Genesis ransomware group
Genesis is one of the extortion operations we watch continuously. This page covers what is known about the group and the current state of its leak site, which we last saw change 17h ago.
Who they are
Financial interests only.
We do not provide or work with affiliate programs, no collaborations either.
The requested payment must be made within a specified time frame, otherwise the price may be increased, we will begin to publish the data we have about your company and notify the company's customers and suppliers.
Charitable, non-profit, and medical institutions are only hacked if they have reputation gaps known from open sources or discovered in company data. However, this is only data extraction; live support systems are not affected.
Data is always destroyed after payment; we do not attack the same company twice.
Interesting fact: once, the total amount of claims against a breached company exceeded its entire capitalization. We know how to create trouble, though it is in our mutual interest to avoid it.
To make the data leak more valuable, the most important information is published in a separate folder for each company called “parsed” and is also published on darkweb forums.
Current status
Genesis's leak site is answering our checks. That does not mean the group is actively posting — plenty of sites stay up for months with nothing new on them — but the infrastructure is live.
The last change we recorded on it was 17h ago (4 Sep 2026 19:21 UTC).
Which organisations this group has named, and when, is part of the SINON platform rather than this page. Create an account to search it, or to be told automatically if a name you care about turns up.
Sectors targeted
- A Healthcare Organization
- An International Public Company
Leak site capture
Watching for your name
If Genesis posts your company, a supplier or a subsidiary, you want to hear it from us rather than from a journalist. SINON checks these sites continuously and alerts on the names you give it.
Start monitoring