DataCarry, also styled Datacarry or DATACARRY, is a financially motivated cyber-extortion operation that emerged in 2025. It has been associated with data-theft-and-leak extortion rather than deployment of ransomware encryption payloads. The operation steals victim data, demands payment to prevent disclosure, and publishes stolen material through a dark-web leak site when demands are not met. DataCarry claimed responsibility for the 2025 compromise of Swedish HR and municipal IT supplier Miljödata, demanding payment and subsequently releasing stolen data. The incident disrupted services used by Swedish municipalities and regions and exposed highly sensitive workforce, health-related, and school-related personal information. Reported targeting includes aviation, education, financial services, insurance, and health care organizations. DataCarry has publicly disclosed victims across multiple countries.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware and data-extortion attack against Miljödata, disrupting municipal and regional IT services in Sweden and exposing sensitive personal data belonging to approximately 2.2 million people. The intrusion reportedly leveraged a long-known critical vulnerability in an outdated firewall-support component installed shortly before the attack.
Ransomware actor/campaign linked to PFCloud bulletproof hosting and targeting aviation, education, finance, insurance, and healthcare.
Ransomware group claiming a breach of Swedish HR software supplier Miljödata, resulting in exposure of employee PII (including names and SSNs) affecting Volvo employees via a third-party vendor compromise.
DATACARRY is a ransomware group that, in 2025, specialized in data theft and extortion through public leaks, foregoing traditional ransomware encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.