DETECTO/ThreatDossier
DashboardPricingThreatsRun Free ScanSign In
DETECTO/ThreatDossier

Security intelligence for MSPs, consultants, and businesses. Find breached credentials, compliance gaps, and exposed infrastructure before attackers do.

Product

  • Scan a Domain
  • Pricing
  • Dashboard
  • Sign In

Resources

  • Threat Intelligence
  • Ransomware Groups

Legal

  • Privacy Policy
  • Terms of Service

© 2026 DETECTO. All rights reserved.

Threats/Groups/Darkside

Darkside

Inactive

darkside

First seen: 2020-08-01 00:00:00.000000Total victims: 10

Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.

0Total Victims
0Countries Targeted
0Sectors Targeted
0Avg Attacks/Month

Activity Timelinelast 24 months

Top Targeted Sectors

Top Targeted Countries

Recent Victimsshowing 10 of 10

NameCountrySectorDate
One Call (insurance)GBFinancial2021-05-13 00:00:00.000000
Colonial PipelineUSTransportation Systems2021-05-07 00:00:00.000000
Toshiba Tec Group—Critical Manufacturing2021-05-01 00:00:00.000000
Compucom (MSP)—Information Technology2021-02-27 00:00:00.000000
Discount Car and Truck Rentals CATransportation Systems2021-02-01 00:00:00.000000
Segafredo ZanettiITFood and Agriculture2021-02-01 00:00:00.000000
Companhia Paranaense de Energia (Copel)BREnergy2021-02-01 00:00:00.000000
Home Hardware Stores LtdCACommercial Facilities2021-02-01 00:00:00.000000
Guess—Commercial Facilities2021-02-01 00:00:00.000000
Brookfield Residential (land developer and home builder)—Commercial Facilities2020-08-01 00:00:00.000000

Data from ransomware.live