Ransomware group profile · #239 by claimed victims
Silent ransomware
Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own statement, they avoid public negotiations and encrypt minimal data. Instead, their focus is on stealing valuable confidential corporate information — and either selling it to competitors, on the dark web, or publishing it selectively.
Victimology
Who Silent claims to have breached, from 6 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 6 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Wisconsin Judicare judicare.org | Government & Defense | US | 21 Jun 2025 |
| Cocoon cocoon-inc.com | Technology | US | 4 May 2025 |
| Advanced Simulation Technology inc. (ASTi) asti-usa.com | Technology | US | 25 Apr 2025 |
| Fleet Canada fleet.ca | Manufacturing | CA | 24 Apr 2025 |
| ESP Associates espassociates.com | Professional Services | US | 23 Apr 2025 |
| Versa Networks versa-networks.com | Technology | US | 23 Apr 2025 |
All 6 Silent victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Silent is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Silent ransomware still active?
How many victims has Silent claimed?
Which industries does Silent target?
Which countries are most affected by Silent?
Where does VULONE get Silent victim data?
VULONE research mentioning Silent
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].