DYSPHOR1A — Ransomware Profile
DYSPHOR1A is a data-leak extortion brand that surfaced on 20 August 2026, running a Tor v3 leak site alongside a mirror on free static hosting rather than operating Tor-only. It publishes stolen datasets for download or sale and offers paid removal of listings, a model the French security outlet ZATAZ described when it covered the group as a new extortion actor whose principal weapon is the threat of disclosure. No encryptor, ransom note or malware sample has been attributed to it, which places it with the extortion-only crews rather than with ransomware operators, and its own site records at least one listing withdrawn after a payment was received. We list no victims for this group, and that is a deliberate statement rather than a gap. The tracker we ingest first annotated DYSPHOR1A as a suspicious group whose victims it had been unable to confirm, then removed every one of its posts from the public feed. We had already imported seven claims during the window in which they were being served, covering organisations in Myanmar, Thailand, Indonesia and India, and we have withdrawn all seven. Two of them did not survive examination on their own terms: one listing's file manifest indicated the bulk of its records came from a Danish public job portal rather than the Myanmar company named in the title, and another consisted of personal data on named individuals that predated the period claimed. Treat any DYSPHOR1A listing as an unverified assertion by the seller until an affected organisation or a vendor confirms it. The brand is real and its leak site is live; what has not been established is that anyone named on it was actually breached.Also tracked as
Normal Hunters
IntelFusions coverage (1)
- A little-known crew claims three Myanmar targets 2026-09-07 · Cyber Incidents
Recent claimed victims
- RTAD GOV MM 2026-09-06
- CitizensPay 2026-09-05
- MBT Telecom 2026-09-04