DisclosureLens
← All groups

conti

Active since 2020-07-31
351 claimed victims

Unverified threat-actor claim — not a regulatory filing

Attribution, victim identity, and counts shown here derive from conti's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Sanctions caution: conti carries US sanctions exposure — OFAC has designated the group or its operators. Public reporting is permitted, but any payment or material support may violate sanctions. Consult counsel before engaging.

According to ransomware.live, the group claims:

Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.

Source: Ransomware.live