
RAGroup
Data as of August 16, 2026.
Credential exposure before the attack
23.3% of RAGroup victims whose domain we can identify (14 of 60) had employee credentials leak in the 12 months before RAGroup named them as a victim.
We don't know whether any of these credentials were how RAGroup gained initial access.
What industries RAGroup targets
Sector identified for 33 of 60 victims.
| Financial Services | 6 | |
| Logistics | 6 | |
| Healthcare | 5 | |
| Manufacturing | 4 | |
| Construction | 3 | |
| Energy | 2 | |
| Retail | 2 | |
| Automotive | 2 |
Where the victims are located
Country identified for 25 of 60 victims.
| Germany | 9 | |
| Taiwan | 3 | |
| United Kingdom | 2 | |
| Italy | 2 | |
| South Korea | 2 | |
| Thailand | 1 | |
| Poland | 1 | |
| Singapore | 1 |
Most recent RAGroup victims
| Victim | Sector | Country | Posted |
|---|---|---|---|
| Ire-Omba SpA ire-omba.it | Not identified | Italy | Dec 29, 2024 |
| die STEG steg.de | Not identified | Germany | Dec 29, 2024 |
| Watertown High School watertownps.org | Education | Not identified | Dec 29, 2024 |
| Compass Communications compass.net.nz | Telecommunications | New Zealand | Dec 13, 2024 |
| NTrust ntrustinfotech.com | Financial Services | Not identified | Dec 5, 2024 |
| Contrack FM contrackfm.com | Not identified | Not identified | Nov 28, 2024 |
| Ventana Micro Systems ventanamicro.com | Not identified | Not identified | Nov 28, 2024 |
| Gulf Energy Maritime gemships.com | Energy | Not identified | Nov 25, 2024 |
| Orange County Pathology Medical Group ocpathology.com | Healthcare | Not identified | Nov 13, 2024 |
| SK Gas skgas.co.kr | Energy | South Korea | Nov 13, 2024 |
| Bullonerie Galvit bulloneriegalvit.it | Logistics | Italy | Nov 1, 2024 |
| P+B Team Aircargo Service pbteam.de | Logistics | Germany | Oct 24, 2024 |
| Prince Pipes princepipes.com | Manufacturing | Not identified | Oct 24, 2024 |
| Digital Engineering digitalengineering.com | Manufacturing | Not identified | Oct 16, 2024 |
| Matouk Bassiouny matoukbassiouny.com | Legal | Not identified | Oct 16, 2024 |
| The ASCENT Group theascent-group.com | Not identified | Not identified | Jul 29, 2024 |
| Kusum Group kusum.com | Not identified | Not identified | Jul 25, 2024 |
| Melchers Singapore melchers.com.sg | Not identified | Singapore | Jul 25, 2024 |
| The Lutheran Foundation thelutheranfoundation.org | Not identified | Not identified | Jul 25, 2024 |
| Main Wein main-wein.com | Not identified | Not identified | Apr 25, 2024 |
Showing the 20 most recent of 60. Browse recent data breaches for more.
RAGroup leak sites
Addresses we've seen RAGroup publish victims from. Any .onion address needs the Tor Browser.
raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.oniongofile.iopa32ymaeu62yo5th5mraikgw5fcvznnsiiwti42carjliarodltmqcqd.onionraworlddecssyq43oim3hxhc5oxvlbaxuj73xbz2pbbowso3l4kn27qd.onionhkpomcx622gnqp2qhenv4ceyrhwvld3zwogr4mnkdeudq2txf55keoad.onion
RAGroup questions
Is RAGroup still active?
Not for over a year. The last victim we recorded was December 29, 2024. The leak site has published nothing since, though the data it already leaked is still out there.
How many victims has RAGroup claimed?
RAGroup has named 60 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did RAGroup first appear?
The first victim we recorded for RAGroup was posted on April 3, 2023. That's when the group entered our collection, which isn't necessarily when it started operating.
Which sectors does RAGroup target?
Financial Services accounts for the most victims we can classify, with 6. Logistics follows at 6. We could identify a sector for 33 of 60 victims, so treat this as the shape of the targeting rather than a full census.
Has RAGroup already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.