Settra is a ransomware and extortion threat group that emerged publicly in 2026 and rapidly appeared in ransomware claim tracking with at least 11 posted victim claims in a single reporting week. The group has been identified as a newcomer in the ransomware ecosystem alongside other newly surfaced crews, indicating a recent operational debut rather than a long-established brand. Settra has been linked to ransomware incidents and associated data-breach claims against organizations in multiple countries, including the United States, Germany, the United Kingdom, and Taiwan. Reported victims span construction, business services, e-commerce, and organizations connected to industrial and defense-related manufacturing. In addition to ransomware deployment, Settra has publicly claimed theft of internal documents and user data, consistent with data-theft-driven extortion activity and leak-site style victim shaming. Observed victimology indicates opportunistic, multinational targeting rather than a narrowly focused geopolitical mission. Reported cases include organizations in construction and business services, a diamond company, and a Taiwanese e-commerce-related subsidiary. In one publicly reported Taiwan case, Settra claimed compromise of systems associated with Pi Mobile Technology, a subsidiary of PChome Online, and theft of internal documents and user data; the affected company stated that its preliminary review did not confirm intrusion into its main website or core systems at that stage. Available reporting supports characterizing Settra as a financially motivated cybercriminal actor engaged in ransomware and extortion operations. High-confidence behaviors include initial access sufficient to compromise victim environments, theft and exfiltration of data, and public extortion through victim claims and alleged publication of stolen material. Reporting also associates the actor with use of valid accounts and collection of data from cloud storage in at least one claimed intrusion. Attribution to any state sponsor or specific country of origin is not currently supported at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newer ransomware/extortion actor contributing to risk in Germany.
Newly emerged ransomware/extortion group noted in June 2026.
Claimed a data breach against Pi Mobile Technology / PChome, alleging theft of internal documents and user data.
Conducting a ransomware attack and associated data breach against petradiamonds.com.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.