Ransomware victim disclosure
← All victimsPaid Victim 32373FFB7AF7E725
Claimed by AuditTeam · listed 3 hours ago
Status timeline
- ListedSep 29, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileNo identifying information available. The victim identifier is a generic placeholder (Paid Victim 32373FFB7AF7E725) with no associated public website or disclosed company name.
Attack summary
Severity: low — Post describes case closure and data purge with no proof files, no active data publication, no operational impact, and no extant threat to the victim. This appears to be a resolution notice rather than a genuine disclosure.AuditTeam claims to have reached a cooperation agreement with the victim. The group states that all acquired data has been purged from their servers, enterprise security remediation has been verified, and the case is closed. No ransom demand or data retention threat is evident.
Original description
AI-summarised, not from the leak postN/A I don't have reliable information about a company with this specific identifier. This appears to be an anonymized or coded reference, possibly from a ransomware leak site or threat intelligence feed, rather than a verifiable company name. Without access to real-time threat intelligence databases or the original source associated with this identifier, I cannot provide factual details about its operations, industry, or country.
The leak post
captured from the group's site[[ DATA EXPOSURE LOGS ]](http://6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion/) # AUDIT ENTITY: [ COOPERATION REACHED ] // ALL ACQUIRED DATA HAS BEEN PURGED FROM OUR SERVERS // ENTERPRISE SECURITY REMEDIATION VERIFIED // ENTITY HAS DEMONSTRATED HIGH SECURITY COMPLIANCE // NO FURTHER ACTION REQUIRED — CASE CLOSED
Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

