Blackwater is a ransomware and data-extortion threat group that emerged in 2026 and operates a leak site used to name victims and threaten publication of stolen data. Reported activity links the group to intrusions affecting organizations in healthcare, energy and utilities, hospitality and tourism, professional services, and other sectors across multiple countries. Victim reporting and leak-site claims indicate Blackwater conducts ransomware operations involving system disruption, data theft, and public extortion deadlines tied to release of allegedly stolen information. In some incidents, victims were described as experiencing system breaches and data blocking consistent with encryption-based ransomware, while other cases emphasized threatened publication of confidential data on the group’s leak site. Blackwater has claimed attacks against organizations in the United States, India, Argentina, Brazil, China, and Turkey. Publicly reported healthcare-related activity includes a claim of responsibility for the April 2026 cyber incident at Minidoka Memorial Hospital in Idaho, where the victim reported temporary disruption to internal systems and imaging services. Blackwater appears to be a newly surfaced actor or possible rebrand; however, no high-confidence attribution to a state sponsor or specific criminal ecosystem is established from the available facts. No corroborated sub-groups or additional aliases are established beyond Blackwater.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack involving system breach and data blocking against www.amca.org.ar.
Conducting a ransomware attack involving system breach and data blocking against www.shalina.com.
Conducting a ransomware attack and data breach against msgas.com.br, with stolen data described as customers’ personal data, contract information, and internal company data.
Conducting a ransomware attack against txdkj.com and threatening release of confidential data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.