Threat Group Profile
ms13089
● Active — last 30 days
Victim claims
2
First seen
May 2026
Last activity
15 Aug 2026
Tracked since
Dec 2025
Group overview
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
Preferred targets
Consumer Services · 1
Other · 1
Most targeted countries
US · 1
CL · 1