teamxxx is an emerging financially motivated ransomware group that launched its dedicated leak site in June 2025. The group distinguishes itself by actively engaging in a double extortion scheme, encompassing data exfiltration and public shaming on its leak site. teamxxx rapidly claimed victims across diverse sectors, including healthcare, agriculture, hospitality, financial services, and shipping, primarily in North America and Europe within its initial months of operation. The group's activities highlight its focus on leveraging sensitive data for ransom payment and public exposure as a pressure tactic.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
CanadaCzech RepublicGermanyUnited KingdomHong KongIrelandNorwaySwedenSingaporeUnited States
Sectores atacados
Healthcare (1)
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingRail TransportationHospitalsEnterprises & HoldingAccommodationManufacturingConstructionPublic AdministrationWholesale Trade