All ransomware groups
sabbath
17 tracked victims
·first seen 2021-11-22·last activity 2022-02-28Group profile
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.
Recent victims
| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2022-02-28 | A aria-label=Google> | Not Found | |
| 2022-01-15 | J JALEEL TRADERS LLC | Agriculture and Food Production | |
| 2022-01-14 | A ASL Napoli 3 Sud Network Seized | Not Found | |
| 2022-01-12 | P Protected: PRIVATE POST ITALY | Not Found | |
| 2022-01-04 | S Summit College | Education | |
| 2022-01-04 | C Close drawer | Not Found | |
| 2022-01-04 | C Close search modal | Not Found | |
| 2021-12-28 | T TRIGYN 2 0 | Data Leak | Technology | |
| 2021-12-20 | P Prenax | Not Found | |
| 2021-12-12 | S Social Enterprise (SEC) | Business Services | |
| 2021-12-10 | T Trigyn Technologies Ltd | Technology | |
| 2021-11-22 | F Flagship | Consumer Services | |
| 2021-11-22 | S Stoningtonschools | Education | |
| 2021-11-22 | A AISD | Education | |
| 2021-11-22 | S Starline | Manufacturing | |
| 2021-11-22 | R RocTechnologies | Technology | |
| 2021-11-22 | M MCP Services LLC | Business Services |

