Panzer — Ransomware Profile
Panzer is an extortion crew first observed on its Tor-based data-leak site in August 2026, and leak-site trackers have since recorded at least 17 claimed victims across at least eleven countries. WatchGuard profiles it as an emerging ransomware-as-a-service operation running double extortion, pairing data theft with encryption and listing a Tox contact channel, and notes early listings spanning education, media, jewelry, oil-and-gas and food businesses in Indonesia, Spain, Nigeria and Thailand. Claims against government bodies followed: DeXpose reported its late-August leak-site claim against Serbia's Government of Vojvodina, while the site has also listed Portugal's Directorate-General for Education, Spain's Castilla-La Mancha region and South Korea's DL E&C. Ransomware.live rates Panzer an emerging group and cautions that its claims remain unverified.
IntelFusions coverage (3)
Recent claimed victims
Read the full analysis on IntelFusions