NetRunner

Quiet since March 31, 2026
6 victims named on the leak site
0 in the last 30 days
6 in the last 12 months
Mar 2026 first victim we recorded
Mar 31, 2026 most recent victim posted
1 leak site tracked

Data as of August 16, 2026.

What industries NetRunner targets

Sector identified for 5 of 6 victims.

Healthcare2
Logistics1
Telecommunications1
Manufacturing1

Where the victims are located

Country identified for all 6 victims.

Japan3
South Korea1
United States1
Italy1

Every NetRunner victim

VictimSectorCountryPosted
Seoyonehap seoyonehap.comLogisticsSouth KoreaMar 31, 2026
Crunch Fitness crunchfitness.comNot identifiedUnited StatesMar 30, 2026
GEG Telecomunicazioni geg.itTelecommunicationsItalyMar 30, 2026
JIFCO jifco.coManufacturingJapanMar 30, 2026
Nippon Medical School nms.ac.jpHealthcareJapanMar 30, 2026
Shiraume Hospital shiraume.or.jpHealthcareJapanMar 30, 2026

Browse recent data breaches for more.

NetRunner leak site

The address we've seen NetRunner publish victims from. Any .onion address needs the Tor Browser.

  • netrunrsb3bivj5gnwajzxlig5qkteb6edgthxj7fmsvhkzxtwfxwaad.onion

NetRunner questions

Is NetRunner still active?

It's gone quiet. The last victim we recorded was March 31, 2026, and nothing has appeared since. Groups do go quiet and come back, so we're still watching.

How many victims has NetRunner claimed?

NetRunner has named 6 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did NetRunner first appear?

The first victim we recorded for NetRunner was posted on March 30, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does NetRunner target?

Healthcare accounts for the most victims we can classify, with 2. Logistics follows at 1. We could identify a sector for 5 of 6 victims, so treat this as the shape of the targeting rather than a full census.

Has NetRunner already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.