logo

Ransomware Tracker (Entry #152): dAn0n

ID: 5442d359-75be-573b-9658-ba739aefef59

STIX ID: report--5442d359-75be-573b-9658-ba739aefef59

Feed Name: WatchGuard Secplicity Blog

Threat Score
65/100

Date Published: 2025-10-17

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

The report summarizes the activity of the dAn0n hacker group first observed in Spring 2024: a data-broker extortion operation that stole and sold victim data and publicly posted 19 victims on a clear-net/dark-web leak site. Their distinguishing tactic was an overt, multi-step "Status" extortion workflow designed to pressure victims (deadlines, notifying leadership/insurers/clients/regulators). The group ceased in August 2024 and later reappeared in 2025 as White Lock, which employed traditional crypto-ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.