DETECTO/ThreatDossier
DashboardPricingThreatsRun Free ScanSign In
DETECTO/ThreatDossier

Security intelligence for MSPs, consultants, and businesses. Find breached credentials, compliance gaps, and exposed infrastructure before attackers do.

Product

  • Scan a Domain
  • Pricing
  • Dashboard
  • Sign In

Resources

  • Threat Intelligence
  • Ransomware Groups

Legal

  • Privacy Policy
  • Terms of Service

© 2026 DETECTO. All rights reserved.

Threats/Groups/Weyhro

Weyhro

Dormant

weyhro

First seen: 2025-03-06T22:20:26.486945+00:00Total victims: 14

Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.

0Total Victims
0Countries Targeted
0Sectors Targeted
0Avg Attacks/Month

Activity Timelinelast 24 months

Top Targeted Sectors

Top Targeted Countries

Recent Victimsshowing 14 of 14

NameCountrySectorDate
Community Services of MissouriUSPublic Sector2025-08-11T00:31:27.776240+00:00
Chemtron RiverBendUSManufacturing2025-08-11T00:30:58.577127+00:00
Synergy InvestmentsUSFinancial Services2025-05-31T04:42:43.012557+00:00
Terra CaribbeanBBBusiness Services2025-05-31T04:41:32.506621+00:00
Adriatic Glass & MirrorsCAManufacturing2025-05-31T04:40:20.598994+00:00
101 Arch StreetUSNot Found2025-05-08T21:21:00.044615+00:00
Valens Bank/Pay/ExchangeDEFinancial Services2025-03-31T20:20:31.473792+00:00
McMillan James Equipment Company (MJEC)USManufacturing2025-03-25T06:25:26.026022+00:00
Montgomery Little & Soran, PCUSBusiness Services2025-03-25T06:24:11.306976+00:00
Central Electropolishing Company, Inc.USManufacturing2025-03-06T22:25:19.826815+00:00
Resnick & Caffrey, PCUSBusiness Services2025-03-06T22:24:08.018974+00:00
Avantune CorporationUSTechnology2025-03-06T22:22:54.843161+00:00
MBI International, Inc.USBusiness Services2025-03-06T22:21:41.911811+00:00
Fragola S.p.AITManufacturing2025-03-06T22:20:26.486945+00:00

Data from ransomware.live