
Snatch
Data as of August 16, 2026.
Credential exposure before the attack
34.9% of Snatch victims whose domain we can identify (51 of 146) had employee credentials leak in the 12 months before Snatch named them as a victim.
We don't know whether any of these credentials were how Snatch gained initial access.
What industries Snatch targets
Sector identified for 63 of 146 victims.
| Healthcare | 12 | |
| Manufacturing | 10 | |
| Education | 9 | |
| Financial Services | 8 | |
| Technology | 7 | |
| Government | 3 | |
| Retail | 3 | |
| Construction | 3 |
Where the victims are located
Country identified for 34 of 146 victims.
| United Kingdom | 8 | |
| United States | 7 | |
| Canada | 4 | |
| France | 3 | |
| China | 2 | |
| Italy | 2 | |
| Malaysia | 1 | |
| Turkey | 1 |
Most recent Snatch victims
| Victim | Sector | Country | Posted |
|---|---|---|---|
| Miki miki.co.uk | Not identified | United Kingdom | Mar 29, 2024 |
| Butler, Lavanceau & Sober blscpafirm.com | Financial Services | Not identified | Mar 25, 2024 |
| Seven Seas Group sevenseasgroup.com | Not identified | Not identified | Mar 8, 2024 |
| Frencken Group frenckengroup.com | Healthcare | Not identified | Mar 4, 2024 |
| HSPG & Associates hspgcpas.com | Financial Services | Not identified | Mar 4, 2024 |
| Malabar Gold & Diamonds malabargoldanddiamonds.com | Retail | Not identified | Feb 5, 2024 |
| Museum of Natural Science museumfuernaturkunde.berlin | Not identified | Not identified | Dec 27, 2023 |
| Tyson tysonfoods.com | Not identified | Not identified | Dec 27, 2023 |
| Weidmuller weidmuller.com | Manufacturing | Not identified | Dec 27, 2023 |
| Kraft Heinz kraftheinzcompany.com | Manufacturing | United States | Dec 18, 2023 |
| Spaulding spauldingclinical.com | Not identified | Not identified | Dec 18, 2023 |
| Alvimedica alvimedica.com | Manufacturing | Not identified | Nov 30, 2023 |
| The Canadian Psychological Association (CPA) cpa.ca | Not identified | Canada | Nov 30, 2023 |
| Hunt Guillot & Associates hga-llc.com | Not identified | Not identified | Nov 30, 2023 |
| Jerry Pate jerrypate.com | Not identified | Not identified | Nov 30, 2023 |
| kologik.com | Government | Not identified | Nov 17, 2023 |
| mediafaxgroup.ro | Not identified | Romania | Nov 17, 2023 |
| montytech.net | Education | Not identified | Nov 17, 2023 |
| museumfuernaturkunde.berlin | Not identified | Not identified | Nov 17, 2023 |
| port.mv | Not identified | Not identified | Nov 17, 2023 |
Showing the 20 most recent of 146. Browse recent data breaches for more.
Snatch leak sites
Addresses we've seen Snatch publish victims from. Any .onion address needs the Tor Browser.
hl66646wtlp2naoqnhattngigjp5palgqmbwixepcjyq5i534acgqyad.onioncloudfsnbg.ccsnatchteam.ccfilesnatchcloud.ccalphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onionstniiomyjliimcgkvdszvgen3eaaoz55hreqqx6o77yvmpwt7gklffqd.onionbasemmnnqwxevlymli5bs36o5ynti55xojzvn246spahniugwkff2pad.onionfilesnatchcloud.top
Snatch questions
Is Snatch still active?
Not for over a year. The last victim we recorded was March 29, 2024. The leak site has published nothing since, though the data it already leaked is still out there.
How many victims has Snatch claimed?
Snatch has named 146 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did Snatch first appear?
The first victim we recorded for Snatch was posted on November 21, 2021. That's when the group entered our collection, which isn't necessarily when it started operating.
Which sectors does Snatch target?
Healthcare accounts for the most victims we can classify, with 12. Manufacturing follows at 10. We could identify a sector for 63 of 146 victims, so treat this as the shape of the targeting rather than a full census.
Has Snatch already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.