Sinobi

Quiet since May 11, 2026
258 victims named on the leak site
0 in the last 30 days
241 in the last 12 months
Jul 2025 first victim we recorded
May 11, 2026 most recent victim posted
7 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

17.8% of Sinobi victims whose domain we can identify (46 of 258) had employee credentials leak in the 12 months before Sinobi named them as a victim.

We don't know whether any of these credentials were how Sinobi gained initial access.

What industries Sinobi targets

Sector identified for 202 of 258 victims.

Manufacturing53
Healthcare29
Construction23
Financial Services21
Technology13
Government8
Hospitality8
Education8

Where the victims are located

Country identified for 245 of 258 victims.

United States198
India13
United Kingdom6
Canada5
France5
Brazil3
Denmark2
Italy2

Most recent Sinobi victims

VictimSectorCountryPosted
NeuroTrials Research neurotrials.comNot identifiedUnited StatesMay 11, 2026
Bay State Land Services baystatelandservices.comNot identifiedUnited StatesMay 6, 2026
Celeris Networks celerisnetworks.comTelecommunicationsUnited StatesMay 6, 2026
Positiwise Software positiwise.comTechnologyIndiaMay 6, 2026
Scales and Associates scalesassoc.comConstructionUnited StatesMay 6, 2026
UNRE AI unre.comConstructionChinaMay 6, 2026
Elgi Electric and Industries elgielectric.comManufacturingIndiaMar 19, 2026
OurAMS ourams.comFinancial ServicesUnited StatesMar 19, 2026
Eco Sound Builders ecosoundbuilders.comConstructionUnited StatesMar 18, 2026
Interpack Northwest interpacknw.comLogisticsUnited StatesMar 18, 2026
McAfee Tool and Die mcafeetool.comManufacturingUnited StatesMar 18, 2026
Summa Energy summa.energyEnergyUnited StatesMar 18, 2026
Teco tecollc.netManufacturingUnited StatesMar 18, 2026
Electriduct electriduct.comEnergyUnited StatesFeb 20, 2026
Gentegra gentegra.comFinancial ServicesUnited StatesFeb 20, 2026
GrayMatter Software Services graymatter.co.inTechnologyIndiaFeb 20, 2026
IbleSoft iblesoft.comTechnologyIndiaFeb 20, 2026
Mayfair Hotels International mayfairhotels.comHospitalitySingaporeFeb 20, 2026
Saltech Systems saltechsystems.comNot identifiedUnited StatesFeb 20, 2026
Halcyon Technologies halcyontek.comTechnologyUnited StatesFeb 16, 2026

Showing the 20 most recent of 258. Browse recent data breaches for more.

Sinobi leak sites

Addresses we've seen Sinobi publish victims from. Any .onion address needs the Tor Browser.

  • sinobi6ftrg27d6g4sjdt65malds6cfptlnjyw52rskakqjda6uvb7yd.onion
  • sinobi6ywgmmvg2gj2yygkb2hxbimaxpqkyk27wti5zjwhfcldhackid.onion
  • sinobi6rlec6f2bgn6rd72xo7hvds4a5ajiu2if4oub2sut7fg3gomqd.onion
  • sinobi23i75c3znmqqxxyuzqvhxnjsar7actgvc4nqeuhgcn5yvz3zqd.onion
  • sinobi7l3wet3uqn4cagjiessuomv75aw3bvgah4jpj43od7xndb7kad.onion
  • sinobia6mw6ht2wcdjphessyzpy7ph2y4dyqbd74bgobgju4ybytmkqd.onion
  • sinobi7sukclb3ygtorysbtrodgdbnrmgbhov45rwzipubbzhiu5jvqd.onion

Sinobi questions

Is Sinobi still active?

It's gone quiet. The last victim we recorded was May 11, 2026, and nothing has appeared since. Groups do go quiet and come back, so we're still watching.

How many victims has Sinobi claimed?

Sinobi has named 258 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files. 241 of them were posted in the last 12 months.

When did Sinobi first appear?

The first victim we recorded for Sinobi was posted on July 7, 2025. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Sinobi target?

Manufacturing accounts for the most victims we can classify, with 53. Healthcare follows at 29. We could identify a sector for 202 of 258 victims, so treat this as the shape of the targeting rather than a full census.

Has Sinobi already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.