← Back to feed
Breaches & RansomwareEmerging1 sourceAug 11, 2026 · 07:12via CyberPress

DeadLock Steals Corporate Data Before Encrypting Systems and Threatening Public Leaks

Brief

First seen in July 2025, the group has already listed more than 80 organizations on its leak site, known as the DeadLock blog .

More than half of the claimed victims are located in Europe, but attacks have also affected organizations across Asia, North America, South America, and Africa.

Targeted sectors include IT, mining, manufacturing, transportation, logistics, hospitality, and consumer goods.

DeadLock has also been linked to multiple cybercriminal groups, including an affiliate associated with the Lynx and INC ransomware ecosystems.

The operation follows the familiar double-extortion model: attackers first steal sensitive information, then lock files and use the threat of a public data leak to increase pressure on victims.

What makes DeadLock notable is its decentralized infrastructure.

Read more on CyberPress