๐Ÿ‡ฑ๐Ÿ‡น

Lithuania

LT

Ransomware victim intelligence profile ยท Ranked #94 globally ยท Updated: Sep 6, 2026

7
Total Victims
0% of global total
#94
Global Rank
7
Active Groups
6
Sectors Targeted

ThreatAI Analysis

Compiled from this database and the ransomware.live profiles of the groups active in Lithuania. Figures are computed from the tracked records, not inferred.

Lithuania sees ransomware activity against 7 victims globally ranking 93, primarily targeted health care, transportation/logistics, and hospitality/tourism by groups like Majinahanashi, Deadlock, and Nightspire.

Lithuania in the global picture

Lithuania accounts for 7 of the ransomware disclosures tracked here, ranking #94 worldwide and making up 0% of the global total. The sectors listed most often are Healthcare, Transportation/Logistics, Hospitality and Tourism.

Who is most active in Lithuania

Majinahanashi โ€” 1 victims in Lithuania. Deadlock โ€” 1 victims in Lithuania. Nightspire โ€” 1 victims in Lithuania.

Where to report an incident in Lithuania

National computer emergency response teams for Lithuania, as registered with ENISA and the teams themselves. Regional, sectoral and vendor response teams are excluded; verify current contact details before relying on them in an incident.

Ransomware Threat Profile: Lithuania

Lithuania ranks #94 globally for ransomware attacks, with 7 confirmed victims in this database โ€” representing 0% of the worldwide total. The most active ransomware groups targeting Lithuania include Majinahanashi, Deadlock, Nightspire.

The most frequently targeted industries in Lithuania are Healthcare, Transportation/Logistics, Hospitality and Tourism. The healthcare sector is particularly vulnerable because attacks on hospitals and medical providers can create life-threatening situations, increasing pressure to pay ransoms quickly.

Lithuania's attack volume reflects broader trends in ransomware targeting: the volume of attacks reflects the country's integration into the global economy and the proliferation of ransomware operations that target organisations of all sizes worldwide.

Organisations in Lithuania should consider the active threat groups documented here when assessing their cybersecurity posture, implementing detection rules, and prioritising incident response planning.

Recent Victims in Lithuania (showing 7 of 7)

# Organization Group Sector Date
1 UAB Biotecha Majinahanashi Healthcare Aug 12, 2026
2 Elmoris Deadlock โ€” Jul 10, 2026
3 MAGNETA LOGISTICS, UAB Nightspire Transportation/Logistics Mar 7, 2026
4 CILI Blacknevas Hospitality and Tourism Aug 6, 2025
5 Mantinga Hunters Agriculture and Food Production Nov 18, 2024
6 briedis.lt Ransomhub Technology Sep 6, 2024
7 nordspace.lt Darkvault Business Services Jun 10, 2024

Frequently Asked Questions

How many ransomware attacks have occurred in Lithuania?

Lithuania has recorded 7 ransomware victim disclosures in this database, ranking #94 globally. This represents 0% of all tracked ransomware attacks worldwide.

Which ransomware groups target Lithuania?

The ransomware groups most active in Lithuania are Majinahanashi, Deadlock, Nightspire, Blacknevas. These groups collectively account for the majority of victim disclosures attributed to Lithuania.

Which industries are most targeted by ransomware in Lithuania?

In Lithuania, the most frequently targeted sectors are Healthcare, Transportation/Logistics, Hospitality and Tourism. These industries hold valuable data and often have critical operational requirements that make them attractive ransomware targets.

How does Lithuania rank globally for ransomware attacks?

Lithuania ranks #94 globally for ransomware attacks with 7 victim disclosures, representing 0% of the worldwide total of 21,391 tracked victims.

How can organisations in Lithuania protect against ransomware?

Organisations in Lithuania should implement a layered security approach including regular offline backups, network segmentation, multi-factor authentication, endpoint detection and response (EDR) tools, and employee security awareness training. Monitoring threat intelligence feeds for active groups targeting Lithuania is also recommended.