Incident analysis
Cocoon was listed by Silent ransomware, a group with 6 victims recorded in this database. The listing appeared on the group's leak site on May 4, 2025.
Cocoon is based in United States. United States ranks #1 worldwide for ransomware disclosures, with 9,971 victims in this database.
Silent typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.