Skip to content
WikiHidden

ep918

ep918 is a ransomware or data-extortion group catalogued by the ransomwatch project. Informational profile for defensive research.

Availability

Unknown

Not checked recently enough to say.

Last observed responding
Last checked
Status set by
Automated checks
Latest evidence
ransomwatch tracker

No official clearnet page is on file, so availability is not checked automatically.

Identity confidence

Low

The claim rests on a single source and identity has not been independently confirmed.

  • Supports confidence: No unresolved identity conflicts
  • Supports confidence: Status history is consistent
  • Weakens confidence: Single-source claim
  • Weakens confidence: Identity cannot be independently confirmed
  • Context: Never observed responding

Availability and identity are assessed separately. A responding endpoint does not show that it is operated by the entity it claims to be. Why this matters

What it is

ep918 is the name under which the open ransomwatch project catalogued a group that published, or claimed to publish, data taken from victims on a leak site. The project recorded one leak-site location for it.

The project links no published research for this name, so little about it is independently documented.

ransomwatch is archived, so this record is historical and says nothing about whether the group is active today. WikiHidden does not publish leak-site addresses, victim names or leaked material. Ransomware brand names are frequently reused, renamed and imitated, so a site using this name is not necessarily the group described here.

If you are affected

General guidance for organisations hit by ransomware or data extortion. It is not legal advice.

  • Isolate affected systems from the network, but do not switch them off: memory and logs are evidence.
  • Report it to the police and to your national cybersecurity agency or CERT. In many places, notifying the data-protection regulator is a legal duty with a short deadline.
  • Check whether a free decryption tool exists before considering anything else. No More Ransom: free decryption tools
  • Paying does not guarantee that data is restored or deleted, and in some jurisdictions payments to sanctioned groups are illegal.
  • Keep the ransom note, samples of encrypted files and all logs, and bring in incident-response specialists.

Availability history

Share of automated checks that received a response each day, over the last 90 days. This measures reachability only.

90 days agoNo automated checks in this periodToday

Status history

Every change of status, who made it and on what evidence.

  1. Unknown
    Imported from a public source. Availability has not been checked yet.Set automatically · Evidence: ransomwatch dataset

Timeline

  1. Last seen online by the ransomwatch tracker

    The last date on which the tracker recorded one of the group's leak sites responding.

Impersonation and scam reports

Only reports confirmed by a reviewer are listed. A report describes lookalikes of this entity; it is not a statement about the entity itself.

No confirmed reports. That is an absence of reports, not a guarantee that no impersonators exist.

Evidence history

The most recent accepted observations. Each records whether something responded and, separately, whether identity was assessed.

WhenResult
ransomwatch trackerRespondedIdentity: Not assessedLast date the tracker recorded a leak site responding.

Times are UTC.

References

Independent sources this profile relies on.

  1. ransomwatch — group catalogue (ep918)ransomwatch · Archive · accessed Oct 5, 2026