, 2026
Western International Group westernint.comManufacturingUnited Arab EmiratesJul 7, 2026
Ahmet Aydeniz Group aydeniz.comConstructionTurkeyJul 6, 2026
Flazio flazio.comTechnologyItalyJul 3, 2026
Holiday Palace holidaypalace.comHospitalityThailandJul 3, 2026
Rita Võ Group ritavo.comRetailVietnamJul 3, 2026
Government of Brazil gov.brGovernmentBrazilJun 24, 2026
PT Portal Biz Nusantara kliknklik.comRetailIndonesiaJun 24, 2026
Flughafen Wien viennaairport.comNot identifiedAustriaJun 24, 2026
Arpinet arpinet.amTelecommunicationsNot identifiedJun 4, 2026
Ministry of Internal Affairs of the Republic of Armenia gov.amGovernmentNot identifiedJun 3, 2026
Minsa minsa.com.mxManufacturingMexicoMay 25, 2026
TKGM tkgm.gov.trGovernmentTurkeyMay 25, 2026
TVN Media tvnmedia.comMediaGermanyMay 25, 2026
Alkaloid AD Skopje alkaloid.com.mkHealthcareNot identifiedMay 22, 2026
Grupo Petersen grupopetersen.com.arFinancial ServicesArgentinaMay 22, 2026
NARIT narit.or.thEducationThailandMay 22, 2026

Showing the 20 most recent of 108. Browse recent data breaches for more.

Bashe leak sites

Addresses we've seen Bashe publish victims from. Any .onion address needs the Tor Browser.

  • basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion
  • bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion
  • bashefe5uezp2jtxpk24b2pyfnnfyguicgrgqufgu57mfluegotbeayd.onion
  • bashei5oy4zvmf2letnupwhgprdkjyssm3zxj2oyr6wfezkf3elehzqd.onion
  • bashed52orwi7qoyvmcfkdnuaogta4inpojfd6cthzkp4qpsq64ux4ad.onion
  • bashedl53memptddxzb4kr5mnkzse4fmhpqeq7jb4srndswar46nofid.onion
  • bashex7mokreyoxl6wlswxl4foi7okgs7or7aergnuiockuoq35yt3ad.onion
  • basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion
  • basherykagbxoaiaxkgqhmhd5gbmedwb3di4ig3ouovziagosv4n77qd.onion
  • bashete63b3gcijfofpw6fmn3rwnmyi5aclp55n6awcfbexivexbhyad.onion

Bashe questions

Is Bashe still active?

Yes. Bashe posted its most recent victim on July 27, 2026.

How many victims has Bashe claimed?

Bashe has named 108 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files. 58 of them were posted in the last 12 months.

When did Bashe first appear?

The first victim we recorded for Bashe was posted on November 25, 2024. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Bashe target?

Financial Services accounts for the most victims we can classify, with 18. Government follows at 13. We could identify a sector for 80 of 108 victims, so treat this as the shape of the targeting rather than a full census.

Has Bashe already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.