A ransomware group calling itself AuditTeam added a new entry to its dark-web leak site on October 2, 2026, naming only a masked target it labeled “Ad***ng.” DeXpose, a dark-web monitoring firm, published the listing the next day, on October 3, under the headline “AuditTeam Targets Ad***ng in Latest Ransomware Attack.” The group’s domain field read “Unavailable,” the country field read “Undisclosed,” and the only concrete threat on record was a one-line note demanding contact: “The full leak will be published soon, unless a company representative contacts us via the channels provided,” according to DeXpose’s writeup.
That is the entire confirmed record of the latest attack. No sector, no stolen-data volume, no ransom figure, and no real company name have been verified by any outlet as of this writing. What makes the listing newsworthy is not the mystery victim, though. It’s the method. AuditTeam has built a short but consistent track record of partially blacking out victim names on its leak site, a pressure tactic designed to make a target recognizable to insiders while keeping the full name hidden from the public and from customers, long enough to extract a payment before the reveal.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
Add Now
What DeXpose Actually Reported About the Ad***ng Attack
The DeXpose incident report lists four fields: Target (“Ad***ng”), Domain (“Unavailable”), Country (“Undisclosed”), and Attacking Group (“AuditTeam”), with a Date Reported of October 2, 2026. The summary states that AuditTeam “claimed responsibility for a cyberattack against Ad***ng, an organization with undisclosed operational details,” and that the group “issued a threat to release sensitive data unless negotiations were initiated.”
That is a thinner disclosure than most ransomware news stories carry, and it’s worth being precise about why: AuditTeam itself withheld the identifying details, and DeXpose reported exactly what the leak site showed, no more. Outlets including Escudo Digital and Bhaskar English have aggregated the same DeXpose listing into their own threat trackers, but none have independently unmasked the victim as of October 4. Any claim about the real company behind “Ad***ng,” its industry, its location, or the volume of data taken would be speculation rather than reporting at this stage, so this analysis treats those specifics as unconfirmed rather than guessing at them.
What is confirmed is the pattern this listing fits into. AuditTeam has run the same partial-mask playbook on at least one other victim earlier this year, and that precedent is where the real story sits.
Who Is AuditTeam? A Six-Month-Old Extortion Operation
AuditTeam is a relatively young double-extortion crew. Its debut postings landed on the ransomware-tracking aggregator ransomware.live on April 8, 2026, naming Kawasaki Motors Philippines Corporation and South Korean game developer Joycity as its first two victims, according to research cited by BeforeCrypt’s AuditTeam profile. In the Joycity case, the group claimed to have stolen internal data and source code.
Threat-intelligence tracker IntelFusions, which has followed the group’s leak-site activity closely, counted 24 listings across 13 countries as of September 20, 2026. Of those, 10 were Russian organizations, making Russia the group’s single most frequently hit country despite the operation showing no exclusive regional focus, per the IntelFusions report. Eight of the 24 listings never resolved to a disclosed company name at all, instead sitting under a “Paid Victim” tag followed by a 16-character hexadecimal identifier, a detail that matters for understanding how this group operates and for interpreting any victim count attached to its name.
Sector-wise, AuditTeam’s confirmed and partially confirmed victims span manufacturing and industrial services (including a heating-substation contractor and a steel-products maker), technology and software firms, gaming studios, transportation and automotive companies, agriculture, retail and e-commerce, education, and IT services. Researchers at BeforeCrypt describe the targeting pattern as opportunistic rather than tied to one industry or one region.
The Victim-Masking Playbook: Why “Ad***ng” Isn’t a Typo
AuditTeam’s signature move is showing just the first two and last two characters of a victim’s name, with the middle blacked out by asterisks. “Ad***ng” fits that exact format. IntelFusions documented the same pattern with a Saint Petersburg engineering firm it eventually identified as TEK SPB, which sat on the leak site under the masked label “TE***PB” for roughly eight days before AuditTeam published the full name on September 20, 2026.
Based on that case and others IntelFusions tracked, the gap between a masked listing going live and a full reveal has run roughly seven to eleven days. If the Ad***ng listing follows that same window, a full name disclosure (absent a payment) would land somewhere around October 9 through October 13, 2026. That is a pattern-based estimate drawn from the group’s prior behavior, not a confirmed date.
The mechanism behind the tactic is straightforward psychological leverage. A masked entry lets a targeted organization’s own employees, customers, or partners recognize that it has likely been hit, since the first and last letters are rarely ambiguous to anyone who already knows the company. At the same time, withholding the full name protects the broader public from immediately identifying the victim, which gives the victim organization a reason to pay before the clock runs out rather than after the damage to its reputation is already done. IntelFusions called the specific combination of masked entries and later “Paid Victim” relabeling distinctive within the incidents it had reviewed up to that point.
