Triple X — Ransomware Profile
Triple X is a data-extortion leak-site operation first observed in May 2026, operating a Tor-based leak site and a companion onion file server. It has published only two claims: Indonesian state-owned bank Bank Negara Indonesia (BNI), advertised in part as free data with the remainder offered for sale via private messages on underground forums, and a US immigration law firm with an unusually large 1.5-terabyte claim. No encryptor, ransom note, or intrusion tooling has been attributed to the group, and neither victim has confirmed a breach. Its free-leak-plus-sale monetization pattern resembles a data-broker or re-leak operation rather than conventional ransomware extortion, and its claims should be treated with caution pending independent corroboration.
Recent claimed victims
Read the full analysis on IntelFusions