Ransomware group profile · #271 by claimed victims
Bonacigroup ransomware
Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going offline, with very little public documentation about their tactics, targets, or tooling.
Victimology
Who Bonacigroup claims to have breached, from 3 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 3 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Marshall Investigative Group Part 1/3 1000 Client | Professional Services | — | 6 Dec 2021 |
| Ward Arcuri Foley & Dwyer | Law Firm | Professional Services | — | 4 Oct 2021 |
| Charles Crown Financial Ltd | Financial Services | — | 4 Oct 2021 |
All 3 Bonacigroup victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Bonacigroup is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Bonacigroup ransomware still active?
How many victims has Bonacigroup claimed?
Which industries does Bonacigroup target?
Which countries are most affected by Bonacigroup?
Where does VULONE get Bonacigroup victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].