Funksec

Dark since March 19, 2025
161 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Dec 2024 first victim we recorded
Mar 19, 2025 most recent victim posted
11 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

21.7% of Funksec victims whose domain we can identify (35 of 161) had employee credentials leak in the 12 months before Funksec named them as a victim.

We don't know whether any of these credentials were how Funksec gained initial access.

What industries Funksec targets

Sector identified for 79 of 161 victims.

Education16
Government13
Financial Services8
Technology8
Telecommunications5
Manufacturing5
Retail4
Healthcare4

Where the victims are located

Country identified for 68 of 161 victims.

India13
Brazil8
United Arab Emirates4
France4
Italy3
Mexico3
Colombia3
Spain3

Most recent Funksec victims

VictimSectorCountryPosted
Semaphore semaphore.asso.frNot identifiedFranceMar 19, 2025
Sanirent sanirent.com.mxNot identifiedMexicoMar 17, 2025
Extreme Performance extremeperformance.comManufacturingNot identifiedMar 13, 2025
University of Modena and Reggio Emilia unimore.itEducationItalyMar 12, 2025
The International School of Elite Education isee-eg.comEducationNot identifiedMar 11, 2025
K Labs klabs.itEducationItalyMar 10, 2025
Université de Rennes univ-rennes.frNot identifiedFranceMar 10, 2025
Sorbonne Université sorbonne-universite.frEducationFranceMar 7, 2025
Desa Cimenyan cimenyan.desa.idNot identifiedIndonesiaMar 4, 2025
Laravel isurges.comGovernmentNot identifiedMar 3, 2025
J.A. Street jastreet.comConstructionNot identifiedMar 3, 2025
Mandarin mandarin.com.brNot identifiedBrazilMar 3, 2025
MyTower mytower.com.brTelecommunicationsBrazilMar 3, 2025
Moon Tech moontech.aeNot identifiedUnited Arab EmiratesFeb 27, 2025
StayzApp stayzapp.inNot identifiedIndiaFeb 27, 2025
Rossman Media rossmanmedia.aeNot identifiedUnited Arab EmiratesFeb 20, 2025
Football Ticket Net footballticketnet.comNot identifiedNot identifiedFeb 19, 2025
Hiway Internet hiway.com.brNot identifiedBrazilFeb 18, 2025
Fast Track Cargo fasttrackcargo.comNot identifiedNot identifiedFeb 17, 2025
MyISP.live myisp.liveTelecommunicationsNot identifiedFeb 17, 2025

Showing the 20 most recent of 161. Browse recent data breaches for more.

Funksec leak sites

Addresses we've seen Funksec publish victims from. Any .onion address needs the Tor Browser.

  • 7ixfdvqb4eaju5lzj4gg76kwlrxg4ugqpuog5oqkkmgfyn33h527oyyd.onion
  • funknqn44slwmgwgnewne6bintbooauwkaupik4yrlgtycew3ergraid.onion
  • fastupload.io
  • funksec7vgdojepkipvhfpul3bvsxzyxn66ogp7q4pptvujxtpyjttad.onion
  • funksecsekgasgjqlzzkmcnutrrrafavpszijoilbd6z3dkbzvqu43id.onion
  • funkiydk7c6j3vvck5zk2giml2u746fa5irwalw2kjem6tvofji7rwid.onion
  • funkxxkovrk7ctnggbjnthdajav4ggex53k6m2x3esjwlxrkb3qiztid.onion
  • funksec53xh7j5t6ysgwnaidj5vkh3aqajanplix533kwxdz3qrwugid.onion
  • funkyiazgfsrxrib6rnxbhkgfqi7isisfbqnwk2ycf7tpgfhtevlamad.onion
  • gofile.io
  • funk4ph7igelwpgadmus4n4moyhh22cib723hllneen7g2qkklml4sqd.onion

Funksec questions

Is Funksec still active?

Not for over a year. The last victim we recorded was March 19, 2025. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has Funksec claimed?

Funksec has named 161 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Funksec first appear?

The first victim we recorded for Funksec was posted on December 4, 2024. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Funksec target?

Education accounts for the most victims we can classify, with 16. Government follows at 13. We could identify a sector for 79 of 161 victims, so treat this as the shape of the targeting rather than a full census.

Has Funksec already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.