Metaencryptor ransomware group
Metaencryptor is one of the extortion operations we watch continuously. This page covers what is known about the group and the current state of its leak site, which we last saw change 18h ago.
Who they are
We are a group of young people who identify themselves as specialists in the field of network security with at least 15 years of experience. This blog and this work are ONLY commercial use, besides not the main one. We have nothing to do with politics, intelligence agencies and the NSB. If you are a hunter of other people's data, then download any files and (or) wait until the time expires for others and the files will be available here. If you have any personal suggestions, we are ready to consider them. Contact us on the "contacts" page. There are a lot of other data, for various reasons, not posted here and we can discuss their sale or transfer under certain conditions. Also, every incident is notified to all possible press in the region and data not intended for sale is transmitted to breached and similar forums. Subscribe to RSS, add to favorites, visit us more often.
Current status
Metaencryptor's leak site is not answering. Sites go dark for infrastructure trouble, a deliberate quiet period, or a takedown, and a good number return weeks later under the same name, so the entry stays on the list either way.
The last change we recorded on it was 18h ago (4 Sep 2026 18:00 UTC).
Which organisations this group has named, and when, is part of the SINON platform rather than this page. Create an account to search it, or to be told automatically if a name you care about turns up.
Sectors targeted
This group does not state an industry on its site, so we have nothing reliable to report. Most crews are opportunistic rather than sector-specific in any case — they hit what they can reach.
Watching for your name
If Metaencryptor posts your company, a supplier or a subsidiary, you want to hear it from us rather than from a journalist. SINON checks these sites continuously and alerts on the names you give it.
Start monitoring