DataCarry is a double-extortion ransomware operation targeting insurance and healthcare sectors.
Analyst brief
DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating under a criminal model. It targets victims in insurance, healthcare, aerospace, legal, and retail sectors across at least six countries. The group employs a double-extortion TTP, encrypting and stealing data, and leverages a Tor-hosted leak portal to pressure victims. Defenders should focus on securing initial access vectors, especially remote desktop services, and strengthen Data Loss Prevention (DLP) measures to mitigate data theft.
datacarry
crime
DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.