Pewcrypt is an obscure ransomware group that first emerged in November 2018, appearing to be financially motivated based on typical ransomware operations. The group's origin and affiliations remain largely unknown due to limited public documentation and intelligence reporting from major security firms and law enforcement agencies. With only one documented victim since their emergence, pewcrypt appears to operate with very limited scope and capability, primarily targeting government facilities within the United States, though their specific attack methodology, tools, and encryption techniques have not been publicly documented by reputable security researchers or agencies such as CISA, FBI, or Mandiant. No notable high-profile campaigns, significant ransom demands, or law enforcement actions have been publicly reported against this group. The current operational status of pewcrypt remains unclear, though their extremely limited victim count and lack of recent public reporting suggests they may have ceased operations, dissolved, or remain dormant with minimal impact on the threat landscape. The group has been linked to 1 public disclosures across our corpus. First observed on a leak site on November 1, 2018. The operation is currently inactive.
Sector and geography
This disclosure adds to ransomware activity in the Government Facilities sector, which has 84 disclosures indexed across all operators we track. Geographically, North Bend (and PD) is reported in United States, a country with 7,392 ransomware disclosures in our corpus.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.