← All ransomware groups

Ransomware group profile · #133 by claimed victims

Suncrypt ransomware

SunCrypt is a RaaS operation first observed in October 2019, notable for pioneering triple extortion (encryption, data publication threats, and DDoS attacks on non-paying victims), operating a closed small affiliate program and partnering with TrickBot for initial access.

Active First seen Aug 2020
32Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
1Countries hit
2Leak-site URLs tracked, 0 online
18 Jun 2022Latest claim recorded

Victimology

Who Suncrypt claims to have breached, from 32 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Professional Services5
Retail & E-Commerce5
Manufacturing4
Healthcare4
Education3
Agriculture and Food Production2
Technology2
Financial Services1

Top countries

United States2

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
SOCOTEC Professional Services 18 Jun 2022
Northeastern Technical College Education 4 Jun 2022
Co-opbank Pertama Financial Services 24 Apr 2022
DJS associate Not Found 16 Apr 2022
Gemeente Buren Government & Defense 14 Apr 2022
Atlas Copco Manufacturing 14 Apr 2022
Oklahoma City Indian Clinic Healthcare 28 Mar 2022
FitFlop Ltd. fitflop ltd. Retail & E-Commerce 17 Mar 2022
Migros Retail & E-Commerce 16 Mar 2022
Royal Smilde Agriculture and Food Production 21 Feb 2022
CENTRAL BAPTIST COLLEGE Education 21 Feb 2022
KVK Tech | Specialty Brands and Generics Technology 15 Feb 2022

All 32 Suncrypt victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Suncrypt is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Suncrypt ransomware still active?
Suncrypt is tracked as active. The most recent leak-site claim VULONE recorded is dated 18 June 2022.
How many victims has Suncrypt claimed?
VULONE has recorded 32 leak-site victim claims attributed to Suncrypt since August 2020, across 1 countries and 12 sectors.
Which industries does Suncrypt target?
The sectors most often named on the Suncrypt leak site are Professional Services, Retail & E-Commerce, Manufacturing.
Which countries are most affected by Suncrypt?
Most Suncrypt victims recorded by VULONE are located in United States.
Where does VULONE get Suncrypt victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].