Donut Leaks is a data-extortion group active since 2022 known for double-extortion operations with custom ransomware encryptor.
Analyst brief
Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, initially linked to multiple RaaS operations before launching an independent extortion platform. The group targets large industrial and critical infrastructure entities, such as Greece's DESFA gas operator and Continental. Key TTPs include deployment of a custom ransomware encryptor, double-extortion (data exfiltration plus encryption), and leveraging their dedicated leak site for pressure. Defenders should prioritize network segmentation, offline backups, and Data Loss Prevention (DLP) controls to mitigate data exfiltration risks.
donutleaks
crime
Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.