Ransomware group profile · #249 by claimed victims
Ms13089 ransomwarealso ms13-089
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
Victimology
Who Ms13089 claims to have breached, from 5 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 5 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| servmarmg.cl servmarmg.cl | Other | CL | 15 Aug 2026 |
| brittanyresidential.com brittanyresidential.com | Retail & E-Commerce | US | 5 May 2026 |
| sjl-legal.com sjl-legal.com | Professional Services | LU | 15 Jan 2026 |
| dgpcommercialisti.it dgpcommercialisti.it | Professional Services | IT | 18 Dec 2025 |
| uro.com uro.com | Healthcare | DE | 18 Dec 2025 |
All 5 Ms13089 victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Ms13089 is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Ms13089 ransomware still active?
How many victims has Ms13089 claimed?
Which industries does Ms13089 target?
Which countries are most affected by Ms13089?
Where does VULONE get Ms13089 victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].