Groove

Dark since October 23, 2021
5 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Aug 2021 first victim we recorded
Oct 23, 2021 most recent victim posted
2 leak sites tracked

Data as of August 16, 2026.

Where the victims are located

Country identified for 2 of 5 victims.

Germany2

Every Groove victim

VictimSectorCountryPosted
episcopalretirement.comNot identifiedNot identifiedOct 23, 2021
therecord.mediaNot identifiedNot identifiedOct 23, 2021
hagerstownpd.orgNot identifiedNot identifiedOct 22, 2021
lrz.deNot identifiedGermanySep 9, 2021
ludofact.deNot identifiedGermanyAug 27, 2021

Browse recent data breaches for more.

Groove leak sites

Addresses we've seen Groove publish victims from. Any .onion address needs the Tor Browser.

  • ws3dh6av66sjbxxkjpw5ao3wqzmtejnkzheswm4dz5rrwvular7xvkqd.onion
  • ws3dh6av66sjbxxkjpw5ao3wqzmtejnkzheswm4dz5rrwvular7xvkqd.onion.ly

Groove questions

Is Groove still active?

Not for over a year. The last victim we recorded was October 23, 2021. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has Groove claimed?

Groove has named 5 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Groove first appear?

The first victim we recorded for Groove was posted on August 27, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.

Has Groove already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.