๐Ÿ‡น๐Ÿ‡ณ

TN

TN

Ransomware victim intelligence profile ยท Ranked #59 globally ยท Updated: Sep 20, 2026

22
Total Victims
0.1% of global total
#59
Global Rank
16
Active Groups
9
Sectors Targeted

ThreatAI Analysis

Compiled from this database and the ransomware.live profiles of the groups active in TN. Figures are computed from the tracked records, not inferred.

TN in the global picture

TN accounts for 22 of the ransomware disclosures tracked here, ranking #59 worldwide and making up 0.1% of the global total. The sectors listed most often are Healthcare, Manufacturing, Transportation/Logistics.

Who is most active in TN

Hunters โ€” 4 victims in TN. Thegentlemen โ€” 3 victims in TN. Devman โ€” 2 victims in TN. Former RansomHub and INC Ransom affiliate.

Ransomware Threat Profile: TN

TN ranks #59 globally for ransomware attacks, with 22 confirmed victims in this database โ€” representing 0.1% of the worldwide total. The most active ransomware groups targeting TN include Hunters, Thegentlemen, Devman.

The most frequently targeted industries in TN are Healthcare, Manufacturing, Transportation/Logistics. The healthcare sector is particularly vulnerable because attacks on hospitals and medical providers can create life-threatening situations, increasing pressure to pay ransoms quickly.

TN's attack volume reflects broader trends in ransomware targeting: the volume of attacks reflects the country's integration into the global economy and the proliferation of ransomware operations that target organisations of all sizes worldwide.

Organisations in TN should consider the active threat groups documented here when assessing their cybersecurity posture, implementing detection rules, and prioritising incident response planning.

Recent Victims in TN (showing 22 of 22)

# Organization Group Sector Date
1 tnmed.org Lockbit5 Healthcare Aug 28, 2026
2 clc-tn.com Settra โ€” Jun 30, 2026
3 monoprix.tn Stormous Consumer Services Jun 28, 2026
4 Bouri Group Thegentlemen Other Jun 4, 2026
5 CRIT Tunisie Titan Business Services May 18, 2026
6 SETCAR Thegentlemen Transportation/Logistics May 12, 2026
7 Kpropha Thegentlemen Healthcare Mar 9, 2026
8 Hopital La Rabta Qilin Healthcare Dec 26, 2025
9 Hopital La Rabta Devman Healthcare Dec 12, 2025
10 Hopital ** ***** Devman Healthcare Dec 11, 2025
11 Alios Finance Group Incransom Financial Services Oct 28, 2025
12 International Freight & Commerce Direwolf Transportation/Logistics Aug 18, 2025
13 Natilait Cicada3301 Agriculture and Food Production Apr 22, 2025
14 Squeezer-software Fog Technology Feb 12, 2025
15 www.groupe-setcar.com.tn Ransomhub Manufacturing Dec 21, 2024
16 Smart-it-partner Funksec Technology Dec 4, 2024
17 ExcelPlast Tunisie Orca Manufacturing Sep 16, 2024
18 maxcess-logistics.com Killsec Transportation/Logistics Jul 1, 2024
19 ATL Leasing Hunters Financial Services Mar 15, 2024
20 ATL Hunters Business Services Mar 12, 2024
21 SOPEM Hunters Manufacturing Feb 13, 2024
22 SOPEM Tunisie Hunters Manufacturing Feb 10, 2024

Frequently Asked Questions

How many ransomware attacks have occurred in TN?

TN has recorded 22 ransomware victim disclosures in this database, ranking #59 globally. This represents 0.1% of all tracked ransomware attacks worldwide.

Which ransomware groups target TN?

The ransomware groups most active in TN are Hunters, Thegentlemen, Devman, Lockbit5. These groups collectively account for the majority of victim disclosures attributed to TN.

Which industries are most targeted by ransomware in TN?

In TN, the most frequently targeted sectors are Healthcare, Manufacturing, Transportation/Logistics. These industries hold valuable data and often have critical operational requirements that make them attractive ransomware targets.

How does TN rank globally for ransomware attacks?

TN ranks #59 globally for ransomware attacks with 22 victim disclosures, representing 0.1% of the worldwide total of 21,768 tracked victims.

How can organisations in TN protect against ransomware?

Organisations in TN should implement a layered security approach including regular offline backups, network segmentation, multi-factor authentication, endpoint detection and response (EDR) tools, and employee security awareness training. Monitoring threat intelligence feeds for active groups targeting TN is also recommended.