Blackout is a ransomware threat group first observed in late February 2024. The group operates a leak site and has publicly claimed intrusions against organizations in multiple countries. Reported victimology includes healthcare entities in Canada, France, and Germany, as well as later victims in Mexico, Croatia, the United Kingdom, the United States, and Japan. Observed targets span healthcare, telecommunications, manufacturing, technology, and passenger travel-related organizations. Blackout's operations are consistent with data-theft-driven ransomware activity and extortion. The group has publicly posted victims on its leak site and used leak deadlines to pressure organizations, indicating a leak-site-enabled extortion model. Reported incidents have been characterized as data breaches associated with ransomware attacks, supporting assessment of both data exfiltration and extortion behavior. At high confidence, Blackout is associated with ransomware victim posting and leak-site operations rather than any confirmed nation-state affiliation. Available reporting supports financially motivated cybercriminal activity. Publicly documented activity remains limited, and no corroborated sub-groups or widely used alternate aliases are established beyond the Blackout name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Bluebell Group, with a leak deadline indicating likely extortion/data leak activity.
Conducting a ransomware attack against Miatech, a US-based organization.
Conducting a ransomware attack against Yano Electronics Ltd. (yano.tokyo), a technology-sector organization in Japan.
Blackout is a ransomware group active since February 2024, targeting healthcare, telecommunications, and manufacturing sectors in multiple countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.