๐Ÿ‡ฒ๐Ÿ‡ฉ

Moldova

MD

Ransomware victim intelligence profile ยท Ranked #115 globally ยท Updated: Sep 20, 2026

4
Total Victims
0% of global total
#115
Global Rank
4
Active Groups
3
Sectors Targeted

ThreatAI Analysis

Compiled from this database and the ransomware.live profiles of the groups active in Moldova. Figures are computed from the tracked records, not inferred.

Moldova ranks 114th globally in ransomware activity with 4 recorded victims; most active threat actors here include Threeam, Nova, and Qilin, targeting Financial Services, Business Services, and Public Sector sectors.

Moldova in the global picture

Moldova accounts for 4 of the ransomware disclosures tracked here, ranking #115 worldwide and making up 0% of the global total. The sectors listed most often are Financial Services, Business Services, Public Sector.

Who is most active in Moldova

Threeam โ€” 1 victims in Moldova. A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. Nova โ€” 1 victims in Moldova. Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victimsโ€™files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure. Qilin โ€” 1 victims in Moldova. Qilin ransomware was first observed in July of 2022.

Where to report an incident in Moldova

National computer emergency response teams for Moldova, as registered with ENISA and the teams themselves. Regional, sectoral and vendor response teams are excluded; verify current contact details before relying on them in an incident.

Ransomware Threat Profile: Moldova

Moldova ranks #115 globally for ransomware attacks, with 4 confirmed victims in this database โ€” representing 0% of the worldwide total. The most active ransomware groups targeting Moldova include Threeam, Nova, Qilin.

The most frequently targeted industries in Moldova are Financial Services, Business Services, Public Sector. These sectors are attractive to ransomware operators due to the sensitive data they hold and the critical nature of their operations.

Moldova's attack volume reflects broader trends in ransomware targeting: the volume of attacks reflects the country's integration into the global economy and the proliferation of ransomware operations that target organisations of all sizes worldwide.

Organisations in Moldova should consider the active threat groups documented here when assessing their cybersecurity posture, implementing detection rules, and prioritising incident response planning.

Recent Victims in Moldova (showing 4 of 4)

# Organization Group Sector Date
1 wmdn.net Threeam โ€” Aug 30, 2026
2 Center Of Information Technologies In Finance Public Institution Nova Financial Services Jul 24, 2026
3 Bekman Marder Hopper Malarkey & Perlin Qilin Business Services Jun 10, 2026
4 compensatii.gov.md Apt73 Public Sector Apr 27, 2026

Frequently Asked Questions

How many ransomware attacks have occurred in Moldova?

Moldova has recorded 4 ransomware victim disclosures in this database, ranking #115 globally. This represents 0% of all tracked ransomware attacks worldwide.

Which ransomware groups target Moldova?

The ransomware groups most active in Moldova are Threeam, Nova, Qilin, Apt73. These groups collectively account for the majority of victim disclosures attributed to Moldova.

Which industries are most targeted by ransomware in Moldova?

In Moldova, the most frequently targeted sectors are Financial Services, Business Services, Public Sector. These industries hold valuable data and often have critical operational requirements that make them attractive ransomware targets.

How does Moldova rank globally for ransomware attacks?

Moldova ranks #115 globally for ransomware attacks with 4 victim disclosures, representing 0% of the worldwide total of 21,768 tracked victims.

How can organisations in Moldova protect against ransomware?

Organisations in Moldova should implement a layered security approach including regular offline backups, network segmentation, multi-factor authentication, endpoint detection and response (EDR) tools, and employee security awareness training. Monitoring threat intelligence feeds for active groups targeting Moldova is also recommended.