Bonacigroup is a relatively minor ransomware operation that emerged in October 2021 with an apparent focus on financially motivated cybercrime activities. Based on available public documentation, the group has maintained a limited operational scope with only three documented victims to date. The group appears to specifically target the legal sector, with their known activities concentrated primarily in the United Kingdom, suggesting either a regional focus or specialized knowledge of legal industry vulnerabilities. Due to the limited number of documented attacks and the group's relatively recent emergence, there is insufficient public reporting from major cybersecurity firms or law enforcement agencies to establish definitive details about their attack methodology, initial access vectors, or specific tools and techniques employed. No major high-profile campaigns or significant ransoms have been publicly attributed to Bonacigroup, and there are no documented law enforcement actions specifically targeting this operation. The current operational status of Bonacigroup remains unclear given the sparse public documentation, though the limited victim count and narrow targeting focus suggest they operate as a smaller-scale ransomware group rather than a major threat actor. The group has been linked to 3 public disclosures across our corpus. First observed on a leak site on October 4, 2021; most recent post December 6, 2021. The operation is currently inactive.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.