Ransomware victim disclosure
← All victimsOn***de
Claimed by AuditTeam · listed 4 days ago
Status timeline
- Listed
May 28, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileVictim name 'On***de' is heavily redacted and cannot be reliably identified. No public site or additional context is available to confirm the company's identity, sector, or operations.
Attack summary
Severity: high — Confirmed exfiltration of massive user and order record sets ('millions') suggests PII at scale and significant business data exposure. Staged disclosure with timer adds operational pressure.AuditTeam claims to have exfiltrated millions of user records, order records, and file server data. The group states a complete data archive will be published upon timer expiration, indicating a staged disclosure threat.
Data the group says was taken
AI dossier — extracted from the leak post- user records (millions)
- order records (millions)
- file server data
The leak post
captured from the group's site[[ DATA EXPOSURE LOGS ]](http://6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion/) **[ AUDIT TEAM NOTE ]** Millions of user records, order records, and file server data. [ ACQUIRED DATA ARTIFACTS RESTRICTED ] [ COMPLETE DATA ARCHIVE WILL BE PUBLISHED UPON TIMER EXPIRATION ]
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
