REvil

Dark since November 29, 2022
249 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Oct 2021 first victim we recorded
Nov 29, 2022 most recent victim posted
8 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

81.5% of REvil victims whose domain we can identify (203 of 249) had employee credentials leak in the 12 months before REvil named them as a victim.

We don't know whether any of these credentials were how REvil gained initial access.

What industries REvil targets

Sector identified for 5 of 249 victims.

Healthcare2
Education1
Manufacturing1
Agriculture1

Where the victims are located

Country identified for 54 of 249 victims.

Australia8
United Kingdom8
Germany7
Brazil4
Canada3
United States2
Italy2
Austria2

Most recent REvil victims

VictimSectorCountryPosted
kusd.eduEducationNot identifiedNov 29, 2022
sunknowledge.comHealthcareNot identifiedNov 29, 2022
medibank.com.auNot identifiedAustraliaNov 8, 2022
midea-group.comNot identifiedNot identifiedSep 1, 2022
doosan.comNot identifiedSouth KoreaAug 3, 2022
omniactives.comNot identifiedNot identifiedJul 26, 2022
optiproerp.comNot identifiedNot identifiedJul 26, 2022
ludwig-freytag.deNot identifiedGermanyMay 13, 2022
unicity.comNot identifiedNot identifiedMay 4, 2022
oil-india.comNot identifiedNot identifiedApr 24, 2022
stratford.eduHealthcareNot identifiedApr 24, 2022
visotec.comNot identifiedNot identifiedApr 24, 2022
pptep.comNot identifiedNot identifiedOct 14, 2021
inkafarma.com.peNot identifiedPeruOct 11, 2021
4datanet.comNot identifiedNot identifiedOct 5, 2021
acer.comNot identifiedNot identifiedOct 5, 2021
actuariesandassociates.comNot identifiedNot identifiedOct 5, 2021
adif.esNot identifiedSpainOct 5, 2021
agile.propertyNot identifiedNot identifiedOct 5, 2021
agromartgroup.comNot identifiedNot identifiedOct 5, 2021

Showing the 20 most recent of 249. Browse recent data breaches for more.

REvil leak sites

Addresses we've seen REvil publish victims from. Any .onion address needs the Tor Browser.

  • dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46qyd.onion
  • blogxxu75w63ujqarv476otld7cyjkq4yoswzt4ijadkjwvg3vrvd5yd.onion
  • cloudfsnbg.cc
  • 54xj22qsftuzs6bhcistgz27reblgijdjggkgb3fdhfgl3ghkmzk7dad.onion
  • 2wub3njb7zvmnn6xohbuizjcbvy4w5dvlb4puesry3rrl6gx4452ezid.onion
  • e7a2uvl3jp2nn3gawdlla36tcfuwu2n5gmovbxvoqqd6rsirh3kvm4id.onion
  • ttn4gqpgvyy6tuezexxhwiukmm2t6zzawj6p3w3jprve36f43zxr24qd.onion
  • fsgwyl2xd2h5s43er7epr6vuqu5eddmmtgp6cq7khmkoe3ba4d37w7ad.onion

REvil questions

Is REvil still active?

Not for over a year. The last victim we recorded was November 29, 2022. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has REvil claimed?

REvil has named 249 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did REvil first appear?

The first victim we recorded for REvil was posted on October 5, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does REvil target?

Healthcare accounts for the most victims we can classify, with 2. Education follows at 1. We could identify a sector for 5 of 249 victims, so treat this as the shape of the targeting rather than a full census.

Has REvil already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.