← Back to all threat actors

xp95

XP95 is a cyber-extortion group that emerged in March 2026, using a pure data-theft-and-extortion model with a Windows XP/95-themed leak site, with notable targets including Statistics South Africa (154 GB exfiltrated) and the Gauteng Provincial Government.

How we source and review actor profiles
Motivation
ransomware
Status
Dormant

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
Indicator1 indicator cataloged

Types: onion.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

xp95Canonical Name

Loading CVEs, techniques, indicators, malware, victims, and activity...