Crime
Vexy Ransomware
vexy
ransomware.liverefreshed 2026-09-15
sigil
Last 30 days
last seen 4 d ago
12
dispatches
12
victims
0
CVEs seen
seen against India · Brazil · Argentina · Ecuador · Mexico
sectors Technology · Manufacturing · Other · Retail & E-Commerce · Hospitality
What changed
- todayvictimsvictim count 9 → 12 (+3)
- 7 d agovictimsvictim count 7 → 9 (+2)
- 7 d agonew alias1 new alias: vexy
Analyst brief
Vexy Ransomware is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
assessed originobserved targets (7)
Observed targets
countries · 7
IndiaBrazilUnited KingdomArgentinaMexicoUnited StatesEcuador
sectors · 6
TechnologyOtherRetail & E-CommerceManufacturingTransportationHospitality
as stated by MISP galaxy / ransomware.live — not inferred
- Victims observed
- 12
- First observed
- Last observed on leak site
- Velocity
- ≈ 12.0 victims / month
- lifetime average, first to last observed
leak-site listings via ransomware.live — a quiet site is not a dead crew
Early access
Track Vexy Ransomware on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.
bot-protected