AuditTeam’s Known Victim Trail in 2026
Piecing together reporting from BeforeCrypt, IntelFusions, Red Piranha, Scrutex, and ransomware.live produces the clearest available timeline of AuditTeam’s public activity so far this year. Note that the counts below come from different trackers using different methodologies, so they should be read as a reconstruction rather than a single authoritative ledger.
| Victim / Listing | Country | Sector | Masking Status | Date |
|---|---|---|---|---|
| Kawasaki Motors Philippines Corporation | Philippines | Automotive / motors | Named at posting | April 8, 2026 |
| Joycity | South Korea | Video game developer | Named at posting | April 8, 2026 |
| TEK SPB | Russia | Heating-substation engineering | Masked “TE***PB” ~8 days, then named | Named Sept. 20, 2026 |
| Wise IT | Undisclosed | IT services | Identified during weekly tracking | Week of Sept. 14-20, 2026 |
| gownet.net / dg.ac.kr domains | South Korea | Undisclosed | Partially identified | Sept. 14-20, 2026 |
| ProMind IT (per ransomware.live) | Undisclosed | IT services | Discovered Oct. 1; estimated attack Sept. 22 | Oct. 1, 2026 |
| “Ad***ng” (current listing) | Undisclosed | Undisclosed | Masked, awaiting reveal | Reported Oct. 2, 2026 |
Separately, security blog Hookphish and tracker GalaxyWarden both logged a “Paid Victim” entry tagged with the hexadecimal identifier 32373ffb7af7e725 under AuditTeam’s name in September 2026, one of the eight listings IntelFusions counted that never got a public company name attached, per GalaxyWarden’s tracking.
Inside the Leak Site: “Data Exposure Terminal”
AuditTeam’s Tor-hosted leak site brands itself with the header “/// DATA EXPOSURE TERMINAL ///.” Each victim entry is formatted as an “AUDIT ENTITY” record, stamped with a 16-character hexadecimal “AUDIT ID” and a “DISCOVERY DATE” field, according to BeforeCrypt’s teardown of the site’s structure. A separate Tor-hosted file server, labeled “[ SYSTEM ERROR ],” is reportedly where AuditTeam stages the actual stolen files once a leak goes live.
That bureaucratic, audit-log aesthetic (entities, IDs, discovery dates) is itself part of the intimidation design common across 2026’s leak-site operators: it frames the extortion as a procedural inevitability rather than a one-off crime, implying the organization was simply “discovered” and logged like a routine compliance finding rather than deliberately hunted.
Double Extortion, Explained
AuditTeam fits the double-extortion model that has dominated ransomware economics since the technique was popularized several years ago: attackers steal data before or during encryption, then threaten to publish it separately from any demand to unlock scrambled files, as outlined in DeXpose’s explainer on the tactic. That gives a victim two separate reasons to pay. Even an organization that restores every system from backup, with zero downtime, still faces the second half of the threat: public exposure of whatever was copied out the door before encryption started.
AuditTeam’s masking twist adds a third pressure point on top of the standard two: reputational ambiguity. A fully named leak-site post is a known quantity for a victim’s PR and legal teams to manage. A masked post is a live countdown with an unknown blast radius, which appears designed to push a decision faster than a fully disclosed listing would.
How AuditTeam Fits Into 2026’s Ransomware Surge
AuditTeam is a small operator inside a very large and still-growing ecosystem. Group-IB data summarized by TechInquirer and covered previously on this site put leak-site activity at 2,393 attacks across 79 active groups in the first quarter of 2026 alone, rising to 2,202 victims across 92 groups in the second quarter. Check Point Research separately tracked 2,122 victims in Q1 2026, down slightly from 2,416 in the fourth quarter of 2025, but also recorded the ransom payment rate falling to roughly 23% in Q2 2026, which Check Point described as a multi-year low.
