Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Donutleaks ransomware

14 victims listed on the Donutleaks leak site across 5 countries. Most recent disclosure .

Victims
14
0.1% of all tracked
Countries
5
Most: United States
Sectors
7
Most: Business Services
First seen
Feb 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Donutleaks and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Donutleaks, a data extorter active since August 2022, has targeted over a dozen organizations across five countries.

Who Donutleaks is

Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.

Recorded activity

Disclosures attributed to Donutleaks in this database run from February 2024 to July 2024, totalling 14 victims — 0.1% of everything tracked here. Donutleaks has listed victims in 5 countries in this database, most often United States, followed by Canada and Italy. The sectors appearing most in its listings are Business Services, Technology, Healthcare.

YARA detection rules

donutleaks.yar
/*
Donut Leaks extortion group
*/

rule DonutLeaks_Note
{
    meta:
        author = "ransomware.live"
        family = "ransomware.donutleaks"
        description = "Detects Donut Leaks extortion note"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $s1 = "Donut Leaks" ascii nocase
        $s2 = "donutleaks" ascii nocase
        $s3 = "donut.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Donutleaks, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Donutleaks has disclosed 14 victims on its leak site, 0.1% of all ransomware listings tracked in this database. Its earliest disclosure here dates to February 2024.

The group has listed organisations in 5 countries, most often in United States (8 victims), followed by Canada, Italy, Spain.

By industry, its listings concentrate in Business Services, Technology, Healthcare — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Donutleaks is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Donutleaks victims 14

Organization Disclosed
Industrial Bolsera
ESSpain
Jack "Designer" Sparrow.
CACanada
KickDown ESET company. No overpayments at 0% (renamed and update)
ESET. PREMIUM.
all-mode.com
USUnited States
labline.it
ITItaly
valleylandtitleco.com - UPD
USUnited States
valleylandtitleco.com
USUnited States
Patriot Machine
USUnited States
Pittsburgh’s Trusted Orthopaedic Surgeons
USUnited States
Good Morning
USUnited States
voidinteractive.net you are welcome in our chat
IRIran
Watsonclinic.com
USUnited States
DOD contractors you are welcome in our chat.
USUnited States

Frequently asked questions

What is Donutleaks ransomware?

Donutleaks is a ransomware threat group that has claimed 14 victims since its first known activity in February 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Donutleaks attacked?

Donutleaks has claimed 14 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Canada, Italy, Spain.

Which countries does Donutleaks target?

Donutleaks has attacked organizations in 5 countries. The top targeted countries are: United States, Canada, Italy, Spain.

Which industries does Donutleaks target?

Donutleaks most frequently targets the Business Services, Technology, Healthcare sectors based on victim disclosures in our database.

Is Donutleaks still active?

Donutleaks's most recent victim disclosure in our database was on July 24, 2024. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.