DataCarry, also styled Datacarry or DATACARRY, is a financially motivated cybercriminal extortion group that emerged in 2025. The group is associated with leak-site operations and has been repeatedly described as conducting extortion-only campaigns centered on data theft and public exposure rather than widespread deployment of file-encrypting ransomware. Reported activity places its victimology across Europe and the Americas, with disclosed victims in at least eight countries. DataCarry has been linked to the compromise of Swedish HR and municipal IT supplier Miljödata, where stolen personal data affecting a large population was later published through the group’s dark web leak operation. The incident drew regulatory scrutiny in Sweden and demonstrated the group’s willingness to weaponize stolen sensitive personal information for coercion and reputational pressure. DataCarry has also been tied to exposure of employee data in downstream third-party breach reporting involving Volvo personnel. Sector reporting links DataCarry to targeting aviation, education, financial services, insurance, healthcare, and public-sector or municipal environments through service-provider compromise. The group has been associated with infrastructure support from bulletproof hosting providers, including PFCloud in one reporting stream. Its operational pattern is consistent with exfiltration-first intrusion activity followed by leak-based extortion, without confirmed reliance on encryption as the primary pressure mechanism. Known aliases and naming variants include DataCarry, Datacarry, and DATACARRY.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware actor/campaign linked to PFCloud bulletproof hosting and targeting aviation, education, finance, insurance, and healthcare.
Ransomware group claiming a breach of Swedish HR software supplier Miljödata, resulting in exposure of employee PII (including names and SSNs) affecting Volvo employees via a third-party vendor compromise.
DATACARRY is a ransomware group that, in 2025, specialized in data theft and extortion through public leaks, foregoing traditional ransomware encryption.
Ransomware group operating in Europe and the Americas, focusing on extortion without encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.