Monthly tracking tells a similarly busy story. Comparitech data summarized by Red Sheep Security counted 997 leak-site claims in August 2026 alone, close to 32 per day, driven heavily by established players like Qilin and resurgent groups like Clop, per the Red Sheep Security breakdown. A separate tracker cited by Shattered.io logged 873 claimed victims in July 2026, up from 722 in June, continuing a summer-long upward trend documented in Shattered.io’s August surge report.
| Source / Tracker | Metric | Figure | Period |
|---|---|---|---|
| Group-IB (via TechInquirer) | Leak-site attacks | 2,393 attacks, 79 active groups | Q1 2026 |
| Group-IB (via TechInquirer) | Victims listed | 2,202 victims, 92 groups | Q2 2026 |
| Check Point Research | Victims listed | 2,122 (vs. 2,416 in Q4 2025) | Q1 2026 |
| Check Point Research | Ransom payment rate | ~23% (multi-year low) | Q2 2026 |
| Comparitech (via Red Sheep Security) | Leak-site claims | 997 claims (~32/day) | August 2026 |
| Tracker cited by Shattered.io | Claimed victims | 873 (up from 722 in June) | July 2026 |
| IntelFusions | AuditTeam listings | 24 across 13 countries | Through Sept. 20, 2026 |
Set against that backdrop, AuditTeam’s reported tally of two dozen listings since April is a rounding error next to the roughly 2,200 victims the broader ecosystem logs in a single quarter. What makes it worth tracking isn’t scale, it’s the masking format, which several other groups appear to be converging toward as payment rates slide and public shaming becomes a larger share of the pressure campaign.
Why Victim Counts for the Same Group Keep Disagreeing
Anyone trying to pin down “how many victims has AuditTeam hit” runs into a methodology problem that is specific to groups using partial disclosure. Red Piranha’s weekly threat-intelligence report counted 11 AuditTeam listings during the September 7-13 window, all initially redacted, per Red Piranha’s report. Scrutex, tracking the following week, also counted 11 new listings, of which six had become identifiable by the time of publication, according to its weekly ransomware roundup.
Those numbers don’t reconcile cleanly with IntelFusions’ cumulative count of 24 through September 20, and that’s the point: when a group relabels paid victims as generic hex-coded entries instead of deleting the post, a tracker that counts named companies will show a lower total than one that counts every leak-site entry regardless of whether a name was ever attached. Analysts have flagged this as a reason to treat any single “AuditTeam has hit X victims” headline as a snapshot of one tracker’s methodology rather than a hard total.
Competitive Comparison: How AuditTeam Stacks Up Against Other 2026 Leak-Site Operators
AuditTeam is one of dozens of active leak-site brands in 2026, and it looks small next to several groups that have made headlines on this site in recent months. KillSec, for instance, had grown large enough that authorities eventually seized 110TB of data when they arrested its teenage ringleader, a scale AuditTeam’s reported two dozen listings doesn’t approach. ShinyHunters, meanwhile, has been tied to roughly 7.1 million exposed records across a string of high-profile breaches, cementing it as one of 2026’s most prolific extortion brands, as detailed in this site’s profile of the group.
Even among smaller operators, AuditTeam’s masking habit stands out. A group that named New Zealand insurer Tower on its leak site, claiming more than 207 total victims across its campaign, published that victim’s name outright rather than redacting it, per earlier coverage of that claim. AuditTeam’s choice to partially mask names, rather than simply naming and shaming immediately, suggests a group that is explicitly optimizing for negotiation leverage over maximum public pressure, at least for now.
Market Impact: Insurance, Incident Response, and Disclosure Pressure
For organizations that find themselves staring at a masked listing that could plausibly be their own name, the masking tactic creates a genuinely difficult decision window before any facts are even confirmed. Cyber insurers have been adjusting pricing and coverage terms throughout 2026 partly in response to this kind of pressure campaign; the gap between budget-tier and enterprise-tier cyber coverage has widened to hundreds of millions of dollars in aggregate limits across carriers, as this site covered in its comparison of Coalition, Chubb, and At-Bay’s cyber policies.
The broader trend of rising stolen-data volumes, even as encryption-driven downtime incidents plateau in some sectors, has also been documented in schools and hospitals, where data-theft-only extortion (skipping encryption entirely) has reportedly surged 275% year over year, according to this site’s earlier reporting on that trend. AuditTeam’s threat against “Ad***ng” follows that same data-theft-first script: no encryption event has been disclosed, only a threat to publish stolen material.
Historical Context: From Instant Naming to Teaser Disclosure
Ransomware leak sites have evolved considerably since the double-extortion model first took hold industry-wide. Early leak sites typically named a victim immediately and attached sample files within days. Over the past two years, and accelerating through 2026, several operators have shifted toward staged or partial disclosure: teaser posts, redacted names, delayed file drops, and now AuditTeam’s specific first-two/last-two-character masking format. Industry trackers describe this broader shift as a function of falling payment rates: as fewer victims pay on the first demand, groups have more incentive to extend the pressure campaign across days or weeks rather than making a single all-or-nothing disclosure.
