CSIDB logo
Organisation

Maze

Profile

Primary URL
Undetermined
Location
-
Sector
Undetermined
Known incidents
0 incidents
Updated
2026-10-06 00:16
Aliases
1 alias

Organisation tracking is available to eligible accounts.

Profile narrative

Maze is a cybercriminal group known for developing and distributing ransomware software that encrypts victims’ files and demands payment in cryptocurrency for a decryption key. The group operated a ransomware‑as‑a‑service model, allowing affiliates to deploy the malware in exchange for a share of the ransom proceeds, which lowered the technical barrier for participation. Victims typically received a ransom note outlining the payment deadline and the consequences of non‑compliance, creating a direct extortion pressure point. In addition to encrypting data, Maze exfiltrated sensitive information before locking systems, threatening to publish the stolen material if the ransom was not paid. This double‑extortion approach distinguished Maze from many earlier ransomware variants that relied solely on file encryption and helped increase the likelihood of payment.

The group’s activity was reported across various industries, including healthcare, municipal services, and manufacturing, indicating a broad sectoral reach. One publicly cited incident occurred on 2020‑08‑02 when Ventura Orthopedics disclosed that patient data had been compromised in a Maze ransomware attack, highlighting the threat to medical providers. Security researchers and news outlets have linked Maze to numerous other breaches worldwide, suggesting a sustained operational presence over several months and a geographic footprint that extended beyond any single region. The ransomware payload was often distributed via phishing emails, compromised remote‑desktop services, or exploited software vulnerabilities, reflecting common infection vectors used by the affiliates. Although the exact number of victims is not disclosed in the provided sources, the frequency of reported incidents points to a notable impact on organizations that stored valuable or regulated data.

Maze’s distinguishing attributes include the use of a public leak site where stolen data was posted to pressure victims into paying, a tactic that amplified the reputational and regulatory risks faced by targets. The affiliate structure allowed individuals with limited technical skill to participate in attacks, while the core developers maintained the malware, infrastructure, and leak‑site operations. Ownership of the group has never been publicly revealed; investigators describe it as a loose collective rather than a formally incorporated entity, with fluid membership and shifting alliances. In late 2020, law‑enforcement actions and internal disputes led to the apparent discontinuation of the Maze brand, with some members migrating to related ransomware families such as Egregor. Despite its decline, the tactics pioneered by Maze continue to influence contemporary ransomware operations, particularly the combination of encryption and data‑leak extortion.

Incidents

0 incidents linked to this organisation.

CSIDB