Lorenz is a ransomware group that emerged in January 2020 and operates primarily for financial gain, having claimed approximately 78 victims across multiple sectors. The group's origin and specific affiliations remain largely undocumented by major threat intelligence organizations, though their targeting patterns suggest a focus on English-speaking nations including the United States, United Kingdom, and Australia. Lorenz primarily targets healthcare, finance, automotive, construction, and retail sectors, suggesting they may opportunistically attack organizations with valuable data and limited security resources rather than following a specific geopolitical agenda. While detailed technical analysis of their attack methodology has not been extensively published by major security firms like Mandiant or government agencies such as CISA, the group appears to follow typical ransomware deployment patterns common to financially-motivated cybercriminal organizations. Public documentation of specific high-profile campaigns, notable victims, or significant law enforcement actions against Lorenz remains limited in open-source intelligence reporting. Based on available victim data extending beyond 2020, the group appears to have maintained some level of operational activity, though comprehensive assessments of their current operational status have not been widely published by authoritative sources in the threat intelligence community. The group has been linked to 78 public disclosures across our corpus. First observed on a leak site on January 12, 2020; most recent post December 11, 2023. The operation is currently inactive.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.