[QILIN] – Ransomware Victim: haaker[.]com
![[QILIN] - Ransomware Victim: haaker[.]com 1 image](https://www.redpacketsecurity.com/wp-content/uploads/2024/09/image.png)
Ransomware Group: QILIN
VICTIM NAME: haaker[.]com
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating to the content of the files should be directed at the attackers directly, not RedPacket Security. This blog is simply posting an editorial news post informing that a company has fallen victim to a ransomware attack. RedPacket Security is in no way affiliated or aligned with any ransomware threat actors or groups and will not host infringing content. The information on this page is fully automated and redacted whilst being scraped directly from the QILIN Onion Dark Web Tor Blog page.
AI Generated Summary of the Ransomware Leak Page
The ransomware leak page tied to haaker[.]com is dated August 20, 2025 and is attributed to the group qilin. The post presents itself as a data-leak announcement following a compromise of the haaker[.]com domain, consistent with double-extortion patterns where stolen data is publicly disclosed. The metadata indicates the post originates from the Netherlands (NL). The page centers on internal business documents purportedly linked to the victim and includes a claim URL, signifying that the attackers are offering access to the leaked data and inviting verification. No ransom amount is explicitly stated in the visible excerpt; rather, the page frames the incident as a data exposure event with leaked materials described above the fold.
The page includes eight image thumbnails hosted on a Tor onion service, which appear to be screenshots of internal records. The described documents span several 2025 dates and include items such as invoices, purchase orders, a budget proposal, and commercial offers, illustrating procurement and financial activity associated with the victim. Personal contact details and credentials are present in the underlying data but are redacted in the public-facing text; the public post preserves the victim name (haaker[.]com) while omitting other company names found in the source material. Overall, the leak presents a data-leak narrative with multiple document images and a notional path to access the leaked material, but it does not disclose a specific ransom figure within the available excerpt.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.