Qiulong

Dark since June 25, 2024
7 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Apr 2023 first victim we recorded
Jun 25, 2024 most recent victim posted
2 leak sites tracked

Data as of August 16, 2026.

What industries Qiulong targets

Sector identified for 2 of 7 victims.

Healthcare2

Where the victims are located

Country identified for all 7 victims.

Brazil6
Canada1

Every Qiulong victim

VictimSectorCountryPosted
Concisa concisa.eng.brNot identifiedBrazilJun 25, 2024
Indigo ENT Group indigoent.caNot identifiedCanadaMay 31, 2024
Hominem Clinic hominemclinic.com.brHealthcareBrazilApr 25, 2024
Hospital Escultural hospitalescultural.com.brHealthcareBrazilApr 29, 2023
Dra. Andrea Rechia draandrearechia.com.brNot identifiedBrazilApr 19, 2023
Dr. Lincoln Graca Neto drlincoln.com.brNot identifiedBrazilApr 19, 2023
Rosalvo Automoveis rosalvoautomoveis.com.brNot identifiedBrazilApr 19, 2023

Browse recent data breaches for more.

Qiulong leak sites

Addresses we've seen Qiulong publish victims from. Any .onion address needs the Tor Browser.

  • 62brsjf2w77ihz5paods33cdgqnon54gjns5nmag3hmqv6fcwamtkmad.onion
  • mega.nz

Qiulong questions

Is Qiulong still active?

Not for over a year. The last victim we recorded was June 25, 2024. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has Qiulong claimed?

Qiulong has named 7 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Qiulong first appear?

The first victim we recorded for Qiulong was posted on April 19, 2023. That's when the group entered our collection, which isn't necessarily when it started operating.

Has Qiulong already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.