LIVE
LATEST THREAT: China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware THREAT ALERT ACTIVE
Intelligence DB / Group Profile RansomHouse

RansomHouse: The Data Extortion Group That Calls Itself a Security Marketplace

RansomHouse operates as a data extortion group that frames its activity as a security awareness service — blaming victims for poor security rather than framing attacks as crimes. With over 90 victims since 2022 and a recent escalation into large enterprise targets, this is a profile of how the group operates and who it targets.

By Ransomware Tracker ·
RansomHousedata-extortionransomwareAMDhealthcaremanufacturinggroup-profiledouble-extortionRage
Threat Level
8/10
Sectors Targeted
healthcare
manufacturing
finance
food-beverage
Ransomware Family
RansomHouse

Overview

RansomHouse is a data extortion and ransomware operation that has been active since late 2021, with the first publicly documented attacks appearing in early 2022. The group is distinctive in its self-presentation: rather than claiming to be criminals conducting ransomware attacks, RansomHouse describes its operations as a “security marketplace” exposing organisations with poor security practices. Ransom notes are framed as invoices for a security service. The group presents itself as doing victims a favour by identifying weaknesses before “real criminals” exploit them.

The self-justification rhetoric is operationally irrelevant — the attacks are financially motivated extortion — but understanding it matters for incident response teams, because RansomHouse uses this framing in negotiations and in communications with victims’ leadership. Organisations that receive initial contact from RansomHouse may encounter communications that appear, at first glance, to be from a legitimate security research firm.

Operations Model

RansomHouse operates primarily as a data extortion group. In many incidents, the group exfiltrates data and threatens to publish it without deploying encryption — making this a pure extortion model rather than ransomware in the encryption-as-a-service sense. In some incidents, the group has deployed Rage ransomware for encryption alongside data theft, using the double-extortion model. The choice appears to depend on the target and the assessed willingness to pay under threat of data disclosure alone.

The group maintains a dedicated leak site (DLS) on the Tor network where stolen data from non-paying victims is published. Victims who do not pay or who pursue legal remedies against the group are typically named publicly on the site with sample data releases before full publication.

RansomHouse is believed to operate as a closed group or small consortium, without the open affiliate recruitment model used by large RaaS operations like LockBit or RansomHub. The consistent TTP profile across incidents and the distinctive negotiation style suggests a small, consistent operational core.

Targeting Profile

RansomHouse targets mid-to-large enterprises across multiple sectors, with a concentration in manufacturing, healthcare, food and beverage, and technology. The group is geographically diverse, with confirmed victims across North America, Europe, Asia, and Africa. Unlike some ransomware groups that avoid specific countries (typically CIS states), RansomHouse does not appear to apply geographic exclusions.

Preferred targets appear to be organisations with significant data assets whose public exposure would create regulatory, reputational, or competitive damage — maximising extortion leverage. Healthcare organisations face the dual pressure of HIPAA notification obligations and patient sensitivity of the data involved. Manufacturing and industrial firms face supply chain visibility concerns if technical or commercial data is released.

Notable Incidents

AMD (April 2022): RansomHouse claimed responsibility for a breach of Advanced Micro Devices, alleging the theft of 450GB of data including source code, firmware, and employee credentials. AMD confirmed a breach investigation but disputed the full scope of the claims. The incident was significant as a demonstration that the group could breach major technology companies and that its leak-site strategy produced media coverage even when victim organisations did not confirm all claims.

Keralty (November 2022): The Colombian healthcare network, which operates clinics across Latin America and serves several million patients, was attacked in late 2022. Patient records and operational data were claimed stolen. The attack disrupted healthcare services at multiple facilities.

Tata Steel Netherlands (February 2023): The Dutch subsidiary of Tata Steel was among several manufacturing sector victims in early 2023, demonstrating the group’s willingness to attack major industrial targets.

Nichirei Corporation (July 2026): The Japanese food logistics company — one of Japan’s largest frozen food producers and distributors — was listed on the RansomHouse leak site in late July 2026, with the group claiming data exfiltration from corporate systems. The incident is consistent with RansomHouse’s pattern of targeting large, brand-sensitive companies where data disclosure creates reputational and commercial risk beyond regulatory exposure.

Initial Access and TTPs

RansomHouse does not have a documented signature vulnerability that it exploits consistently across all incidents. The group has been observed using:

  • Credential theft and phishing: Authentication credentials obtained through phishing or purchased from initial access brokers appear to feature in multiple incidents.
  • Exploitation of known vulnerabilities: The group has exploited unpatched vulnerabilities in internet-facing systems, consistent with opportunistic rather than targeted initial access.
  • SQL injection and application vulnerabilities: Some victim notifications and the group’s own communications have attributed initial access to web application vulnerabilities, with RansomHouse using this to reinforce its “poor security practices” narrative.

Post-compromise activity is consistent with other financially motivated groups: network enumeration, lateral movement to identify high-value data repositories, bulk exfiltration before any encryption or contact with the victim, and then either encryption deployment or direct extortion approach.

Negotiation Style

RansomHouse’s negotiation communications are notably more formal and framed as business correspondence than most ransomware groups. Initial contact typically includes a detailed description of the data claimed stolen, an assessment of the “security gaps” the group claims to have identified, and a demand framed as payment for “responsible disclosure” or “security services.”

Organisations that engage in negotiation report that RansomHouse negotiators present as measured and professional, in contrast to the aggressive or abusive tone used by some other groups. This approach appears designed to lower the defensive posture of victim organisations, encourage engagement, and extract payment from organisations that might otherwise immediately involve law enforcement and refuse to negotiate.

Defensive Implications

Data exfiltration monitoring is the critical detection point. Because RansomHouse frequently operates without deploying encryption, traditional ransomware detection based on file system encryption activity will not provide early warning. Monitoring for anomalous outbound data transfers — particularly large volumes to cloud storage endpoints, use of exfiltration tools like rclone or megacmd, or DNS resolution to uncommon file transfer services — is essential.

Prepare for a formal-sounding initial contact. Incident response plans should include guidance on how to recognise and respond to extortion contact that is styled as legitimate business correspondence. Legal should be involved immediately; do not engage with initial contact on the substance of claims before legal counsel has reviewed the communication.

Sensitive data inventory is the pre-condition for effective response. Understanding what data you hold and where it lives determines the damage assessment when exfiltration is claimed. Organisations that cannot quickly assess whether a claimed data set is genuine are at a negotiating disadvantage.

// Related Intelligence
Group Profile

Panzer: New RaaS Operation Rapidly Expands Global Victim List

Group Profile

Titan Ransomware: A New RaaS Group Behind a Nine-Victim, Single-Day Strike on Italian Firms

Group Profile

Gunra Ransomware: Conti-Derived RaaS Expands to Five Continents with Multi-Sector Targeting