Conti

Dark since December 19, 2022
753 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Aug 2020 first victim we recorded
Dec 19, 2022 most recent victim posted
17 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

59.8% of Conti victims whose domain we can identify (450 of 753) had employee credentials leak in the 12 months before Conti named them as a victim.

We don't know whether any of these credentials were how Conti gained initial access.

What industries Conti targets

Sector identified for 17 of 753 victims.

Manufacturing10
Construction3
Technology1
Healthcare1
Hospitality1
Education1

Where the victims are located

Country identified for 171 of 753 victims.

United Kingdom34
Germany24
Canada15
Italy14
United States14
France14
Australia9
Netherlands6

Most recent Conti victims

VictimSectorCountryPosted
mackdefense.comNot identifiedNot identifiedDec 19, 2022
perennialsfabrics.comNot identifiedNot identifiedNov 15, 2022
rrd.comNot identifiedNot identifiedNov 15, 2022
safeguardit.comNot identifiedNot identifiedNov 15, 2022
allianceokc.comManufacturingNot identifiedJun 8, 2022
easybuildingdesigner.comManufacturingNot identifiedJun 8, 2022
centralrestaurant.comNot identifiedNot identifiedMay 25, 2022
linn.or.usNot identifiedUnited StatesMay 25, 2022
parkfun.comNot identifiedNot identifiedMay 25, 2022
rategain.comNot identifiedNot identifiedMay 25, 2022
agilesourcingpartners.comNot identifiedNot identifiedMay 24, 2022
allcatclaims.comNot identifiedNot identifiedMay 24, 2022
conceptsinmillwork.comNot identifiedNot identifiedMay 24, 2022
eurofred.comNot identifiedNot identifiedMay 24, 2022
imenco.noNot identifiedNorwayMay 24, 2022
minutoverde.clNot identifiedChileMay 24, 2022
omicronconsulting.itNot identifiedItalyMay 24, 2022
pianca.comNot identifiedNot identifiedMay 24, 2022
worksoft.comNot identifiedNot identifiedMay 24, 2022
cjkgroup.comNot identifiedNot identifiedMay 13, 2022

Showing the 20 most recent of 753. Browse recent data breaches for more.

Conti leak sites

Addresses we've seen Conti publish victims from. Any .onion address needs the Tor Browser.

  • nilbxxtm5mava3k2r5vzkuuu2g4bp5wlupo3nzry3c6q5rm5sti5ktqd.onion
  • continewsnv5otx5kaoje7krkto2qbu3gtqef22mnr7eaxw3y6ncz3ad.onion
  • gxjvjttlieqjbbqkdyccxdx74c6hx32zs2efolswvolgykro3chxbsid.onion
  • 4nmxrhdtbznfr7f3q6bhd4qxxfcxodao3h2txugojsizca4uhppdkzad.onion
  • temp.sh
  • continewsnv5otx5kaoje7krkto2qbu3gtqef22mnr7eaxw3y6ncz3ad.onion.ly
  • ilbxxtm5mava3k2r5vzkuuu2g4bp5wlupo3nzry3c6q5rm5sti5ktqd.onion
  • nilbxtm5mava3k2r5vzkuuu2g4bp5wlupo3nzry3c6q5rm5sti5ktqd.onion
  • nilbxxtm5ava3k2r5vzkuuu2g4bp5wlupo3nzry3c6q5rm5sti5ktqd.onion
  • nilbxxtm5mava3k25vzkuuu2g4bp5wlupo3nzry3c6q5rm5sti5ktqd.onion
  • nilbxxtm5mava3k2r5vzkuuu2g4bp5wlupo3nzry3c6q5r5sti5ktqd.onion
  • nilbxxtm5mava3k2r5vzkuuu2g4bp5wlupo3nzry3c6q5rm5sti5tqd.onion
  • nilbxxtm5mava3k2r5vzkuuu2g4bp5wlupo3nzry3c6q5rmsti5ktqd.onion
  • nilbxxtm5mava3k2r5vzkuuu2g4bp5wlupo3nzry3c6qrm5sti5ktqd.onion
  • nilbxxtm5mava3k2r5zkuuu2g4bp5wlupo3nzry3c6q5rm5sti5ktqd.onion
  • nilbxxtm5mava3kr5vzkuuu2g4bp5wlupo3nzry3c6q5rm5sti5ktqd.onion
  • nlbxxtm5mava3k2r5vzkuuu2g4bp5wlupo3nzry3c6q5rm5sti5ktqd.onion

Conti questions

Is Conti still active?

Not for over a year. The last victim we recorded was December 19, 2022. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has Conti claimed?

Conti has named 753 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Conti first appear?

The first victim we recorded for Conti was posted on August 27, 2020. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Conti target?

Manufacturing accounts for the most victims we can classify, with 10. Construction follows at 3. We could identify a sector for 17 of 753 victims, so treat this as the shape of the targeting rather than a full census.

Has Conti already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.