← All ransomware groups
Rhysida logo

Ransomware group profile · #25 by claimed victims

Rhysida ransomware

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

Active First seen Jun 2023 .rhysida
291Victims claimed on leak sites
16Victims in the last 30 days
18Victims in the last 90 days
41Countries hit
5Leak-site URLs tracked, 2 online
12 Sep 2026Latest claim recorded

Victimology

Who Rhysida claims to have breached, from 291 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 13OctNov 2025: 11Dec 2025: 11Jan 2026: 4JanFeb 2026: 6Mar 2026: 1Apr 2026: 1AprMay 2026: 3Jun 2026: 1Jul 2026: 0JulAug 2026: 8Sep 2026: 10

Top sectors

Education58
Healthcare50
Professional Services38
Government & Defense32
Manufacturing30
Technology18
Retail & E-Commerce15
Transportation9

Top countries

United States126
Canada20
United Kingdom10
Germany9
Australia8
Italy8
Switzerland6
Brazil5

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Axdia International 12 Sep 2026
Axdia International axdia.com Professional Services 12 Sep 2026
General Santos Doctors Hospital 10 Sep 2026
Professional Retail Services 10 Sep 2026
General Santos Doctors Hospital Healthcare PH 10 Sep 2026
Professional Retail Services Retail & E-Commerce 10 Sep 2026
SAD'S Interim 8 Sep 2026
SAD'S Interim sads-interim.eu Professional Services FR 8 Sep 2026
Rug & Home Retail & E-Commerce US 7 Sep 2026
Szechenyi Programiroda Nonprofit Kf Other HU 1 Sep 2026
Valley Health Team Healthcare 28 Aug 2026
Berlin, Germany Not Found DE 28 Aug 2026

All 291 Rhysida victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Rhysida is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Rhysida ransomware still active?
Rhysida is tracked as active. The most recent leak-site claim VULONE recorded is dated 12 September 2026. 16 victims were claimed in the last 30 days.
How many victims has Rhysida claimed?
VULONE has recorded 291 leak-site victim claims attributed to Rhysida since June 2023, across 41 countries and 14 sectors.
Which industries does Rhysida target?
The sectors most often named on the Rhysida leak site are Education, Healthcare, Professional Services.
Which countries are most affected by Rhysida?
Most Rhysida victims recorded by VULONE are located in United States, Canada, United Kingdom.
Where does VULONE get Rhysida victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].