OSIRIS

Quiet since March 24, 2026
3 victims named on the leak site
0 in the last 30 days
3 in the last 12 months
Dec 2025 first victim we recorded
Mar 24, 2026 most recent victim posted
2 leak sites tracked

Data as of August 16, 2026.

What industries OSIRIS targets

Sector identified for 2 of 3 victims.

Hospitality1
Manufacturing1

Where the victims are located

Country identified for all 3 victims.

Philippines1
United States1
India1

Every OSIRIS victim

VictimSectorCountryPosted
Mantratec mantratec.comNot identifiedIndiaMar 24, 2026
American Vanguard american-vanguard.comManufacturingUnited StatesJan 12, 2026
The Araneta Group aranetagroup.comHospitalityPhilippinesDec 18, 2025

Browse recent data breaches for more.

OSIRIS leak sites

Addresses we've seen OSIRIS publish victims from. Any .onion address needs the Tor Browser.

  • osirisbm3357xrccnid23nlyuqwzbgqheaei6dxvyi34tbkqr3bmvfid.onion
  • ausare.net

OSIRIS questions

Is OSIRIS still active?

It's gone quiet. The last victim we recorded was March 24, 2026, and nothing has appeared since. Groups do go quiet and come back, so we're still watching.

How many victims has OSIRIS claimed?

OSIRIS has named 3 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did OSIRIS first appear?

The first victim we recorded for OSIRIS was posted on December 18, 2025. That's when the group entered our collection, which isn't necessarily when it started operating.

Has OSIRIS already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.