
n0n
Data as of September 21, 2026.
What industries n0n targets
Sector identified for 5 of 8 victims.
| Healthcare | 2 | |
| Financial Services | 1 | |
| Education | 1 | |
| Telecommunications | 1 |
Where the victims are located
Country identified for 7 of 8 victims.
| United States | 3 | |
| Argentina | 1 | |
| United Kingdom | 1 | |
| Vietnam | 1 | |
| Luxembourg | 1 |
Every n0n victim
| Victim | Sector | Country | Posted |
|---|---|---|---|
| Argentem Creek Partners argentemcreek.com | Financial Services | United States | Sep 21, 2026 |
| Ministry of Education of Argentina argentina.gob.ar | Not identified | Argentina | Sep 21, 2026 |
| AstraZeneca astrazeneca.com | Healthcare | United Kingdom | Sep 21, 2026 |
| BeLi Teachers beliteachers.com | Education | Vietnam | Sep 21, 2026 |
| Fanatics fanaticsinc.com | Not identified | United States | Sep 21, 2026 |
| Inter inter.com.ve | Telecommunications | Not identified | Sep 21, 2026 |
| Stokr stokr.io | Not identified | Luxembourg | Sep 21, 2026 |
| United Federation of Teachers uft.org | Healthcare | United States | Sep 21, 2026 |
Browse recent data breaches for more.
n0n leak site
The address we've seen n0n publish victims from. Any .onion address needs the Tor Browser.
nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion
n0n questions
Is n0n still active?
Yes. n0n posted its most recent victim on September 21, 2026. That's 8 victims in the last 30 days.
How many victims has n0n claimed?
n0n has named 8 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did n0n first appear?
The first victim we recorded for n0n was posted on September 21, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.
Which sectors does n0n target?
Healthcare accounts for the most victims we can classify, with 2. Financial Services follows at 1. We could identify a sector for 5 of 8 victims, so treat this as the shape of the targeting rather than a full census.
Has n0n already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.