← All ransomware groups

Ransomware group profile · #124 by claimed victims

Moneymessage ransomwarealso ThreatLabz

Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in the millions and publishing stolen data on their blog if unpaid, with most known victims based in the US.

Active First seen Mar 2023
35Victims claimed on leak sites
1Victims in the last 30 days
5Victims in the last 90 days
8Countries hit
0Leak-site URLs tracked
28 Aug 2026Latest claim recorded

Victimology

Who Moneymessage claims to have breached, from 35 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 1JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 1Jun 2026: 0Jul 2026: 4JulAug 2026: 1Sep 2026: 0

Top sectors

Manufacturing7
Professional Services5
Healthcare5
Government & Defense4
Financial Services3
Transportation3
Education2
Technology2

Top countries

United States13
Bangladesh1
Italy1
United Kingdom1
Russia1
Australia1
Argentina1
Egypt1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
ProCare Healthcare US 28 Aug 2026
Yourway Transportation Transportation US 25 Jul 2026
Indigo Energy indigoenergy.com Energy & Utilities US 23 Jul 2026
Envision Unlimited Not Found 9 Jul 2026
X-Copper Professional xcopper.com Manufacturing US 2 Jul 2026
Forestdale Professional Services GB 11 May 2026
Family Partnerships of Central Florida fpocf.org Government & Defense US 28 Jan 2026
Bucks County Opportunity Council, INC. bcoc.org Government & Defense US 4 Aug 2025
Young Adjustment Company youngadjustment.com Professional Services US 15 Jul 2025
The Tech Interactive thetech.org Education US 1 May 2025
Marina Family Medical marinafamilymedical.com.au Healthcare AU 18 Jan 2025
National Atomic Energy Commission cnea.gob.ar Government & Defense AR 18 Dec 2024

All 35 Moneymessage victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Moneymessage is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Moneymessage ransomware still active?
Moneymessage is tracked as active. The most recent leak-site claim VULONE recorded is dated 28 August 2026. 1 victims were claimed in the last 30 days.
How many victims has Moneymessage claimed?
VULONE has recorded 35 leak-site victim claims attributed to Moneymessage since March 2023, across 8 countries and 12 sectors.
Which industries does Moneymessage target?
The sectors most often named on the Moneymessage leak site are Manufacturing, Professional Services, Healthcare.
Which countries are most affected by Moneymessage?
Most Moneymessage victims recorded by VULONE are located in United States, Bangladesh, Italy.
Where does VULONE get Moneymessage victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].