
Helldown
Data as of August 16, 2026.
Credential exposure before the attack
24.2% of Helldown victims whose domain we can identify (8 of 33) had employee credentials leak in the 12 months before Helldown named them as a victim.
We don't know whether any of these credentials were how Helldown gained initial access.
What industries Helldown targets
Sector identified for 20 of 33 victims.
| Healthcare | 4 | |
| Logistics | 3 | |
| Construction | 3 | |
| Legal | 2 | |
| Manufacturing | 2 | |
| Financial Services | 1 | |
| Non-profit | 1 | |
| Technology | 1 |
Where the victims are located
Country identified for 16 of 33 victims.
| Germany | 4 | |
| United States | 2 | |
| Switzerland | 2 | |
| France | 2 | |
| Poland | 2 | |
| Czech Republic | 1 | |
| Italy | 1 | |
| Austria | 1 |
Most recent Helldown victims
| Victim | Sector | Country | Posted |
|---|---|---|---|
| American Ventures americanventures.com | Financial Services | United States | Nov 7, 2024 |
| San Jacinto County san-jacinto.tx.us | Not identified | United States | Nov 7, 2024 |
| Compass Funding Solutions compassfs.net | Logistics | Not identified | Nov 7, 2024 |
| CSI Kitchen & Bath csikitchenandbath.com | Not identified | Not identified | Nov 7, 2024 |
| Fuelco fuelco-us.com | Not identified | Not identified | Nov 7, 2024 |
| General Dentistry for Children generaldentistryforchildren.com | Not identified | Not identified | Nov 7, 2024 |
| Haus des Stiftens hausdesstiftens.org | Non-profit | Not identified | Nov 7, 2024 |
| Knox Law Center knoxlawcenter.com | Legal | Not identified | Nov 7, 2024 |
| La Clinique Du Coureur lacliniqueducoureur.com | Healthcare | Not identified | Nov 7, 2024 |
| Nightnurse Images nightnurse.ch | Not identified | Switzerland | Nov 7, 2024 |
| Qualiform qualiform.cz | Construction | Czech Republic | Nov 7, 2024 |
| Smarts Engineering smarts-engineering.de | Technology | Germany | Nov 7, 2024 |
| Tivoli 33 tivoli-33.org | Education | France | Nov 7, 2024 |
| Gonzalez Castillo Moya valleyfirm.com | Legal | Not identified | Nov 7, 2024 |
| Klinik am Kurpark klinik-am-kurpark.de | Healthcare | Germany | Sep 17, 2024 |
| Jewish Federation of Greater Harrisburg jewishharrisburg.org | Not identified | Not identified | Aug 26, 2024 |
| Cincinnati Pain Physicians cincinnatipainphysicians.com | Healthcare | Not identified | Aug 23, 2024 |
| Barry Avenue Plating barryavenueplating.com | Not identified | Not identified | Aug 22, 2024 |
| RSK Immobilien GmbH rsk-immobilien.de | Real Estate | Germany | Aug 22, 2024 |
| Khonaysse khonaysser.com | Manufacturing | Not identified | Aug 20, 2024 |
Showing the 20 most recent of 33. Browse recent data breaches for more.
Helldown leak sites
Addresses we've seen Helldown publish victims from. Any .onion address needs the Tor Browser.
onyxcgfg4pjevvp5h34zvhaj45kbft3dg5r33j5vu3nyp7xic3vrzvad.oniononyxcb44xvqra35m3lp3z26kf2pxrlbn64nbzvyvzjyc3uykzrwcjdid.oniononyxcym4mjilrsptk5uo2dhesbwntuban55mvww2olk5ygqafhu3i3yd.onion
Helldown questions
Is Helldown still active?
Not for over a year. The last victim we recorded was November 7, 2024. The leak site has published nothing since, though the data it already leaked is still out there.
How many victims has Helldown claimed?
Helldown has named 33 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did Helldown first appear?
The first victim we recorded for Helldown was posted on August 14, 2024. That's when the group entered our collection, which isn't necessarily when it started operating.
Which sectors does Helldown target?
Healthcare accounts for the most victims we can classify, with 4. Logistics follows at 3. We could identify a sector for 20 of 33 victims, so treat this as the shape of the targeting rather than a full census.
Has Helldown already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.