Quantum

Dark since December 9, 2022
61 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Oct 2021 first victim we recorded
Dec 9, 2022 most recent victim posted
16 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

21.3% of Quantum victims whose domain we can identify (13 of 61) had employee credentials leak in the 12 months before Quantum named them as a victim.

We don't know whether any of these credentials were how Quantum gained initial access.

What industries Quantum targets

Sector identified for 16 of 61 victims.

Manufacturing7
Financial Services3
Construction2
Healthcare1
Legal1
Education1
Energy1

Where the victims are located

Country identified for 13 of 61 victims.

Canada3
United Kingdom3
Australia2
United States2
Italy1
Netherlands1
China1

Most recent Quantum victims

VictimSectorCountryPosted
acquarius.giFinancial ServicesNot identifiedDec 9, 2022
ahtwindows.comEnergyNot identifiedDec 9, 2022
chemiflex.comManufacturingNot identifiedDec 9, 2022
orotexus.comNot identifiedNot identifiedDec 9, 2022
pilenpak.comManufacturingNot identifiedDec 9, 2022
radicalmotorsport.comManufacturingUnited KingdomDec 9, 2022
capitalpower.comNot identifiedCanadaNov 2, 2022
libertypultrusions.comManufacturingNot identifiedOct 21, 2022
rblt.comFinancial ServicesNot identifiedOct 19, 2022
iad.gob.doNot identifiedNot identifiedSep 2, 2022
moscone.comNot identifiedNot identifiedSep 2, 2022
mmsslaw.comLegalNot identifiedAug 24, 2022
shawandslavsky.comNot identifiedNot identifiedAug 19, 2022
freyrsolutions.comNot identifiedNot identifiedAug 9, 2022
beesense-sys.comManufacturingNot identifiedAug 5, 2022
liftow.comNot identifiedNot identifiedAug 5, 2022
autohaus.co.ukNot identifiedUnited KingdomJul 19, 2022
broshuis.comNot identifiedNot identifiedJul 19, 2022
delonhampton.comConstructionUnited StatesJul 19, 2022
zeusscientific.comNot identifiedNot identifiedJul 15, 2022

Showing the 20 most recent of 61. Browse recent data breaches for more.

Quantum leak sites

Addresses we've seen Quantum publish victims from. Any .onion address needs the Tor Browser.

  • quantum445bh3gzuyilxdzs5xdepf3b7lkcupswvkryf3n7hgzpxebid.onion
  • quantum445bh3gzuyilxdzs5xdepf3b7lkcupswvkryf3n7hgzpxebid.onion.ws
  • bi7v6o5djhfji22usugjzpk26nvvwugaubrf3yypyvmkzw7su2nad5id.onion
  • 6kkjbpmqavf2nvs33furf3hywg2z4e4zrnwnmzegcpq4atfyp3jilnid.onion
  • q45frho6hatxtx7qxjytt4cswinakvc2h6iag65jlsaws32xdzz47kyd.onion
  • rrmywkltwjpntybqj7migd5ibdzzxulnhgndb6dnoe6unlljslqb7lid.onion
  • 3uzycwcxrccpvrwx43mpr3gxwcqqgu4x72kedws6zuolp45gopjrzqyd.onion
  • fjlprvuqzs6h4ielcdkmof5nju3ent7c34esaptm7677xono7osvp5yd.onion
  • b2rt3dmb62jo62e2rr5rfrpyomka477tjkcni2fsamjd3wksolae5wqd.onion
  • dblgdn4manmaiewnsqa3vgm26v7ujtx75wtev5pyfmtpww4ofqrqpiid.onion
  • 275dg33wjetp6arghjtp3d7265nsknx2heho5n6bqioy2ehl7c3i3iyd.onion
  • www.sendspace.com
  • oyjydoka32xa24doeymhq4thoibxqdd7i7hnngojpycd74frggkvhyyd.onion
  • bfdwhgjey6xb25e6pc6i7upnswh4znqwwnmlmgzapiwfmt7ugzcwvyyd.onion
  • k2j6llaw66bvlgxcy67uj2prdqqzbl7aj46wab4mpdyizpmati55kfad.onion
  • 2k5qdebrbzv2uj2xz25f53bhjyqgmv2vixyy7p3vaeeb2bqz6jhnalad.onion

Quantum questions

Is Quantum still active?

Not for over a year. The last victim we recorded was December 9, 2022. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has Quantum claimed?

Quantum has named 61 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Quantum first appear?

The first victim we recorded for Quantum was posted on October 13, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Quantum target?

Manufacturing accounts for the most victims we can classify, with 7. Financial Services follows at 3. We could identify a sector for 16 of 61 victims, so treat this as the shape of the targeting rather than a full census.

Has Quantum already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.