← Back to Ransomware Chk

Exitium

Active
Exitium is a data extortion group first observed in early 2026, operating a Tor-based double extortion site and targeting victims via bulk data exfiltration followed by public naming-and-shaming, with known victims including a Brazilian agro-industrial firm and a US county appraisal district.
4 Victims
Mar 17, 2026 First Discovered
Apr 14, 2026 Last Discovered
19 Days Inactive
0% Infostealer
1/1 Sites Online
Top Countries
NY 1
TW 1
BR 1
US 1
Top Sectors
Healthcare 1
Energy 1
Agriculture and Food Production 1
Public Sector 1
Known Locations (1)
Exitium
m3ksukzn2glzfdvlusohril7n3iyk4z4fudf6mm22lwhpbpt5aiee5qd.onion
Victims (4)
Gastroenterology & Hepatology of CNY
NY Healthcare Discovered: Apr 14, 2026 · Attack est.: Apr 14, 2026
Website: gandhofcny.com Zoominfo: https://www.zoominfo.com/c/gastroenterology--hepatology-of-cny-pc/346091487 Data sample, whole internal data will be sold if they wouldn't pay ransom. Also Digestive Disease Center of CNY, LLC (ddcofcny.com) GI practice + AAAHC-accredited endoscopy...
Ming Hwei Energy
TW Energy Discovered: Mar 29, 2026 · Attack est.: Mar 29, 2026
Zoominfo: https://www.zoominfo.com/c/ming-hwei-energy-co-ltd/446006038 A small private B2B firm (11–50 staff,
Marborges Agroindustria
BR Agriculture and Food Production Discovered: Mar 23, 2026 · Attack est.: Mar 23, 2026
Zoominfo: https://www.zoominfo.com/c/marborges-agroindustria/547271801 Company in Brasil with a bad security.
Fannin CAD
US Public Sector Discovered: Mar 17, 2026 · Attack est.: Mar 17, 2026
Zoominfo: https://www.zoominfo.com/pic/fannin-central-appraisal-district/1117264519 Exfiltrated: 400 GB of data