← Back to all threat actors

FIN8

Also known as Syssphinx
Tracked as G0061

FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.

How we source and review actor profiles
Motivation
ransomware
Sectors
retail, hospitality
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Syssphinx

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0061

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

FIN8Canonical Name
SyssphinxAlias
G0061Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...