Orova — Ransomware Profile
Orova is an extortion operation that WatchGuard classifies as a data broker and records as first seen in May 2026. WatchGuard lists 24 known victims and reports that the group runs direct extortion, double extortion and free data leaks. Victim negotiation runs through a Tor-hosted portal separate from the leak site, and the group publishes a Tox identifier as an alternative contact channel.Recent claimed victims
- Siddhi Green Excellence Pvt. Ltd 2026-09-20
- Euramex Management Group 2026-09-20
- Fu Sheng Industrial Co., Ltd 2026-08-31
- ASYS Corporation 2026-08-31
- ITC Properties Group Limited 2026-08-29
- South Pacific Hotel Limited 2026-08-29
- Bai-chi CPA Firm 2026-08-25
- Central Florida Civil LLC 2026-08-25
- Arich Enterprise Co., Ltd. 2026-08-25
- DL HOLDINGS GROUP 2026-08-19
- Smartsoft 2026-08-16
- Ganzhou Xinye Craft Co., Ltd. 2026-08-11
- Woodside Ranch 2026-08-06
- Magnolia Dental 2026-08-06
- St Theresa Catholic Church 2026-08-06
- First Baptist Church of Belleview 2026-08-06
- Stonecrest POA 2026-08-06
- Country Oaks Veterinary Clinic 2026-08-06
- Hilliard's Air Conditioning & Heating Inc 2026-08-06
- Stoneybrook West Master Association, Inc 2026-08-06
- Gemstone UK 2026-08-06
- David King Architect 2026-08-06
- FixIT Tek 2026-08-05
- SBI Manufacturing 2026-08-04
- EMPYREAN INT’L TECHNO DEVICES 2026-08-04
Vendor research
- OROVA Ransomware WatchGuard Technologies