CSIDB logo
Threat actor

Donut Leaks

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
2 incidents
First seen
2022-07-24
Last seen
2022-08-23
Updated
2026-08-01 19:03
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Donut Leaks, also referenced as the d0nut ransomware team, is a threat actor that has been linked to multiple ransomware and extortion incidents. The actor’s location is indicated as Russia in the provided context, and their activities have been associated with potential affiliations to established ransomware operations such as Hive and Ragnar Locker, suggesting a collaborative data‑sharing relationship with those groups. The actor operates Tor‑based shaming blogs and data storage sites, employing tools like File Browser to host and leak stolen information.

Observed targeting by Donut Leaks spans several sectors and geographic regions. Incidents attributed to the actor include a healthcare provider (Montgomery General Hospital in West Virginia, United States), a legal services firm (UnitedLex, also based in the United States), and an architectural practice (Sheppard Robson in the United Kingdom). Additional incidents referenced in the source material, such as the Sando incident dated August 2022, indicate activity beyond these regions, though specific sectors for those cases are not detailed in the material. The actor’s strategic objectives, as described in the source material, involve financial extortion through ransom demands coupled with threats to leak exfiltrated data, a double‑extortion model intended to compel payment even when victims refuse initial ransom demands.

The actor’s tactics, techniques, and procedures observed across the reported incidents include the deployment of ransomware to encrypt victim systems, the prior exfiltration of sensitive files, and the use of negotiated ransom amounts that sometimes differ from initial demands. Donut Leaks has been seen leveraging Tor‑hosted leak sites and File Browser instances to publish large volumes of stolen data—approximately 2.8 TB across multiple victims—as a means of increasing pressure on targets. Negotiation attempts have been documented, wherein the actor communicated directly with victim leadership, offered reduced payment amounts, and referenced the victims’ cyber‑insurance policies as leverage points. No specific malware families or initial access vectors are explicitly attributed to Donut Leaks in the provided material, though the association with Hive and Ragnar Locker suggests possible overlap in tooling or infrastructure.

Notable operations linked to Donut Leaks include the August 2022 Sando incident, where Hive initially claimed responsibility before Donut Leaks released a larger volume of stolen data; the July‑August 2022 ransomware attack on the UK‑based architecture firm Sheppard Robson, which involved network disruption, ransom demands, and a refusal to pay; the March 2023 ransomware attack and data leak at Montgomery General Hospital, involving exfiltration of administrative and some patient data; and the April 2023 incident against UnitedLex, in which over 200 GB of corporate files were exfiltrated, negotiations for a $600,000 payment were attempted, and a subsequent $5 million ransom demand was issued before the data was leaked and later appeared on a BlackCat leak site. These incidents illustrate the actor’s pattern of ransomware deployment, data theft, and extortion follow‑through. End of profile.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB