Funksec is a recently emerged ransomware group first observed in December 2024, operating with apparent financial motivations based on their targeting patterns and victim acquisition approach. The group's origin and potential state affiliations remain unclear due to their recent emergence, though they appear to operate independently rather than as a Ransomware-as-a-Service model based on available intelligence. With 172 documented victims across multiple countries, Funksec has demonstrated a broad targeting approach, primarily focusing on the United States, India, Brazil, Spain, and Israel, with particular emphasis on technology companies, government entities, educational institutions, and business services organizations. The group's attack methodology, encryption techniques, and specific tactics, techniques, and procedures remain largely undocumented by major threat intelligence firms, though their rapid victim acquisition suggests an established operational capability. Given the group's recent discovery in December 2024, there have been no widely reported major campaigns or high-profile incidents that have drawn significant public attention from law enforcement or cybersecurity organizations. Funksec remains active as of early 2025, continuing to target organizations across their established geographic and sectoral preferences. The group has been linked to 172 public disclosures across our corpus. First observed on a leak site on December 4, 2024; most recent post March 18, 2025. The operation is currently inactive.
Sector and geography
This disclosure adds to ransomware activity in the Not Found sector, which has 4,859 disclosures indexed across all operators we track. Geographically, forum-rainbow-rp.forumotion.eu is reported in EU.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.