RALord

Dark since April 28, 2025
27 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Mar 2025 first victim we recorded
Apr 28, 2025 most recent victim posted
3 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

51.9% of RALord victims whose domain we can identify (14 of 27) had employee credentials leak in the 12 months before RALord named them as a victim.

We don't know whether any of these credentials were how RALord gained initial access.

What industries RALord targets

Sector identified for 18 of 27 victims.

Manufacturing4
Education2
Construction2
Non-profit2
Telecommunications2
Government2
Hospitality1
Retail1

Where the victims are located

Country identified for 18 of 27 victims.

France3
Brazil2
Mexico2
Argentina1
Taiwan1
United States1
Spain1
Egypt1

Most recent RALord victims

VictimSectorCountryPosted
Diallog Telecommunications diallog.comTelecommunicationsCanadaApr 28, 2025
Helukabel helukabel.deManufacturingGermanyApr 24, 2025
Rawafid Industrial rawafid.saConstructionSaudi ArabiaApr 24, 2025
Agromate agromate.com.myManufacturingMalaysiaApr 22, 2025
Bettanin Industrial bettininformatica.com.brTechnologyBrazilApr 21, 2025
Bio-Clima Service bioclimaservice.itNot identifiedItalyApr 17, 2025
ARRCO arrco-air.comNot identifiedNorwayApr 16, 2025
Apunto Telecom apuntotelcom.comTelecommunicationsSpainApr 15, 2025
Aeronautical Radio arinc.comGovernmentNot identifiedApr 15, 2025
Faculty of Engineering, Cairo University cu.edu.egEducationEgyptApr 15, 2025
Al-Hejailan Group hejailan.comManufacturingNot identifiedApr 15, 2025
Instituto Nacional de Estadística y Geografía (INEGI) inegi.org.mxGovernmentMexicoApr 15, 2025
Viavi Solutions jdsu.comNot identifiedNot identifiedApr 15, 2025
Lutron Electronics lutron.comManufacturingNot identifiedApr 15, 2025
Newhotel Software newhotel.comNot identifiedNot identifiedApr 15, 2025
Remote Sensing Systems remss.comNot identifiedNot identifiedApr 15, 2025
Rajasthan Youth Association (RYA) Book Bank ryabookbank.comFinancial ServicesNot identifiedApr 15, 2025
County of San Bernardino sbcounty.govNot identifiedNot identifiedApr 15, 2025
Poder Judicial del Estado de Oaxaca tribunaloaxaca.gob.mxNot identifiedMexicoApr 15, 2025
HASBCO hasbco.comRetailUnited StatesApr 11, 2025

Showing the 20 most recent of 27. Browse recent data breaches for more.

RALord leak sites

Addresses we've seen RALord publish victims from. Any .onion address needs the Tor Browser.

  • ralordqe33mpufkpsr6zkdatktlu3t2uei4ught3sitxgtzfmqmbsuyd.onion
  • ralord3htj7v2dkavss2hjzviviwgsf4anfdnihn5qcjl6eb5if3cuqd.onion
  • mega.nz

RALord questions

Is RALord still active?

Not for over a year. The last victim we recorded was April 28, 2025. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has RALord claimed?

RALord has named 27 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did RALord first appear?

The first victim we recorded for RALord was posted on March 26, 2025. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does RALord target?

Manufacturing accounts for the most victims we can classify, with 4. Education follows at 2. We could identify a sector for 18 of 27 victims, so treat this as the shape of the targeting rather than a full census.

Has RALord already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.