← All ransomware groups
Datacarry logo

Ransomware group profile · #175 by claimed victims

Datacarry ransomware

DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.

Active First seen May 2025
16Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
12Countries hit
1Leak-site URLs tracked, 0 online
6 Dec 2025Latest claim recorded

Victimology

Who Datacarry claims to have breached, from 16 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 1Dec 2025: 1Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Retail & E-Commerce5
Healthcare2
Financial Services2
Transportation2
Agriculture and Food Production2
Professional Services1
Hospitality1
Technology1

Top countries

Sweden2
Belgium2
Italy2
Spain2
Denmark1
Switzerland1
France1
South Africa1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Camomilla camomilla.com Retail & E-Commerce IT 6 Dec 2025
UAM Transportation ES 21 Nov 2025
Miljödata (1 day left) Agriculture and Food Production SE 13 Sep 2025
Miljödata miljodata.se Agriculture and Food Production SE 13 Sep 2025
Peggy Sage peggysage.com Retail & E-Commerce FR 15 Aug 2025
Món Sant Benet monsantbenet.com Hospitality ES 12 Jun 2025
V² Development vsquared2.com Technology GR 4 Jun 2025
Alliance Healthcare IT alliancehealthcareit.com Healthcare IT 29 May 2025
La Maison Liégeoise maisonliegeoise.be Retail & E-Commerce BE 26 May 2025
Executive Jet Support ejs.aero Transportation GB 26 May 2025
alles Lægehus alleslaegehus.dk Healthcare DK 26 May 2025
Mammut Sports Group mammut.com Retail & E-Commerce CH 26 May 2025

All 16 Datacarry victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Datacarry is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Datacarry ransomware still active?
Datacarry is tracked as active. The most recent leak-site claim VULONE recorded is dated 6 December 2025.
How many victims has Datacarry claimed?
VULONE has recorded 16 leak-site victim claims attributed to Datacarry since May 2025, across 12 countries and 8 sectors.
Which industries does Datacarry target?
The sectors most often named on the Datacarry leak site are Retail & E-Commerce, Healthcare, Financial Services.
Which countries are most affected by Datacarry?
Most Datacarry victims recorded by VULONE are located in Sweden, Belgium, Italy.
Where does VULONE get Datacarry victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].