In barely twelve months of operation, NightSpire has compiled one of the most geographically diverse victim lists of any ransomware group active in 2025-2026. Ransomware.live tracks 166 known victims as of March 2026, spread across 33 countries — a number that represents only organizations whose data appeared on NightSpire's Tor-based leak site after refusing to pay. The actual victim count, including those who paid ransoms privately, is likely significantly higher.
Geographic Targeting
The United States accounts for over 40% of confirmed victims, consistent with broader ransomware trends. Secondary targeting is distributed across the United Kingdom, Japan, Italy, France, and India — each with 5-6 confirmed victims. But NightSpire's reach extends well beyond traditional ransomware targets: the group has hit organizations in South Africa (Eastern Cape Department of Human Settlements), Peru (Instituto Nacional de Oftalmologia), Taiwan (government and healthcare claims), Nigeria (Fidelity Pension Managers), Egypt, Vietnam, Mexico, Hungary, Brazil, and the UAE (Abu Dhabi Indian School). This global spread reflects purely opportunistic targeting driven by exposed attack surface rather than geopolitical motivation.
Sector Distribution
Manufacturing leads NightSpire's sector targeting at over one-third of victims, followed by technology and IT services, financial services, healthcare, construction, education, and retail. Notable 2026 victims include GoHighLevel, a major US-based SaaS platform (claimed February 28, 2026), Hyatt Place Chelsea New York (48.5 GB of VIP and client data compromised), and Taylor County Property Appraiser Office in Florida (claimed March 11, 2026). The group demonstrates no strong sector preference, consistent with its opportunistic exploitation of weak external security postures.
Acceleration in 2026
While NightSpire maintained a steady attack tempo through late 2025 — including days with three to four victim postings in November — the group entered 2026 with sustained momentum. February 2026 alone saw victims posted across the US, Germany, Japan, Hungary, Czech Republic, Brazil, and the UAE. New victims continued appearing on the leak site as recently as March 13, 2026, confirming the group is currently operating at full capacity.
Extortion Tactics
NightSpire applies extreme pressure on victims through countdown timers as short as two days on its leak site — among the most aggressive deadlines in the current ransomware landscape. Ransom demands range from $150,000 to $2 million depending on the target's size and perceived ability to pay. The group posts periodic large batches of victims in a single day to generate media attention and signal operational volume. Data leaked from non-paying victims includes banking and financial records, contracts, GDPR-protected personal data, employee documents, and client information.
Defensive Priorities
NightSpire's victim profile is overwhelmingly composed of small and medium-sized enterprises with fewer than 1,000 employees — organizations that typically lack dedicated security operations, run unpatched edge devices, and have inconsistent backup practices. The most impactful defensive action remains patching FortiOS to version 7.0.17 or later to close CVE-2024-55591, enforcing MFA on all remote access points, and monitoring for the group's characteristic exfiltration workflow: Everything.exe enumeration followed by 7-Zip staging and outbound WinSCP or MEGACmd connections.