Skip to main content

Operator dossier

Global Secret Group is a ransomware operator currently active on public leak sites. Darkfield has indexed 31 public victims claimed by this operator between July 26, 2026 and July 27, 2026. Global Secret Group is a ransomware threat actor first observed in July 2026, with operations consistent with financially motivated cybercrime based on their targeting profile and victim patterns. The group has claimed or been attributed to 28 known victims across a relatively short operational window, suggesting an emerging or actively expanding operation. Given the limited public documentation available from CISA, FBI, Mandiant, or other reputable security research organizations at this time, a comprehensive technical profile cannot be fully established. What is known from available victim and targeting data indicates the group predominantly focuses on organizations in the United States, Canada, Brazil, the United Kingdom, and Cyprus, with a clear sectoral preference for Technology, Retail and E-Commerce, Energy and Utilities, Professional Services, and Financial Services — a targeting pattern broadly consistent with financially motivated ransomware actors seeking high-value data and organizations with both the ability and incentive to pay ransoms. The cross-sector and multi-national targeting pattern may suggest opportunistic intrusion methodology rather than a narrowly scoped, nation-state-aligned operation, though this assessment remains preliminary pending further public disclosure by authoritative sources. As of the time of this writing, Global Secret Group's operational infrastructure, affiliation with any ransomware-as-a-service ecosystem, specific malware tooling, and current active status have not been formally attributed or publicly documented by major threat intelligence authorities, and this profile will require revision as additional intelligence becomes available.

Most-targeted sectors

Most-affected countries

Recent disclosures by Global Secret Group

All 31 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Global Secret Group

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Active ransomware operator

All groups

Global Secret Group

31 victims indexed · first seen 3 days ago · last activity 3 days ago

31
Victims indexed
#143 of 369 tracked operators
<1m
Active period
Jul 2026 → Jul 2026
14
Countries hit
top US · 13

At a glance

Status
active
First seen
3 days ago
Last activity
3 days ago
Primary sector
Technology · 9 hits

About

Global Secret Group is a ransomware threat actor first observed in July 2026, with operations consistent with financially motivated cybercrime based on their targeting profile and victim patterns. The group has claimed or been attributed to 28 known victims across a relatively short operational window, suggesting an emerging or actively expanding operation. Given the limited public documentation available from CISA, FBI, Mandiant, or other reputable security research organizations at this time, a comprehensive technical profile cannot be fully established. What is known from available victim and targeting data indicates the group predominantly focuses on organizations in the United States, Canada, Brazil, the United Kingdom, and Cyprus, with a clear sectoral preference for Technology, Retail and E-Commerce, Energy and Utilities, Professional Services, and Financial Services — a targeting pattern broadly consistent with financially motivated ransomware actors seeking high-value data and organizations with both the ability and incentive to pay ransoms. The cross-sector and multi-national targeting pattern may suggest opportunistic intrusion methodology rather than a narrowly scoped, nation-state-aligned operation, though this assessment remains preliminary pending further public disclosure by authoritative sources. As of the time of this writing, Global Secret Group's operational infrastructure, affiliation with any ransomware-as-a-service ecosystem, specific malware tooling, and current active status have not been formally attributed or publicly documented by major threat intelligence authorities, and this profile will require revision as additional intelligence becomes available.

Timeline

1 months
2026-07-01T00:00:00+00:00 · 28
2026-07-01T00:00:00+00:002026-07-01T00:00:00+00:00

Top countries

🇺🇸 United States
13
🇨🇦 Canada
2
🇧🇷 Brazil
2
🇬🇧 United Kingdom
1
🇨🇾 Cyprus
1
🇦🇪 United Arab Emirates
1
Iraq
1
🇨🇳 China
1

Top sectors

Technology
9
Retail & E-Commerce
5
Energy & Utilities
3
Professional Services
3
Financial Services
3
Manufacturing
2
Healthcare
2
Hospitality
1

MITRE ATT&CK

14 techniques · 7 tactics

Tactics

Initial AccessExecutionDefense EvasionDiscoveryCollectionExfiltrationImpact

Techniques

  • T1190Exploit Public-Facing Application
  • T1566Phishing
  • T1059Command and Scripting Interpreter
  • T1047Windows Management Instrumentation
  • T1562Impair Defenses
  • T1070Indicator Removal
  • T1083File and Directory Discovery
  • T1082System Information Discovery
  • T1057Process Discovery
  • T1074Data Staged
  • T1041Exfiltration Over C2 Channel
  • T1486Data Encrypted for Impact
  • T1490Inhibit System Recovery
  • T1489Service Stop

Recent victims

Loading…

Source

Updated 3 days ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Global Secret Group posts a victim.

Add Global Secret Group to your watchlist — Pro pings you within 5 minutes of any new Global Secret Group leak-site post, Telegram callout, or affiliate-rebrand inference.