Payload.bin

Dark since January 1, 2022
21 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Jul 2021 first victim we recorded
Jan 1, 2022 most recent victim posted
1 leak site tracked

Data as of August 16, 2026.

Credential exposure before the attack

81% of Payload.bin victims whose domain we can identify (17 of 21) had employee credentials leak in the 12 months before Payload.bin named them as a victim.

We don't know whether any of these credentials were how Payload.bin gained initial access.

Where the victims are located

Country identified for 2 of 21 victims.

Australia1
Japan1

Most recent Payload.bin victims

VictimSectorCountryPosted
paw.euNot identifiedNot identifiedJan 1, 2022
calsoftinc.comNot identifiedNot identifiedSep 30, 2021
calautomotive.comNot identifiedNot identifiedSep 26, 2021
myyp.comNot identifiedNot identifiedSep 26, 2021
irely.comNot identifiedNot identifiedAug 24, 2021
nsuship.co.jpNot identifiedJapanAug 24, 2021
conferenceusa.comNot identifiedNot identifiedAug 19, 2021
dawsoncountyne.orgNot identifiedNot identifiedAug 19, 2021
pdsec.comNot identifiedNot identifiedAug 19, 2021
sklarwilton.comNot identifiedNot identifiedAug 19, 2021
coreslab.comNot identifiedNot identifiedAug 18, 2021
emmawillard.orgNot identifiedNot identifiedAug 18, 2021
crm.comNot identifiedNot identifiedAug 14, 2021
webstercare.com.auNot identifiedAustraliaAug 5, 2021
truckcentercompanies.comNot identifiedNot identifiedAug 2, 2021
capstoneins.comNot identifiedNot identifiedAug 2, 2021
connelypartners.comNot identifiedNot identifiedAug 2, 2021
wrgtexas.comNot identifiedNot identifiedAug 2, 2021
reconservices.comNot identifiedNot identifiedJul 28, 2021
uptownbakers.comNot identifiedNot identifiedJul 27, 2021

Showing the 20 most recent of 21. Browse recent data breaches for more.

Payload.bin leak site

The address we've seen Payload.bin publish victims from. Any .onion address needs the Tor Browser.

  • vbmisqjshn4yblehk2vbnil53tlqklxsdaztgphcilto3vdj4geao5qd.onion

Payload.bin questions

Is Payload.bin still active?

Not for over a year. The last victim we recorded was January 1, 2022. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has Payload.bin claimed?

Payload.bin has named 21 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Payload.bin first appear?

The first victim we recorded for Payload.bin was posted on July 27, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.

Has Payload.bin already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.