Skip to main content
Back to Ransomware Database
Ransomware Group

ms13089

MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.

Known victims5

Threat Level

LOW

0

Check If You’re Affected

Search our database to see if your organization appears in ms13089’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request