DYSPHOR1A

Active
11 victims named on the leak site
11 in the last 30 days
11 in the last 12 months
Aug 2026 first victim we recorded
Sep 7, 2026 most recent victim posted
2 leak sites tracked

Data as of September 14, 2026.

What industries DYSPHOR1A targets

Sector identified for 6 of 11 victims.

Education3
Financial Services2
Government1

Where the victims are located

Country identified for 5 of 11 victims.

Thailand1
India1
United Kingdom1
Indonesia1
France1

Every DYSPHOR1A victim

VictimSectorCountryPosted
CTZPay ctzpay.comFinancial ServicesNot identifiedSep 7, 2026
Myanmar Broadband Telecom com.mmNot identifiedNot identifiedSep 7, 2026
Road Transport Administration Department gov.mmGovernmentNot identifiedSep 7, 2026
Netim netim.comNot identifiedFranceAug 24, 2026
Yoma Fleet yomafleet.comNot identifiedNot identifiedAug 22, 2026
Allianz Ayudhya allianz.co.thFinancial ServicesThailandAug 21, 2026
University of Delhi du.ac.inEducationIndiaAug 21, 2026
GUSTO College gusto-education.comEducationUnited KingdomAug 21, 2026
JobNet Myanmar com.mmNot identifiedNot identifiedAug 21, 2026
Kepolisian Negara Republik Indonesia polri.go.idNot identifiedIndonesiaAug 21, 2026
Strategy First International College edu.mmEducationNot identifiedAug 21, 2026

Browse recent data breaches for more.

DYSPHOR1A leak sites

Addresses we've seen DYSPHOR1A publish victims from. Any .onion address needs the Tor Browser.

  • normalhunters0x.surge.sh
  • y3maveiwszbnrziufbbberx74cvrdcsf72nxzuqxzv7ppdmmqzffazid.onion

DYSPHOR1A questions

Is DYSPHOR1A still active?

Yes. DYSPHOR1A posted its most recent victim on September 7, 2026. That's 11 victims in the last 30 days.

How many victims has DYSPHOR1A claimed?

DYSPHOR1A has named 11 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did DYSPHOR1A first appear?

The first victim we recorded for DYSPHOR1A was posted on August 21, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does DYSPHOR1A target?

Education accounts for the most victims we can classify, with 3. Financial Services follows at 2. We could identify a sector for 6 of 11 victims, so treat this as the shape of the targeting rather than a full census.

Has DYSPHOR1A already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.