Backmydata is a ransomware threat actor associated with disruptive attacks in Romania. It is publicly linked to a February 2024 ransomware incident that forced more than 100 Romanian hospitals to take systems offline after healthcare management systems were impacted. The actor is therefore associated with ransomware operations targeting healthcare organizations and causing significant operational disruption to public services. High-confidence public reporting in this context supports classifying Backmydata as a financially motivated ransomware actor using encryption-based extortion, but does not provide sufficient corroborated detail on its origin, broader victimology, tooling, or additional aliases beyond the Backmydata name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation referenced as having disrupted healthcare management systems, knocking offline over 100 Romanian hospitals (Feb 2024).
Conducting ransomware attacks against healthcare organizations, disrupting healthcare management systems.
Backmydata is known for ransomware attacks, including a major incident in February 2024 that disrupted healthcare management systems in over 100 Romanian hospitals.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.