Menu
Browse

Cyber Threat Actor: RansomHouse

Actor Type Location Known Incidents
 Icon
Criminal
Russia
20 incidents
Profile

RansomHouse is a threat actor that operates under the alias RansomHouse and has been identified as originating from Russia according to available reporting. The group describes itself as a “professional mediators community” that positions itself as a data‑extortion marketplace targeting organizations it claims have a negligent attitude toward the privacy and security of customers’ personal data. It first appeared in public reporting in May 2022 and has since been linked to a series of intrusions across multiple sectors and geographies.

The actor’s public statements claim that it does not deploy ransomware itself and focuses solely on data theft and extortion, yet multiple investigations have linked its operations to the WhiteRabbit ransomware encryptor, suggesting a partnership or affiliate relationship for the encryption component of its attacks. RansomHouse actors have been observed exploiting vulnerabilities in network infrastructure and VMware environments to gain initial access, as noted in the Mission Community Hospital incident where they cited network and VMware weaknesses. After gaining access, they typically exfiltrate large volumes of data—ranging from hundreds of gigabytes to several terabytes—before threatening to publish the stolen information unless a payment is made, and they have stated that unsolicited data may be sold to other cybercriminals or released for free on their leak site.

Notable operations attributed to RansomHouse include the May 2026 claim of access to Trellix’s source code repository, the October 2023 ransomware attack on the Allied Pilots Association that encrypted systems and required restoration from backups, and the August 2023 incident at Radley London where they asserted the theft of 600 GB of data accompanied by system encryption. In June 2023 they were linked to the Eisai pharmaceutical ransomware that encrypted servers, and in May 2023 they claimed the theft of 2.5 TB of data including patient information from Mission Community Hospital. Additional high‑profile cases involve the April 2023 AvidXchange leak of payroll and credential data, the March 2023 attacks on Albany ENT & Allergy Services, the Comune di Taggia and Cospec Srl municipalities in Italy, the March 2023 disruption of a university hospital in Brussels, and the March 2023 ransomware impact on Hospital Clínic de Barcelona in Spain. Earlier activity includes the November 2022 Kerlaty healthcare organization attack where they claimed to have stolen 3 TB of data, and the June 2022 assertion of responsibility for the Shoprite supermarket chain breach with a claimed 600 GB exfiltration, claims that were partially corroborated by leaked evidence but denied by ADATA in a separate case.

Regarding attribution, the only publicly asserted geographic origin is Russia, and the group’s self‑characterization as a professional mediators community is the primary insight into its internal framing. No explicit state sponsorship or affiliation with a larger criminal consortium has been documented in the sources; however, the repeated reference to collaboration with groups that use the WhiteRabbit ransomware encryptor indicates a cooperative relationship for the encryption facet of their operations. The actor’s public messaging consistently emphasizes extortion through data leakage threats and the optional sale of stolen data to other cybercriminals if demands are not met.

Incidents
Attributed incidents available to members
20 incidents
Sources
Sources available to members
14 sources