Back to Ransomware Database
Ransomware Group
ms13089
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
Known victims5
Threat Level
LOW
Check If You’re Affected
Search our database to see if your organization appears in ms13089’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request