The ransomware group cry0 emerged in March 2026, using data broker tactics to engage in direct and double extortion. They are known for encrypting victim data while threatening to leak it through a dedicated leak site on TOR networks.
Key insights
•Employs direct and double extortion tactics.
•Utilizes a data leak site accessible via TOR networks.
•Engages in threats to leak stolen information publicly.
•Offers free portions of leaked data to entice compliance.
•Targets a wide array of sectors, including healthcare and education.
We use cookies to improve your experience, analyze traffic, and personalize content. We won't set non-essential cookies until you agree. Privacy Policy