Ransomware victim disclosure
← All victimsPaid Victim F9CF4B639CAC1B18
Claimed by AuditTeam · listed 3 days ago
Status timeline
- ListedSep 13, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileNo identifying information available. The victim is recorded only by an opaque identifier (Paid Victim F9CF4B639CAC1B18) and no clearnet site was found.
Attack summary
Severity: low — The post announces case closure and data purge with no proof of exfiltration published, no data inventory disclosed, and no operational impact stated. This appears to be a resolution notice rather than a live threat disclosure.AuditTeam claims to have reached a cooperation agreement with the victim and states that all acquired data has been purged from their servers and that enterprise security remediation has been verified. No ransom demand or ongoing threat is indicated.
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's site[[ DATA EXPOSURE LOGS ]](http://6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion/) # AUDIT ENTITY: [ COOPERATION REACHED ] // ALL ACQUIRED DATA HAS BEEN PURGED FROM OUR SERVERS // ENTERPRISE SECURITY REMEDIATION VERIFIED // ENTITY HAS DEMONSTRATED HIGH SECURITY COMPLIANCE // NO FURTHER ACTION REQUIRED — CASE CLOSED
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

