NoEscape is a financially motivated ransomware group that emerged in mid-2023, rapidly establishing itself as a significant threat with 249 documented victims across multiple sectors. The group's origins and affiliations remain largely undocumented by major security agencies, though their operational patterns suggest they likely operate independently rather than as a Ransomware-as-a-Service model. NoEscape demonstrates sophisticated attack methodologies targeting critical infrastructure and essential services, with their campaigns showing a clear preference for high-value targets in government, healthcare, education, finance, and manufacturing sectors across developed nations, particularly focusing on the United States, United Kingdom, Italy, France, and Australia. The group's rapid victim accumulation rate since their June 2023 emergence indicates an aggressive operational tempo and effective attack capabilities, though specific technical details about their initial access vectors, encryption methods, and extortion tactics have not been extensively documented in public threat intelligence reports from major security agencies. As of current intelligence assessments, NoEscape appears to remain an active threat with no documented law enforcement disruptions or confirmed rebranding activities. The group has been linked to 249 public disclosures across our corpus. First observed on a leak site on June 12, 2023; most recent post December 4, 2023. The operation is currently inactive.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.