← All ransomware groups

Ransomware group profile · #94 by claimed victims

Losttrust ransomware

LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching its leak site in September 2023, believed to be a rebrand of the MetaEncryptor gang, primarily targeting manufacturing, professional services, construction, and education sectors with 71% of known victims in the US.

Active First seen Sep 2023
53Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
9Countries hit
1Leak-site URLs tracked, 0 online
26 Sep 2023Latest claim recorded

Victimology

Who Losttrust claims to have breached, from 53 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Professional Services13
Manufacturing8
Education5
Government & Defense5
Technology4
Agriculture and Food Production3
Energy & Utilities3
Retail & E-Commerce3

Top countries

United States5
Italy2
Sweden1
India1
Mexico1
Switzerland1
Argentina1
Romania1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Arazoza Brothers arazozabrothers.com Professional Services 26 Sep 2023
Popovici Niu Stoica & Asociaii pnsa.ro Professional Services RO 26 Sep 2023
Procab procab.se Manufacturing SE 26 Sep 2023
Hoosier Uplands Economic Development hoosieruplands.org Government & Defense IN 26 Sep 2023
Oasys Technologies oasystechnologies.com Technology 26 Sep 2023
Merced City School District mcsd.k12.ca.us Education 26 Sep 2023
Morgan School District morgansd.org Education 26 Sep 2023
Ferguson Wellman fergusonwellman.com Financial Services 26 Sep 2023
TORMAX tormax.com Manufacturing CH 26 Sep 2023
Brown and Streza brownandstreza.com Financial Services 26 Sep 2023
Bit bit.com.ar Agriculture and Food Production AR 26 Sep 2023
Glassline glassline.com Manufacturing 26 Sep 2023

All 53 Losttrust victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Losttrust is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Losttrust ransomware still active?
Losttrust is tracked as active. The most recent leak-site claim VULONE recorded is dated 26 September 2023.
How many victims has Losttrust claimed?
VULONE has recorded 53 leak-site victim claims attributed to Losttrust since September 2023, across 9 countries and 13 sectors.
Which industries does Losttrust target?
The sectors most often named on the Losttrust leak site are Professional Services, Manufacturing, Education.
Which countries are most affected by Losttrust?
Most Losttrust victims recorded by VULONE are located in United States, Italy, Sweden.
Where does VULONE get Losttrust victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].