Payload.bin
Data as of August 16, 2026.
Credential exposure before the attack
81% of Payload.bin victims whose domain we can identify (17 of 21) had employee credentials leak in the 12 months before Payload.bin named them as a victim.
We don't know whether any of these credentials were how Payload.bin gained initial access.
Where the victims are located
Country identified for 2 of 21 victims.
| Australia | 1 | |
| Japan | 1 |
Most recent Payload.bin victims
| Victim | Sector | Country | Posted |
|---|---|---|---|
| paw.eu | Not identified | Not identified | Jan 1, 2022 |
| calsoftinc.com | Not identified | Not identified | Sep 30, 2021 |
| calautomotive.com | Not identified | Not identified | Sep 26, 2021 |
| myyp.com | Not identified | Not identified | Sep 26, 2021 |
| irely.com | Not identified | Not identified | Aug 24, 2021 |
| nsuship.co.jp | Not identified | Japan | Aug 24, 2021 |
| conferenceusa.com | Not identified | Not identified | Aug 19, 2021 |
| dawsoncountyne.org | Not identified | Not identified | Aug 19, 2021 |
| pdsec.com | Not identified | Not identified | Aug 19, 2021 |
| sklarwilton.com | Not identified | Not identified | Aug 19, 2021 |
| coreslab.com | Not identified | Not identified | Aug 18, 2021 |
| emmawillard.org | Not identified | Not identified | Aug 18, 2021 |
| crm.com | Not identified | Not identified | Aug 14, 2021 |
| webstercare.com.au | Not identified | Australia | Aug 5, 2021 |
| truckcentercompanies.com | Not identified | Not identified | Aug 2, 2021 |
| capstoneins.com | Not identified | Not identified | Aug 2, 2021 |
| connelypartners.com | Not identified | Not identified | Aug 2, 2021 |
| wrgtexas.com | Not identified | Not identified | Aug 2, 2021 |
| reconservices.com | Not identified | Not identified | Jul 28, 2021 |
| uptownbakers.com | Not identified | Not identified | Jul 27, 2021 |
Showing the 20 most recent of 21. Browse recent data breaches for more.
Payload.bin leak site
The address we've seen Payload.bin publish victims from. Any .onion address needs the Tor Browser.
vbmisqjshn4yblehk2vbnil53tlqklxsdaztgphcilto3vdj4geao5qd.onion
Payload.bin questions
Is Payload.bin still active?
Not for over a year. The last victim we recorded was January 1, 2022. The leak site has published nothing since, though the data it already leaked is still out there.
How many victims has Payload.bin claimed?
Payload.bin has named 21 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did Payload.bin first appear?
The first victim we recorded for Payload.bin was posted on July 27, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.
Has Payload.bin already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.