dunghill
- First seen
- 2023-01-01 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:49:20
Targeted industries: manufacturing technology-and-telecommunications retail-and-hospitality transportation-and-logistics
Context
Dunghill Leak is the publicly branded data leak site (DLS) operated by the Dark Angels ransomware group, established circa January 2023. Rather than a standalone encryption threat, it serves as the disclosure and extortion platform where stolen victim data is published if ransom demands are ignored. Dark Angels is known for highly targeted “big game hunting” tactics, exfiltrating tens to hundreds of terabytes of corporate data, often without encrypting systems. Victims include major industry players—like Johnson Controls, Sabre, Sysco, and a Fortune 50 firm—which reportedly paid a record-breaking $75 million USD ransom. The leak site is complemented by a mirrored Telegram channel for distributing victim announcements and maintaining negotiation traffic.
Reports & references
- zscaler.com — Shining Light Dark Angels Ransomware Group (report)
- isaca.org — Darkangels Strikes Big Record Breaking Ransom Secured (report)
- krebsonsecurity.com — Low Drama Dark Angels Reap Record Ransoms (report)
- ransomlook.io — Dunghill (report)
- watchguard.com — Dunghill Leak (report)
- techtarget.com — The Mystery Of The 75M Ransom Payment To Dark Angels (report)