Threat actor analysis
Snatch has disclosed 16 victims on its leak site, 0.1% of all ransomware listings tracked in this database. Its earliest disclosure here dates to January 2024.
The group has listed organisations in 8 countries, most often in United States (6 victims), followed by United Kingdom, India, France.
By industry, its listings concentrate in Public Sector, Business Services, Transportation/Logistics — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.
Like most current ransomware operations, Snatch is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.