← All ransomware groups

Ransomware group profile · #31 by claimed victims

Hive ransomware

Hive is a strain of ransomware that was first discovered in June 2021. Hive was designed to be used by Ransomware-as-a-service providers, to enable novice cyber-criminals to launch ransomware attacks on healthcare providers, energy providers, charities, and retailers across the globe. In 2022 there was a switch from GoLang to Rust.

Active First seen Aug 2021
208Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
27Countries hit
3Leak-site URLs tracked, 0 online
16 Jan 2023Latest claim recorded

Victimology

Who Hive claims to have breached, from 208 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Manufacturing46
Professional Services29
Healthcare23
Technology21
Retail & E-Commerce14
Education13
Transportation9
Energy & Utilities7

Top countries

United States37
United Kingdom8
Netherlands3
Spain2
Canada2
Brazil2
Indonesia2
China2

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
R C Stevens Construction rcstevens.com Manufacturing 16 Jan 2023
G.W. Becker gwbcrane.com Manufacturing 11 Jan 2023
Consulate Health Care consulatehc.com Healthcare 6 Jan 2023
Centro Médico Virgen De La Caridad cmvcaridad.com Healthcare 31 Dec 2022
Camst Group camstgroup.com Hospitality 30 Dec 2022
MHMR Authority Of Brazos Valley mhmrabv.org Healthcare 22 Dec 2022
Alvaria alvaria.com Technology US 21 Dec 2022
Interface interface.com Manufacturing US 20 Dec 2022
North Idaho College Education 20 Dec 2022
Innovative Education Management Education 20 Dec 2022
Dixons Allerton Academy Education 20 Dec 2022
City Of Huntsville, Texas Government & Defense 20 Dec 2022

All 208 Hive victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Hive is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Hive ransomware still active?
Hive is tracked as active. The most recent leak-site claim VULONE recorded is dated 16 January 2023.
How many victims has Hive claimed?
VULONE has recorded 208 leak-site victim claims attributed to Hive since August 2021, across 27 countries and 14 sectors.
Which industries does Hive target?
The sectors most often named on the Hive leak site are Manufacturing, Professional Services, Healthcare.
Which countries are most affected by Hive?
Most Hive victims recorded by VULONE are located in United States, United Kingdom, Netherlands.
Where does VULONE get Hive victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

VULONE research mentioning Hive

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].