Meow is a relatively new ransomware group that emerged in November 2023, primarily motivated by financial gain through extortion activities targeting organizations across multiple sectors. The group has compromised at least 145 known victims in a short operational timeframe, demonstrating rapid scaling of their criminal enterprise. Based on their targeting patterns, Meow appears to focus heavily on English-speaking countries, with the United States, United Kingdom, and Canada representing their primary victim base, though they have also expanded operations to include targets in Italy and Colombia. The group shows a preference for attacking business services organizations, manufacturing companies, healthcare institutions, and agriculture and food production entities, suggesting they may employ broad-spectrum targeting rather than highly specialized sector focus. Their emergence in late 2023 and the significant victim count achieved in a relatively short period indicates either a sophisticated operation with experienced operators or potential links to existing ransomware ecosystems, though specific details about their attack methodology, initial access vectors, encryption techniques, or data exfiltration practices have not been extensively documented by major threat intelligence sources. Given the recent timeline of their emergence and limited public reporting from established security researchers, detailed technical analysis of their tools, tactics, and procedures remains sparse. The group appears to remain active as of current reporting, though comprehensive law enforcement actions or major disruption efforts have not been publicly documented. The group has been linked to 145 public disclosures across our corpus. First observed on a leak site on November 24, 2023; most recent post November 19, 2024. The operation is currently inactive.
Sector and geography
This disclosure adds to ransomware activity in the Not Found sector, which has 4,859 disclosures indexed across all operators we track. Geographically, La Futura is reported in Italy, a country with 496 ransomware disclosures in our corpus.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.