← All ransomware groups

Ransomware group profile · #147 by claimed victims

Doppelpaymer ransomware

Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".

Active First seen May 2019
25Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
5Countries hit
2Leak-site URLs tracked, 0 online
10 Apr 2021Latest claim recorded

Victimology

Who Doppelpaymer claims to have breached, from 25 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Manufacturing9
Government & Defense9
Technology3
Education2
Agriculture and Food Production1
Transportation1

Top countries

United States15
France4
Chile1
Mexico1
Canada1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Office of the Attorney General Manufacturing US 10 Apr 2021
Azusa police department Government & Defense US 1 Mar 2021
Manutan manutan.fr Manufacturing FR 21 Feb 2021
Kia Motors America (KMA) Manufacturing US 16 Feb 2021
Cuyahoga Metropolitan Housing Authority Government & Defense US 8 Feb 2021
Foxconn Manufacturing MX 29 Nov 2020
Delaware County Government & Defense US 28 Nov 2020
Compal Manufacturing 8 Nov 2020
Banijay Group SAS Technology FR 1 Nov 2020
Chatham County Government Government & Defense US 28 Oct 2020
Hall County Government & Defense US 7 Oct 2020
Newcastle University Education 30 Aug 2020

All 25 Doppelpaymer victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Doppelpaymer is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Doppelpaymer ransomware still active?
Doppelpaymer is tracked as active. The most recent leak-site claim VULONE recorded is dated 10 April 2021.
How many victims has Doppelpaymer claimed?
VULONE has recorded 25 leak-site victim claims attributed to Doppelpaymer since May 2019, across 5 countries and 6 sectors.
Which industries does Doppelpaymer target?
The sectors most often named on the Doppelpaymer leak site are Manufacturing, Government & Defense, Technology.
Which countries are most affected by Doppelpaymer?
Most Doppelpaymer victims recorded by VULONE are located in United States, France, Chile.
Where does VULONE get Doppelpaymer victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].