teamxxx
Active since 2025-02-17
Unverified threat-actor claim — not a regulatory filing
Attribution, victim identity, and counts shown here derive from teamxxx's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
According to ransomware.live, the group claims:
TeamXXX is an emerging ransomware group that launched its leak site in June 2025, claiming victims across healthcare, agriculture, hospitality, financial services, and shipping sectors in the US, UK, Norway, Ireland, and Europe within its first months.
Source: Ransomware.live