
Cicada3301
Data as of August 16, 2026.
Credential exposure before the attack
52% of Cicada3301 victims whose domain we can identify (39 of 75) had employee credentials leak in the 12 months before Cicada3301 named them as a victim.
We don't know whether any of these credentials were how Cicada3301 gained initial access.
What industries Cicada3301 targets
Sector identified for 36 of 75 victims.
| Manufacturing | 8 | |
| Financial Services | 6 | |
| Legal | 5 | |
| Healthcare | 4 | |
| Education | 2 | |
| Energy | 2 | |
| Logistics | 2 | |
| Technology | 2 |
Where the victims are located
Country identified for 20 of 75 victims.
| Brazil | 5 | |
| France | 3 | |
| United Kingdom | 3 | |
| Switzerland | 2 | |
| Japan | 1 | |
| Mexico | 1 | |
| Czech Republic | 1 | |
| United States | 1 |
Most recent Cicada3301 victims
| Victim | Sector | Country | Posted |
|---|---|---|---|
| C&I Engineering cieng.com | Energy | United States | Sep 5, 2025 |
| B & M Expertise bmexpertise.fr | Financial Services | France | Jul 21, 2025 |
| Burnham Nationwide burnhamnationwide.com | Construction | Not identified | Jul 21, 2025 |
| Cartório Dias de Primavera diasdeprimavera.com.br | Not identified | Brazil | Jul 21, 2025 |
| GAT Logística gatlogistica.com.br | Healthcare | Brazil | Jul 21, 2025 |
| Sensical sensical.com | Manufacturing | Not identified | Jul 21, 2025 |
| Сonasa conasa.com | Financial Services | Brazil | Jul 15, 2025 |
| Pacific BioLabs pacificbiolabs.com | Not identified | Not identified | Jul 11, 2025 |
| Mack Energy mec.com | Energy | Mexico | Jul 10, 2025 |
| Amazon Transportes amazontransportes.com.br | Logistics | Brazil | Apr 23, 2025 |
| Asesoría Bieito bieito.com | Financial Services | Not identified | Apr 23, 2025 |
| Natilait natilait.com.tn | Not identified | Not identified | Apr 23, 2025 |
| Prague City Service Administration sshmp.cz | Government | Czech Republic | Apr 10, 2025 |
| Eagle Distilleries eagledis.com | Not identified | Not identified | Apr 7, 2025 |
| IATSE 667 iatse667.com | Not identified | Not identified | Mar 26, 2025 |
| MinebeaMitsumi minebeamitsumi.com | Healthcare | Not identified | Mar 24, 2025 |
| Benjamin Consulting Services bcsmidwest.com | Not identified | Not identified | Feb 26, 2025 |
| Birdsall Muller birdsall-law.com | Not identified | Not identified | Feb 25, 2025 |
| Executive Agenda executiveagenda.com | Not identified | Not identified | Feb 25, 2025 |
| Digital Technology dtc.co.jp | Not identified | Japan | Feb 24, 2025 |
Showing the 20 most recent of 75. Browse recent data breaches for more.
Cicada3301 leak sites
Addresses we've seen Cicada3301 publish victims from. Any .onion address needs the Tor Browser.
cicadabv7vicyvgz5khl7v2x5yygcgow7ryy6yppwmxii4eoobdaztqd.onioncicadacnft7gcgnveb7wjm6pjpjcjcsugogmlrat7u7pcel3iwb7bhyd.onionmega.nzcicadafhqpjwm2sblkfbuwn7sglbibuejr3m7fildpqpjv3hghlhb4id.onion5atqn4dwosjauijzj445mm7t6bqrcvzlzcylpmpnx243jxvlimyb6aid.onion
Cicada3301 questions
Is Cicada3301 still active?
It's gone quiet. The last victim we recorded was September 5, 2025, and nothing has appeared since. Groups do go quiet and come back, so we're still watching.
How many victims has Cicada3301 claimed?
Cicada3301 has named 75 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files. 1 of them was posted in the last 12 months.
When did Cicada3301 first appear?
The first victim we recorded for Cicada3301 was posted on June 20, 2024. That's when the group entered our collection, which isn't necessarily when it started operating.
Which sectors does Cicada3301 target?
Manufacturing accounts for the most victims we can classify, with 8. Financial Services follows at 6. We could identify a sector for 36 of 75 victims, so treat this as the shape of the targeting rather than a full census.
Has Cicada3301 already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.