Ransomware victim disclosure
← All victimsCowans
listed as COWANS.ORG · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileCowans (cowans.org) is an organisation whose public website is currently unavailable, making it impossible to determine its industry, location, or scale from available sources. The domain suggests it may be a non-profit, association, or professional services entity given the .org TLD. No further verifiable information can be confirmed at this time.
Attack summary
Severity: medium — Data is listed as published by Clop, a group known for mass exfiltration campaigns, but the leak post provides no readable content, no data inventory, and no proof files are enumerated; severity is elevated above low due to Clop's established pattern of large-scale data theft, but cannot be rated high or critical without evidence of regulated or sensitive data.Clop ransomware group claims an attack against cowans.org and lists the disclosure status as data_published, suggesting data exfiltration has occurred or been published; however, the leak post itself contains no readable content beyond a redirect notice, leaving the nature and scope of the claimed data largely unverifiable.
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

