ransomhouse
Known ransomware group ACTIVE Currently active
RansomHouse is an extortion group active since 2021 that positions itself as a "data disclosure" broker, frequently claiming it does not deploy encryptors but instead monetizes stolen data. It has been associated with the White Rabbit and Mario ESXi ransomware tooling.
3
Total Claims
1
Critical
—
Records Claimed
3
Industries Hit
Active span: May 17, 2026 – Sep 12, 2026 · 3 organizations targeted
Currently active
Actor Threat Profile
Activity Timeline
Peak: May 2026 (1)May 2026
LessMore
Sep 2026Top Targeted Industries
Government & Defense 1
Education 1
Healthcare 1
Tradecraft & Infrastructure
0
Documented tools
0 / 0
MITRE tactics / techniques
3
Known leak sites
Targeted Organizations
Claims by ransomhouse
Low
Ransomware Claim: Namibian Defence Force
Namibian Defence Force
ransomhouse
Ransomware Government & Defense
Sep 17, 2026 Low
Ransomware Claim: California School Employees Association
California School Employees Association
ransomhouse
Ransomware Education
Sep 11, 2026 Critical
Ransomware Claim: Hospital Clinic de Barcelona
Hospital Clinic de Barcelona
ransomhouse
Ransomware Healthcare
May 22, 2026