Skip to content
skopnix
← adversaries
Crime

Vexy Ransomware

vexy
ransomware.liverefreshed 2026-09-15

sigil

Last 30 days

last seen 4 d ago

12
dispatches
12
victims
0
CVEs seen

seen against India · Brazil · Argentina · Ecuador · Mexico

sectors Technology · Manufacturing · Other · Retail & E-Commerce · Hospitality

What changed
  • todayvictimsvictim count 9 → 12 (+3)
  • 7 d agovictimsvictim count 7 → 9 (+2)
  • 7 d agonew alias1 new alias: vexy
Analyst brief

Vexy Ransomware is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.

IndiaBrazilUnited KingdomArgentinaMexicoUnited StatesEcuador

assessed originobserved targets (7)

Observed targets

countries · 7

IndiaBrazilUnited KingdomArgentinaMexicoUnited StatesEcuador

sectors · 6

TechnologyOtherRetail & E-CommerceManufacturingTransportationHospitality

as stated by MISP galaxy / ransomware.live — not inferred

Victims observed
12
First observed
Last observed on leak site
Velocity
12.0 victims / month
lifetime average, first to last observed

leak-site listings via ransomware.live — a quiet site is not a dead crew

Take it with you
References
Early access

Track Vexy Ransomware on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected