BlackByte

Dark since July 31, 2025
140 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Oct 2021 first victim we recorded
Jul 31, 2025 most recent victim posted
7 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

32.9% of BlackByte victims whose domain we can identify (46 of 140) had employee credentials leak in the 12 months before BlackByte named them as a victim.

We don't know whether any of these credentials were how BlackByte gained initial access.

What industries BlackByte targets

Sector identified for 44 of 140 victims.

Manufacturing17
Government5
Healthcare3
Financial Services3
Technology3
Non-profit3
Logistics2
Education2

Where the victims are located

Country identified for 35 of 140 victims.

Italy4
United Kingdom3
Australia2
Greece2
Peru2
New Zealand2
Mexico2
Brazil2

Most recent BlackByte victims

VictimSectorCountryPosted
Cpat Flex cpatflex.comTelecommunicationsNot identifiedJul 31, 2025
Towne Mortgage townemortgage.comNot identifiedNot identifiedJul 31, 2025
Dara Pharma dara-pharma.comHealthcareSpainJul 30, 2025
Lee & Associates lee-associates.comNot identifiedNot identifiedJul 30, 2025
Allstarmg allstarmg.comManufacturingNot identifiedJul 21, 2025
Helpsonv helpsonv.orgNon-profitNot identifiedJul 21, 2025
All Star Innovations allstarmg.comManufacturingNot identifiedJul 18, 2025
ARK Consultancy arkconsultancy.co.ukNot identifiedUnited KingdomJul 18, 2025
GreenLight Biosciences greenlightbiosciences.comNot identifiedNot identifiedJul 18, 2025
HELP of Southern Nevada helpsonv.orgNon-profitNot identifiedJul 18, 2025
T2 Group t2group.co.ukNot identifiedUnited KingdomJul 18, 2025
TOTVS totvs.comTechnologyNot identifiedOct 1, 2024
Modern Auto modernauto.comNot identifiedNot identifiedJul 18, 2024
The Law Office of Omar O. Vargas quenotedeporten.comNot identifiedNot identifiedJul 18, 2024
Studio Notarile Bucciolmi studionotarilebucciolmi.itNot identifiedItalyJul 18, 2024
Newburgh, NY cityofnewburgh-ny.govGovernmentNot identifiedJun 24, 2024
Encina Wastewater Authority encinajpa.comNot identifiedNot identifiedMar 15, 2024
meridian.coopTechnologyNot identifiedOct 5, 2023
Xcaret xcaret.comNot identifiedNot identifiedSep 19, 2023
Alps Alpine alpsalpine.comManufacturingNot identifiedSep 12, 2023

Showing the 20 most recent of 140. Browse recent data breaches for more.

BlackByte leak sites

Addresses we've seen BlackByte publish victims from. Any .onion address needs the Tor Browser.

  • jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad.onion
  • anonfiles.com
  • f5uzduboq4fa2xkjloprmctk7ve3dm46ff7aniis66cbekakvksxgeqd.onion
  • dounczge5jhw4iztnnpzp54kd4ot3tikhjsimurtcewqssgye6vvrhqd.onion
  • 53d5skw4ypzku4bfq2tk2mr3xh5yqrzss25sooiubmjz67lb3gdivcad.onion
  • ransomocmou6mnbquqz44ewosbkjk3o5qjsl3orawojexfook2j7esad.onion
  • vbfqeh5nugm6r2u2qvghsdxm3fotf5wbxb5ltv6vw77vus5frdpuaiid.onion

BlackByte questions

Is BlackByte still active?

Not for over a year. The last victim we recorded was July 31, 2025. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has BlackByte claimed?

BlackByte has named 140 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did BlackByte first appear?

The first victim we recorded for BlackByte was posted on October 17, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does BlackByte target?

Manufacturing accounts for the most victims we can classify, with 17. Government follows at 5. We could identify a sector for 44 of 140 victims, so treat this as the shape of the targeting rather than a full census.

Has BlackByte already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.