
BlackX
Data as of August 16, 2026.
What industries BlackX targets
Sector identified for 4 of 7 victims.
| Non-profit | 1 | |
| Healthcare | 1 | |
| Technology | 1 | |
| Retail | 1 |
Where the victims are located
Country identified for 6 of 7 victims.
| South Korea | 2 | |
| South Africa | 1 | |
| United States | 1 | |
| Germany | 1 | |
| Malaysia | 1 |
Every BlackX victim
| Victim | Sector | Country | Posted |
|---|---|---|---|
| Tong Kong E & E tongkong.com.my | Retail | Malaysia | Jul 30, 2026 |
| Sana\'a Center for Strategic Studies sanaacenter.org | Not identified | Not identified | Jul 16, 2026 |
| Daechang Solution dsol.co.kr | Technology | South Korea | Jun 15, 2026 |
| African National Congress anc1912.org.za | Not identified | South Africa | Jun 3, 2026 |
| Community Resource Services correction.org | Non-profit | United States | Jun 3, 2026 |
| Landesinnungsverband für das Bayerische Elektrohandwerk elektroverband-bayern.de | Not identified | Germany | Jun 3, 2026 |
| Wonjin Beauty Medical Group wonjinbeauty.com | Healthcare | South Korea | Jun 3, 2026 |
Browse recent data breaches for more.
BlackX leak site
The address we've seen BlackX publish victims from. Any .onion address needs the Tor Browser.
blackxppq2jvqyg4slyg3sbszv7ib2avaaycvhff5qipgdoepqi57xyd.onion
BlackX questions
Is BlackX still active?
Yes. BlackX posted its most recent victim on July 30, 2026.
How many victims has BlackX claimed?
BlackX has named 7 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did BlackX first appear?
The first victim we recorded for BlackX was posted on June 3, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.
Has BlackX already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.