
Trigona
Data as of August 16, 2026.
Credential exposure before the attack
7.7% of Trigona victims whose domain we can identify (4 of 52) had employee credentials leak in the 12 months before Trigona named them as a victim.
We don't know whether any of these credentials were how Trigona gained initial access.
What industries Trigona targets
Sector identified for 34 of 52 victims.
| Healthcare | 8 | |
| Construction | 8 | |
| Financial Services | 5 | |
| Manufacturing | 4 | |
| Logistics | 2 | |
| Telecommunications | 2 | |
| Technology | 2 | |
| Education | 1 |
Where the victims are located
Country identified for 21 of 52 victims.
| Australia | 4 | |
| United Kingdom | 3 | |
| Indonesia | 3 | |
| Italy | 2 | |
| Spain | 2 | |
| Mexico | 2 | |
| Brazil | 1 | |
| Argentina | 1 |
Most recent Trigona victims
| Victim | Sector | Country | Posted |
|---|---|---|---|
| Claro claro.com | Telecommunications | Not identified | Apr 3, 2024 |
| ATMCo atmco.net | Not identified | Not identified | Mar 18, 2024 |
| Bwizer bwizer.com | Healthcare | Not identified | Mar 18, 2024 |
| Indoarsip indoarsip.co.id | Not identified | Indonesia | Mar 18, 2024 |
| Dinamic Oil dinamicoil.com | Not identified | Italy | Feb 29, 2024 |
| Pension Alemana hostalalemana.com | Not identified | Not identified | Feb 29, 2024 |
| Hostal Arriazu hostalarriazu.com | Not identified | Not identified | Feb 29, 2024 |
| Hostal Espoz y Mina hostalespozymina.com | Not identified | Not identified | Feb 29, 2024 |
| Hotel Avenida hotelavenidapalace.pt | Hospitality | Portugal | Feb 29, 2024 |
| America Movil americamovil.com | Telecommunications | Mexico | Feb 15, 2024 |
| Falco falco.com | Manufacturing | Mexico | Feb 15, 2024 |
| Alconex alconex.com | Not identified | Not identified | Oct 16, 2023 |
| fpz.de | Not identified | Germany | Oct 13, 2023 |
| cascadefamily.com | Healthcare | Not identified | Oct 2, 2023 |
| Chait chaitco.com | Construction | Not identified | Sep 21, 2023 |
| Portesa portesa.es | Not identified | Spain | Sep 21, 2023 |
| Grupo Boreal grupoboreal.com.ar | Healthcare | Argentina | Sep 19, 2023 |
| Steelforce steelforce.eu | Logistics | Not identified | Sep 15, 2023 |
| Aria Care Partners ariacarepartners.com | Healthcare | Not identified | Sep 6, 2023 |
| Cazalys cazalys.com.au | Not identified | Australia | Sep 6, 2023 |
Showing the 20 most recent of 52. Browse recent data breaches for more.
Trigona leak sites
Addresses we've seen Trigona publish victims from. Any .onion address needs the Tor Browser.
krsbhaxbki6jr4zvwblvkaqzjkircj7cxf46qt3na5o5sj2hpikbupqd.oniontrigonax2zb3fw34rbaap4cqep76zofxs53zakrdgcxzq6xzt24l5lqd.onion6n5tfadusp4sarzuxntz34q4ohspiaya2mc6aw6uhlusfqfsdomavyyd.onionzp6la4xdki3irsenq3t7z7pu2nnaktqgob6aizlzjkdiyw6azjeuhzqd.onionmedusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onionrhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onionaeey7hxzgl6zowiwhteo5xjbf6sb36tkbn5hptykgmbsjrbiygv4c4id.onion
Trigona questions
Is Trigona still active?
Not for over a year. The last victim we recorded was April 3, 2024. The leak site has published nothing since, though the data it already leaked is still out there.
How many victims has Trigona claimed?
Trigona has named 52 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.
When did Trigona first appear?
The first victim we recorded for Trigona was posted on January 22, 2023. That's when the group entered our collection, which isn't necessarily when it started operating.
Which sectors does Trigona target?
Healthcare accounts for the most victims we can classify, with 8. Construction follows at 8. We could identify a sector for 34 of 52 victims, so treat this as the shape of the targeting rather than a full census.
Has Trigona already got your credentials?
Check whether your employees' logins have leaked on the dark web before they're exploited.
Check your exposure →Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.