BlackX

Active
7 victims named on the leak site
1 in the last 30 days
7 in the last 12 months
Jun 2026 first victim we recorded
Jul 30, 2026 most recent victim posted
1 leak site tracked

Data as of August 16, 2026.

What industries BlackX targets

Sector identified for 4 of 7 victims.

Non-profit1
Healthcare1
Technology1
Retail1

Where the victims are located

Country identified for 6 of 7 victims.

South Korea2
South Africa1
United States1
Germany1
Malaysia1

Every BlackX victim

VictimSectorCountryPosted
Tong Kong E & E tongkong.com.myRetailMalaysiaJul 30, 2026
Sana\'a Center for Strategic Studies sanaacenter.orgNot identifiedNot identifiedJul 16, 2026
Daechang Solution dsol.co.krTechnologySouth KoreaJun 15, 2026
African National Congress anc1912.org.zaNot identifiedSouth AfricaJun 3, 2026
Community Resource Services correction.orgNon-profitUnited StatesJun 3, 2026
Landesinnungsverband für das Bayerische Elektrohandwerk elektroverband-bayern.deNot identifiedGermanyJun 3, 2026
Wonjin Beauty Medical Group wonjinbeauty.comHealthcareSouth KoreaJun 3, 2026

Browse recent data breaches for more.

BlackX leak site

The address we've seen BlackX publish victims from. Any .onion address needs the Tor Browser.

  • blackxppq2jvqyg4slyg3sbszv7ib2avaaycvhff5qipgdoepqi57xyd.onion

BlackX questions

Is BlackX still active?

Yes. BlackX posted its most recent victim on July 30, 2026.

How many victims has BlackX claimed?

BlackX has named 7 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did BlackX first appear?

The first victim we recorded for BlackX was posted on June 3, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.

Has BlackX already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.