L Group — Ransomware Profile

L Group is a data-extortion operation whose Tor-based leak site surfaced in early August 2026, debuting with roughly 26 posts in a single day per DataBreach.com, which named it one of eight new leak-site brands that month and cautioned that a new brand is not necessarily a new gang and that leak-site posts are not verified breaches. The site has listed at least 28 organizations across roughly 15 countries, most as bare domains, spanning education, agriculture, government, manufacturing and technology; claims include Brazil's Universidade Veiga de Almeida and, per DeXpose, Venezuelan cloud host DaycoHost. Ransomware.live likewise labels it an emerging group whose claims warrant caution pending verification, estimating its earliest claimed attack dates back to February 2025, and RansomLook recorded its latest post on 23 August 2026, with the site since intermittently offline.

IntelFusions coverage (1)

Recent claimed victims

Read the full analysis on IntelFusions