Minteye is a ransomware group that emerged in October 2025, specializing in data exfiltration and encryption to extort victims for financial gain. They operate a data leak site to publicize stolen information and pressure organizations into paying ransoms, employing a double extortion tactic to maximize impact.
Key insights
•Utilizes credentials obtained from infostealer malware or weak authentication for initial access.
•Employs data encryption along with threats of public disclosure as a means of extortion.
•Has a dedicated onion-based data leak site for listing victims and leaking exfiltrated data.
•Claims responsibility for cyberattacks to increase pressure on victims.
•Targets a wide range of sectors, leading to significant data breaches and operational disruptions.