rhysida
Known ransomware group Dormant / low-volume
Rhysida is a ransomware-as-a-service group active since 2023, repeatedly targeting healthcare, education, and government entities. It has been the subject of CISA advisories and is known for auctioning stolen data on its leak site.
1
Total Claims
0
Critical
—
Records Claimed
1
Industries Hit
Active span: May 15, 2026 – May 15, 2026 · 1 organizations targeted
Dormant / low-volume
Actor Threat Profile
Activity Timeline
Peak: May 2026 (1)May 2026
LessMore
May 2026Top Targeted Industries
Education 1
Tradecraft & Infrastructure
8
Documented tools
12 / 32
MITRE tactics / techniques
2
Known leak sites
DiscoveryEnumExfiltrationLOLBASOffsecRMM-Tools
Full intelligence profile on ransomware.live →