n0n

Active
8 victims named on the leak site
8 in the last 30 days
8 in the last 12 months
Sep 2026 first victim we recorded
Sep 21, 2026 most recent victim posted
1 leak site tracked

Data as of September 21, 2026.

What industries n0n targets

Sector identified for 5 of 8 victims.

Healthcare2
Financial Services1
Education1
Telecommunications1

Where the victims are located

Country identified for 7 of 8 victims.

United States3
Argentina1
United Kingdom1
Vietnam1
Luxembourg1

Every n0n victim

VictimSectorCountryPosted
Argentem Creek Partners argentemcreek.comFinancial ServicesUnited StatesSep 21, 2026
Ministry of Education of Argentina argentina.gob.arNot identifiedArgentinaSep 21, 2026
AstraZeneca astrazeneca.comHealthcareUnited KingdomSep 21, 2026
BeLi Teachers beliteachers.comEducationVietnamSep 21, 2026
Fanatics fanaticsinc.comNot identifiedUnited StatesSep 21, 2026
Inter inter.com.veTelecommunicationsNot identifiedSep 21, 2026
Stokr stokr.ioNot identifiedLuxembourgSep 21, 2026
United Federation of Teachers uft.orgHealthcareUnited StatesSep 21, 2026

Browse recent data breaches for more.

n0n leak site

The address we've seen n0n publish victims from. Any .onion address needs the Tor Browser.

  • nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion

n0n questions

Is n0n still active?

Yes. n0n posted its most recent victim on September 21, 2026. That's 8 victims in the last 30 days.

How many victims has n0n claimed?

n0n has named 8 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did n0n first appear?

The first victim we recorded for n0n was posted on September 21, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does n0n target?

Healthcare accounts for the most victims we can classify, with 2. Financial Services follows at 1. We could identify a sector for 5 of 8 victims, so treat this as the shape of the targeting rather than a full census.

Has n0n already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.