RansomHouse is a cybercriminal group active since 2022 known for publishing stolen data on Tor.
Analyst brief
RansomHouse is a cybercriminal group active since early 2022 that publishes allegedly stolen data on their Tor site. It remains unclear whether they conduct the attacks themselves or purchase leaked databases from third parties. The group targets diverse sectors including manufacturing, financial services, and government & defense across the United States, Brazil, Canada, Japan, and Argentina. Defenders should monitor Tor-based leak indicators and focus on network segmentation to mitigate third-party data leak risks.
RansomHouse
activeunknown
This group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear if they conducted the attacks themselves, or if they bought leaked databases from third parties.