
BlackByte
Data as of August 16, 2026.
Credential exposure before the attack
32.9% of BlackByte victims whose domain we can identify (46 of 140) had employee credentials leak in the 12 months before BlackByte named them as a victim.
We don't know whether any of these credentials were how BlackByte gained initial access.
What industries BlackByte targets
Sector identified for 44 of 140 victims.
| Manufacturing | 17 | |
| Government | 5 | |
| Healthcare | 3 | |
| Financial Services | 3 | |
| Technology | 3 | |
| Non-profit | 3 | |
| Logistics | 2 | |
| Education | 2 |
Where the victims are located
Country identified for 35 of 140 victims.
| Italy | 4 | |
| United Kingdom | 3 | |
| Australia | 2 | |
| Greece | 2 | |
| Peru | 2 | |
| New Zealand | 2 | |
| Mexico | 2 | |
| Brazil | 2 |
Most recent BlackByte victims
| Victim | Sector | Country | Posted |
|---|---|---|---|
| Cpat Flex cpatflex.com | Telecommunications | Not identified | Jul 31, 2025 |
| Towne Mortgage townemortgage.com | Not identified | Not identified | Jul 31, 2025 |
| Dara Pharma dara-pharma.com | Healthcare | Spain | Jul 30, 2025 |
| Lee & Associates lee-associates.com | Not identified | Not identified | Jul 30, 2025 |
| Allstarmg allstarmg.com | Manufacturing | Not identified | Jul 21, 2025 |
| Helpsonv helpsonv.org | Non-profit | Not identified | Jul 21, 2025 |
| All Star Innovations allstarmg.com | Manufacturing | Not identified | Jul 18, 2025 |
| ARK Consultancy arkconsultancy.co.uk | Not identified | United Kingdom | Jul 18, 2025 |
| GreenLight Biosciences greenlightbiosciences.com | Not identified | Not identified | Jul 18, 2025 |
| HELP of Southern Nevada helpsonv.org | Non-profit | Not identified | Jul 18, 2025 |
| T2 Group t2group.co.uk | Not identified | United Kingdom | Jul 18, 2025 |
| TOTVS totvs.com | Technology | Not identified | Oct 1, 2024 |
| Modern Auto modernauto.com | Not identified | Not identified | Jul 18, 2024 |
| The Law Office of Omar O. Vargas quenotedeporten.com | Not identified | Not identified | Jul 18, 2024 |
| Studio Notarile Bucciolmi studionotarilebucciolmi.it | Not identified | Italy | Jul 18, 2024 |
| Newburgh, NY cityofnewburgh-ny.gov | Government | Not identified | Jun 24, 2024 |
| Encina Wastewater Authority encinajpa.com | Not identified | Not identified | Mar 15, 2024 |
| meridian.coop | Technology | Not identified | Oct 5, 2023 |
| Xcaret xcaret.com | Not identified | Not identified | Sep 19, 2023 |
| Alps Alpine alpsalpine.com | Manufacturing | Not identified | Sep 12, 2023 |
Showing the 20 most recent of 140. Browse recent data breaches for more.
BlackByte leak sites
Addresses we've seen BlackByte publish victims from. Any .onion address needs the Tor Browser.
jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad.onionanonfiles.comf5uzduboq4fa2xkjloprmctk7ve3dm46ff7aniis66cbekakvksxgeqd.oniondounczge5jhw4iztnnpzp54kd4ot3tikhjsimurtcewqssgye6vvrhqd.onion53d5skw4ypzku4bfq2tk2mr3xh5yqrzss25sooiubmjz67lb3gdivcad.onionransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onionvbfqeh5nugm6r2u2qvghsdxm3fotf5wbxb5ltv6vw77vus5frdpuaiid.onion
BlackByte questions
Is BlackByte still active?
Not for over a year. The last victim we recorded was July 31, 2025. The leak site has published nothing since, though the data it already leaked is still out there.
How many victims has BlackByte claimed?
BlackByte has named 140 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did BlackByte first appear?
The first victim we recorded for BlackByte was posted on October 17, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.
Which sectors does BlackByte target?
Manufacturing accounts for the most victims we can classify, with 17. Government follows at 5. We could identify a sector for 44 of 140 victims, so treat this as the shape of the targeting rather than a full census.
Has BlackByte already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.