Tommyleaks
Tommyleaks is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Tommyleaks is an active ransomware group known for using double extortion and a public leak site to pressure victims.
Tommyleaks is an active ransomware/extortion group that pressures victims by publishing stolen data on its public leak site. The group primarily targets corporate networks and organizations across various sectors. Their key TTPs include data exfiltration, internal network propagation, ransomware deployment, and double extortion tactics. Defenders should focus on monitoring external-facing services, enhancing network segmentation, enforcing multi-factor authentication, and regularly testing offline backups of critical data.
Tommyleaks is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
Tommyleaks uses double extortion tactics to pressure its victims, which involves publishing stolen data on its public leak site.
Defenders should focus on monitoring external-facing services, enhancing network segmentation, enforcing multi-factor authentication (MFA), and regularly testing offline backups of critical data.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.