ShadowByt3$
ACTIVEransomware group
ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communic
Group Activity
Last 12 monthsVictims (30)
HandyTrac (Greystar Litchfield Park, AZ)
We have access to sensitive data. It's in your best interest to contact us and negotiate since it will just hurt you if you don't. We stole a lot of sensitive i...
John Engel Team
Contact us and negotiate. Don't be like the other real estate companies we have breached. We have serious data which contains the following below. Also we have ...
Ben Leeds Properties
We have emailed the following la@benleedsproperties.com nikki@benleedsproperties.com 21736Roscoe@benleedsproperties.com 3327livonia@benleedsproperties.com...
BayView Real Estate
Guess your too busy focusing on your clients then changing password and protecting your clients. We breached them through pm.livable.com. You can see screenshot...
Copy
Joining Requirements
Contact us before registering. You must have valid access or proof of work from previous defunct groups in order to join. If you do not have any valid credentia...
Sinar Mas Agribusiness and Food Golden Agri-Resources)
We Breached This company a few months ago. we stole 375.66MB. mirror 1: https://anonfilesnew.com/s/4t-mBJg9wMy More info is on darkforums.ru about this leak.
A-Plus Software Limited
We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend. We gained access to there system on 08/18/2026 The followi...
Knottingham Trent University
We breached Knottingham trent University on August 19th 2026 by gaining access through webapps.ntu.ac.uk. We alerted the university which they know they have be...
ShadowByt3$ 2.0
Operating Since October 2025 Gate Status: AWAITING HANDSHAKE Initialize Security Handshake
TINYpulse NINTENDO BREACH (nintendo.com)
This will be quick. You don't even want to read the private messages as some will be embarrasing. Some people are confused but this breach doesn't affect you un...
Nintendo Company (Nintendo.com)
proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extortion as a service group. We stole close enough to 1gb. You have 48 hours...
Lead Company (Leadership Boulevard)
Company Site: leadschool.in size: 765.9MB This is will be quick. The following schools are affected: The specific schools explicitly named in the exfiltrated fo...
University Of Georgia
We have breached you and gained access to the following portals: https://operations.cropwise.com/d/users/sign_in https://accounts.cropwise.com/signin proof: htt...
Cropwise (Syngenta Group)
We have breached you and gained access to the following portals: https://operations.cropwise.com/d/users/sign_in https://accounts.cropwise.com/signin proof: htt...
PowerCampus
Cloud-based school management and collaboration platform targeting educational institutes in India, covering online fee payments, exam management, online admiss...
BreachForumsis Back (
ShadowByt3$ has breached University of Georgia. The full data is on are leak site. We stole approximately 3.2 MB in raw text files. No customers were affected j...
Eric J Taylor Doxx
Uploader: Anonymous
Ellucian PowerCampus Warning (Contact Us)
This is a warning for ellucian PowerCampus. Due to not people paying much for are breach we will give you 48 hours to contact us. If you don't it will get publi...
Stride Learning
Stride Learning Should've Paid the ransom. We were only asking $500,000 in bitcoin or monero it's not that hard. This is a warning to all companies that if you ...
Amplify Technology
Amplify technology has been a victim of an attack. There project they were working on with the pakistan and other countries got stolen. We stole 1.69Gb of data....
University Of Georgia (uga.edu)
Uploader: Anonymous
UMSA Argentina
Uploader: Anonymous
StarBucks Company (StarBucks.com
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't c...
Amplify_Technology_breached_032326
Hotelogix Company (
Should've not messed with us Hotelogix. We gave you guys numerous times to reach back and proceed with payment but you decided to fuck around and you found out....
sample_Pay_or_gets_leaked_and_sold_and_on_news
Sample_Forestal Atlántico Sur (FAS)_fas.com.uy
Pay_until_timer_runs_outForestal Atlántico Sur (FAS)_fas.com.uy
UMSA
File: UMSA_LEAK.7z
Infrastructure
https://transfer.it487ms
8m ago
http://sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onion4117ms
3d ago
unreachable
http://shadoz22.io/501ms
6d ago
unreachable
https://shadowsblog.cloud-ip.cc/8239ms
8m ago
unreachable
http://sdwbytqeb664krp2wz2qs3lxxah2rhneuotot5hy7g4jpn2pindigcad.onion/leaks.php8199ms
6d ago
unreachable
http://shdwbt3ja2ptjt6poluegas44i35727lgmoqqquoww642x3zyocyhuqd.onion/leaks8224ms
17h ago
unreachable
https://shadowbyt3s.8bit.ca/index.php826ms
6d ago
unreachable
http://mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion/leaks.php4345ms
3d ago
unreachable
http://52rtvdymcqvebbamd3la3wtu3ofrcuzuzja3vrsu6wiyrq223osptzqd.onion2756ms
18h ago