Tracked intelligence for the pyrx ransomware group: victim-claim volume, leak-site availability, and activity status.
Related: the group dossier profiles a group's 365-day publishing rhythm and co-claims, group comparison puts two groups side by side, and the victim-claim directory lists the individual observed claims.
How to cite: Dragons Eye Ransomware Tracker, “pyrx ransomware group”, provider-observed ransomware claim data as of 2026-01-11, this page's URL. Keep the observed-claim caveat with any reused figures; the methodology documents the evidence model and the data-quality dashboard quantifies screening and exclusions.
Source: reconciled leak-site victim claims aggregated from documented public monitoring providers. Independent providers are distinguished from mirrors, and no provider count verifies an underlying allegation. Definitions for every term used here are in the glossary.
All ransomware groups · Intelligence overview
Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.