Active double-extortion group Β· 150+ victims Β· 2023β2025 activity
Cloak Ransomware β Incident Response & Technical Overview
Cloak is an active ransomware operation using
double extortion: encryption of systems combined with
publication of stolen data on a Tor-based leak site. Public leak data shows more than
150 victims since 2023, with recent activity across Europe and North America. Our DFIR
team supports you with structured containment, forensics
and secure recovery.
10+ years ransomware recovery
EU-based digital forensics & IR team
Cloak, Akira, LockBit, BlackCat & more