🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS    ◆    🔴 [LATEST] BREACHFORUMS ADMIN: HASANBROKER WAS A PREDATOR? DARK WEB FORUM WARS EXPLODE

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Global
RANSOMHOUSE

/actor/ransomhouse/  ·  1 intel report

Year Established
2021
Attribution
Unknown
Motivation
Financial
Modus Operandi (MO)
Data theft extortion without ransomware, marketplace model for stolen data, corporate targeting
Primary Aliases
Ransomhouse, RH

RansomHouse is a financially motivated threat actor that distinguishes itself from conventional ransomware operations through its explicit rejection of file-encrypting ransomware in favour of a pure data theft and extortion model. The group positions itself as a "marketplace" connecting data thieves with buyers and extorting victims simultaneously.

RansomHouse claims to have no interest in encrypting victim systems, arguing that such disruption is counterproductive and that stolen data alone provides sufficient leverage for extortion. This approach reduces collateral damage and operational complexity while maintaining comparable extortion pressure.

The group claimed responsibility for a significant attack on Advanced Micro Devices (AMD) in 2022, alleging the theft of 450 GB of data including research materials, financial information, and employee data. They have also targeted major healthcare organisations, hotel chains, and retail enterprises. RansomHouse maintains a data leak site where they publish victim profiles and sample data to demonstrate breach validity and pressure payment.

RansomHouse's "marketplace" framing and data-only approach reflects a broader evolution in the cybercriminal ecosystem toward sophisticated extortion operations that maximise financial return while minimising operational risk and law enforcement attention compared to disruptive ransomware deployments.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Aug 2026

> LINKED_INTEL_REPORTS (1)

> cd ../articles