Shadow is a newly observed ransomware group that first emerged in February 2026 with limited documented activity, having only one publicly confirmed victim to date. Given the recent emergence and minimal attack footprint, the group's primary motivation appears to be financial, though their operational scope and strategic objectives remain unclear. The group's country of origin, potential affiliations with established ransomware operations, and whether they operate as an independent entity or utilize a Ransomware-as-a-Service model have not been documented by security researchers or law enforcement agencies. Due to the limited number of confirmed attacks, specific details regarding Shadow's attack methodology, initial access vectors, encryption techniques, or use of double extortion tactics have not been publicly analyzed or reported by major cybersecurity firms or government agencies. No notable high-profile campaigns, significant ransom demands, or law enforcement actions have been associated with this group. Shadow's current operational status remains active as of early 2026, though their limited activity makes it difficult to assess their long-term viability or potential for expansion. The group has been linked to 1 public disclosures across our corpus. First observed on a leak site on February 25, 2026. The operation is currently active.
Sector and geography
This disclosure adds to ransomware activity in the Not Found sector, which has 4,859 disclosures indexed across all operators we track. Geographically, UMSA is reported in Bolivia.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.