Orova — Ransomware Profile

Orova is an extortion operation that WatchGuard classifies as a data broker and records as first seen in May 2026. WatchGuard lists 24 known victims and reports that the group runs direct extortion, double extortion and free data leaks. Victim negotiation runs through a Tor-hosted portal separate from the leak site, and the group publishes a Tox identifier as an alternative contact channel.

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions