DataLeak

Dark since June 15, 2023
6 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Dec 2022 first victim we recorded
Jun 15, 2023 most recent victim posted
4 leak sites tracked

Data as of August 16, 2026.

What industries DataLeak targets

Sector identified for 2 of 6 victims.

Financial Services2

Where the victims are located

Country identified for 3 of 6 victims.

Germany2
Brazil1

Every DataLeak victim

VictimSectorCountryPosted
crhealthcare.orgNot identifiedNot identifiedJun 15, 2023
beacon.co.ttFinancial ServicesNot identifiedDec 5, 2022
grantweber.comFinancial ServicesNot identifiedDec 5, 2022
nissin.com.brNot identifiedBrazilDec 5, 2022
rkw-group.comNot identifiedGermanyDec 5, 2022
wiesauplast.deNot identifiedGermanyDec 5, 2022

Browse recent data breaches for more.

DataLeak leak sites

Addresses we've seen DataLeak publish victims from. Any .onion address needs the Tor Browser.

  • woqjumaahi662ka26jzxyx7fznbp4kg3bsjar4b52tqkxgm2pylcjlad.onion
  • gofile.io
  • 7ukmkdtyxdkdivtjad57klqnd3kdsmq6tp45rrsxqnu76zzv3jvitlqd.onion
  • kolbh6putvp6aw3vpmsppor4kyzs7ctxfbp2donetycftz5jru73ytid.onion

DataLeak questions

Is DataLeak still active?

Not for over a year. The last victim we recorded was June 15, 2023. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has DataLeak claimed?

DataLeak has named 6 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did DataLeak first appear?

The first victim we recorded for DataLeak was posted on December 5, 2022. That's when the group entered our collection, which isn't necessarily when it started operating.

Has DataLeak already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.