APT / THREAT GROUP
Blackout
10
victims
1
aliases
Intelligence Profile
Ransomware
Threat Analysis
Blackout is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
Ransomware Victims (10)
CTIWATCH tracks 10 organizations claimed as victims by Blackout on its data leak site, with attack dates, sectors and countries.
View full victims list →Intelligence Reports Mentioning Blackout
Internet Starts to Return in Iran After 3-Month Blackout
Wired Security· May 26, 2026
In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking
SecurityWeek· May 22, 2026
Your Push Notifications Aren’t Safe From the FBI
Wired Security· Apr 11, 2026
Iranians Don’t Have a Missile Alert System, So Volunteers Built Their Own Warning Map
Wired Security· Mar 25, 2026
Iran internet blackout reaches 6th day as rights groups call for end to digital shutdown
The Record· Mar 6, 2026
External References
Quick Facts
TypeAPT / Threat Group
Aliases1
Also Known As
Blackout
Research Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.