Datacarry

Compare
Parsing: enabled

View crypto

Description

DataCarry is a newly observed ransomware and data-extortion operation, first seen in May 2025. It operates a double-extortion model, exfiltrating data and threatening publication via a Tor-hosted portal. The group has already claimed multiple victims across diverse sectors including insurance, healthcare, real estate, retail, and aerospace in countries such as Latvia, Belgium, Türkiye, South Africa, Switzerland, Denmark, and the United Kingdom. The rapid emergence and multi-country reach signal a well-organized operation.

External Analysis3
External Analysis
https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/datacarry
https://asec.ahnlab.com/en/88240/
https://www.bitdefender.com/blog/businessinsights/bitdefender-threat-debrief-june-2025
Ransom notes1
Urls1
Url
Status
Screen
Uptime 30d
Health
http://dcarryhaih5oldidg3tbqwnde4lxljytnpvberrwgj2vlvunopd46dad.onion/ Up Screen
47%
Activity (interactive) 14
Activity charts
Posts14
Date Title Description Screen
Miljödata🇸🇪
Miljödata (1 day left)🇸🇪
Peggy Sage🇫🇷
Món Sant Benet🇪🇸
V² Development🇬🇷
Alliance Healthcare IT🇮🇹
La Maison Liégeoise🇧🇪
Executive Jet Support🇬🇧
alles Lægehus🇩🇰
Mammut Sports Group🇨🇭
FrontierCo🇿🇦
Étude Bordet🇧🇪
ALB Forex🇹🇷
Balcia Insurance🇱🇻
Note