TI

Titan Ransomware

Active

Threat actor group tracked in the global ransomware database ยท Last disclosure: Aug 20, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Manufacturing
25
Total Victims
0.1% of all tracked
10
Countries Targeted
10
Sectors Targeted
2026
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Titan and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Founded on 4 April 2026, Titan has recorded twenty-five victims globally across ten countries, striking hardest in Italy, Czech Republic, and the United States among others.

Who Titan is

Founded 4 April 2026

Recorded activity

Disclosures attributed to Titan in this database run from May 2026 to August 2026, totalling 25 victims โ€” 0.1% of everything tracked here. Titan has listed victims in 10 countries in this database, most often Italy, followed by Czech Republic and United States. The sectors appearing most in its listings are Manufacturing, Business Services, Technology.

Threat Actor Analysis

Titan is a ransomware threat group that has disclosed 25 victims in publicly accessible leak site data, representing 0.1% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Titan in our dataset dates to May 2026.

Geographically, Titan has targeted organisations in 10 countries. The most frequently targeted nation is Italy with 10 victim organisations. Other heavily targeted nations include Czech Republic, United States, India.

Industry-wise, Titan shows a concentration in the Manufacturing, Business Services, Technology sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime โ€” conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Titan likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 25 most recent of the 25 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 25 of 25)

# Organization Country Sector Date
1 Alto Calore Servizi SPA www.altocalore.it ๐Ÿ‡ฎ๐Ÿ‡น Italy Energy & Utilities Aug 20, 2026
2 CONDOR SPA www.condor-group.it ๐Ÿ‡ฎ๐Ÿ‡น Italy Manufacturing Aug 20, 2026
3 CTP S.r.l. ctpsrl.it ๐Ÿ‡ฎ๐Ÿ‡น Italy โ€” Aug 20, 2026
4 Elbor S.p.A. www.elbor.it ๐Ÿ‡ฎ๐Ÿ‡น Italy Manufacturing Aug 20, 2026
5 ELCON MEGARAD S.p.A elconmegarad.com ๐Ÿ‡ฎ๐Ÿ‡น Italy Manufacturing Aug 20, 2026
6 POEMA S.r.l. www.poemasrl.it ๐Ÿ‡ฎ๐Ÿ‡น Italy Other Aug 20, 2026
7 TECNOLOGICA S.r.l. tecnologicasrl.com ๐Ÿ‡ฎ๐Ÿ‡น Italy Technology Aug 20, 2026
8 Tedesco & Partners STP srl tedescoepartners.it ๐Ÿ‡ฎ๐Ÿ‡น Italy Professional Services Aug 20, 2026
9 Termotecnica Industriale S.r.l. termotecnica.it ๐Ÿ‡ฎ๐Ÿ‡น Italy Manufacturing Aug 20, 2026
10 PERTINENT HEALTHCARE BUSINESS SOLUTIONS PRIVATE LIMITED pertinenthbs.com ๐Ÿ‡ฎ๐Ÿ‡ณ India Healthcare Jul 21, 2026
11 PERTINENT HEALTHCARE BUSINESS SOLUTIONS PRIVATE LIMITED pertinenthbs.com ๐Ÿ‡ฎ๐Ÿ‡ณ India Healthcare Jul 21, 2026
12 Cooperate consulting CZ s.r.o. ๐Ÿ‡จ๐Ÿ‡ฟ Czech Republic Business Services Jul 13, 2026
13 DataOstrov s.r.o. ๐Ÿ‡จ๐Ÿ‡ฟ Czech Republic Technology Jul 13, 2026
14 Ozmit s.r.o. ๐Ÿ‡จ๐Ÿ‡ฟ Czech Republic โ€” Jul 13, 2026
15 Cooperate service CZ s.r.o. ghz-shop.cz ๐Ÿ‡จ๐Ÿ‡ฟ Czech Republic Business Services Jul 12, 2026
16 Eureka Construction INC eurekaconst.com ๐Ÿ‡บ๐Ÿ‡ธ United States Construction Jul 12, 2026
17 Apex Maritime Co., Inc. k-apex.kln.com ๐Ÿ‡ฐ๐Ÿ‡ท South Korea Transportation/Logistics May 30, 2026
18 SIRILAK SEAFOOD (PW) LTD. LK Agriculture and Food Production May 30, 2026
19 Abp Autoricambi Srl www.abpautoricambi.it ๐Ÿ‡ฎ๐Ÿ‡น Italy Manufacturing May 18, 2026
20 CRIT Tunisie www.crit-tunisie.net TN Business Services May 18, 2026
21 DFI AMERICA, LLC www.dfi.com ๐Ÿ‡บ๐Ÿ‡ธ United States Business Services May 18, 2026
22 ETM-ELECTROMATIC, INC. www.teledyneetm.com ๐Ÿ‡บ๐Ÿ‡ธ United States Manufacturing May 18, 2026
23 Groupe CRIT SA www.groupe-crit.com ๐Ÿ‡ซ๐Ÿ‡ท France Business Services May 18, 2026
24 Mezta Corporativo, S.A. de C.V. ๐Ÿ‡ฒ๐Ÿ‡ฝ Mexico โ€” May 18, 2026
25 Quahe Woo & Palmer LLC www.qwp.sg ๐Ÿ‡ธ๐Ÿ‡ฌ Singapore Business Services May 18, 2026

Frequently Asked Questions

What is Titan ransomware?

Titan is a ransomware threat group that has claimed 25 victims since its first known activity in May 2026. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Titan attacked?

Titan has claimed 25 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are Italy, Czech Republic, United States, India.

Which countries does Titan target?

Titan has attacked organizations in 10 countries. The top targeted countries are: Italy, Czech Republic, United States, India.

Which industries does Titan target?

Titan most frequently targets the Manufacturing, Business Services, Technology sectors based on victim disclosures in our database.

Is Titan still active?

Titan's most recent victim disclosure in our database was on August 20, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.