Threat actor analysis
Alphv has disclosed 59 victims on its leak site, 0.3% of all ransomware listings tracked in this database. Its earliest disclosure here dates to January 2024.
The group has listed organisations in 14 countries, most often in United States (36 victims), followed by Canada, Spain, Germany.
By industry, its listings concentrate in Business Services, Healthcare, Manufacturing — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.
Like most current ransomware operations, Alphv is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.