The “Paid Victim” relabeling IntelFusions documented, rather than simply deleting a resolved listing, is itself a variant of this strategy: it keeps a visible record that a case existed (useful leverage for future targets watching the site) while technically removing the specific company’s exposure once payment clears.
What Happens Next: Predictions
1. A reveal or a “Paid Victim” relabel is likely within the group’s established window. Based on the roughly seven-to-eleven-day gap AuditTeam has shown between masking and disclosure in the TEK SPB case, expect the “Ad***ng” listing to either convert to a full name or disappear into a generic “Paid Victim” tag sometime between October 9 and October 13, 2026, absent any independent confirmation beforehand.
2. More groups will copy the partial-masking format. With Check Point’s tracked payment rate sitting near a multi-year low of 23%, operators have a direct financial incentive to extend pressure windows rather than disclose everything up front, and AuditTeam’s approach is a replicable template other small crews are likely to test.
3. Victim-count disputes around AuditTeam will continue. As long as the group keeps relabeling resolved cases as hex-coded “Paid Victim” entries instead of deleting them, expect trackers like Red Piranha, Scrutex, and IntelFusions to keep publishing different totals for the same underlying activity.
4. AuditTeam’s targeting will keep skewing toward mid-sized organizations. Its confirmed and partially confirmed victim list, spanning manufacturing, gaming, IT services, and education, points to opportunistic targeting of organizations without the dedicated detection resources that larger enterprises increasingly have in place.
5. Attribution questions will persist. Six months into its public activity, no researcher has tied AuditTeam to a known ransomware-as-a-service brand or a previously catalogued encryptor family. Expect that gap to remain open until a malware sample, leaked chat logs, or infrastructure overlap surfaces.
What Organizations Should Do Right Now
DeXpose’s own guidance for organizations worried about a masked listing is straightforward and echoes standard incident-response advice: monitor dark-web and infostealer channels continuously, run a compromise assessment rather than assuming a listing is unrelated, verify that backups are current and stored offline or immutable, feed threat-intelligence indicators into existing SIEM or XDR tooling, enforce multi-factor authentication broadly, and bring in incident-response professionals and legal counsel before any direct contact with a threat actor. None of that guidance changes because a name happens to be partially hidden. If anything, the uncertainty built into a masked listing is exactly why skipping the verification step in favor of guessing is the wrong move for any security team watching this story unfold.
Frequently Asked Questions
What is AuditTeam ransomware?
AuditTeam is a double-extortion ransomware and data-theft group that runs a Tor-hosted leak site, first publicly tracked in April 2026, which steals data and threatens to publish it unless a victim organization negotiates.
Who did AuditTeam target in its October 2026 attack?
DeXpose reported on October 3, 2026, that AuditTeam claimed an attack against an organization it listed only as “Ad***ng,” with the domain, country, and sector all undisclosed. No outlet has independently confirmed the real company name as of this writing.
Why is the victim’s name shown as “Ad***ng” instead of a full name?
AuditTeam routinely masks victim names on its leak site by showing only the first two and last two characters, replacing the middle with asterisks. Researchers at IntelFusions have documented full reveals following roughly seven to eleven days after a masked posting in at least one other case.
How many victims has AuditTeam claimed in 2026?
Counts vary by tracker. IntelFusions counted 24 listings across 13 countries through September 20, 2026, while weekly reports from Red Piranha and Scrutex counted roughly 11 new listings per week in mid-September, with some overlap and some relabeled as generic “Paid Victim” entries rather than named companies.
Is AuditTeam tied to a known ransomware-as-a-service operation?
No confirmed attribution exists. Researchers have not linked AuditTeam to a known encryptor family or an established ransomware-as-a-service affiliate program based on currently available evidence.
What should an organization do if it suspects a masked listing refers to it?
Security researchers recommend treating a masked listing as a credible warning sign: launch a compromise assessment, verify backup integrity, check dark-web monitoring tools for related indicators, and involve incident-response professionals and legal counsel before any contact with the threat actor.
Does paying a ransom guarantee a listing gets removed?
Not necessarily. In at least one documented AuditTeam case, a resolved listing was relabeled as a generic hex-coded “Paid Victim” entry rather than deleted outright, meaning a record of the incident can persist even after payment.
How does AuditTeam’s masking tactic compare to other ransomware groups?
Most leak-site operators name a victim immediately. AuditTeam’s staged, partial-disclosure format is less common, though it fits a broader 2026 trend toward teaser-style leak-site postings as overall ransom payment rates have fallen toward roughly 23%, according to Check Point Research.
