SATANLOCK

Dark since July 7, 2025
6 victims named on the leak site
0 in the last 30 days
0 in the last 12 months
Apr 2025 first victim we recorded
Jul 7, 2025 most recent victim posted
2 leak sites tracked

Data as of August 16, 2026.

What industries SATANLOCK targets

Sector identified for 4 of 6 victims.

Education1
Healthcare1
Real Estate1
Telecommunications1

Where the victims are located

Country identified for 2 of 6 victims.

Thailand1
Sweden1

Every SATANLOCK victim

VictimSectorCountryPosted
Fakkwan Wittayakom School fkk.ac.thEducationThailandJul 7, 2025
Klinik Utama DR. Indrajana klinikdrindrajana.comHealthcareNot identifiedJul 7, 2025
Viggiani Bullone Girardi studionotarile.comReal EstateNot identifiedJul 7, 2025
Teligent Telecom teligent.seTelecommunicationsSwedenJul 7, 2025
Tecnologías Zona 2 mspz2.gob.ecNot identifiedNot identifiedApr 24, 2025
Ministry of Public Health of Ecuador mspz2.gob.ecNot identifiedNot identifiedApr 8, 2025

Browse recent data breaches for more.

SATANLOCK leak sites

Addresses we've seen SATANLOCK publish victims from. Any .onion address needs the Tor Browser.

  • tzhwmgguyxrg6q3tu4q3gvopcjynrhw6ryx2bdl5ghisdkyunfua5xyd.onion
  • gofile.io

SATANLOCK questions

Is SATANLOCK still active?

Not for over a year. The last victim we recorded was July 7, 2025. The leak site has published nothing since, though the data it already leaked is still out there.

How many victims has SATANLOCK claimed?

SATANLOCK has named 6 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did SATANLOCK first appear?

The first victim we recorded for SATANLOCK was posted on April 8, 2025. That's when the group entered our collection, which isn't necessarily when it started operating.

Has SATANLOCK already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.