Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
GhostSec is a hacktivist collective that developed the GhostLocker ransomware and ran joint RaaS operations with Stormous before publicly announcing a return to hacktivism in May 2024, handing GhostLocker's continuation to Stormous while continuing ideologically driven attacks.
GhostSec began as a hacktivist collective and, in October 2023, launched GhostLocker, a ransomware-as-a-service offering. It later fielded GhostLocker 2.0, a Golang rewrite, and conducted joint ransomware operations with Stormous, both part of the self-styled 'Five Families' cybercrime alliance (alongside ThreatSec, Blackforums and SiegedSec). Cisco Talos and others documented the group's expanding arsenal and cross-group tooling during this period.
On 15 May 2024, GhostSec announced it was stepping back from cybercrime and returning to hacktivism, stating it had secured sufficient funding, and said Stormous would take over management of GhostLocker, including transfer of existing clients and sharing of the GhostLocker V3 source code. As of 2025 the Stormous RaaS program continued as an apparent continuation of GhostLocker, while GhostSec resumed ideologically motivated operations.
GhostSec's hacktivist targeting has repeatedly focused on Israel and regional interests, with website defacements carrying pro-Palestinian messaging, and claimed activity across MENA including Lebanon, Israel, Egypt, Qatar, Turkey and Morocco. These claims are largely self-reported via Telegram and leak channels and should be treated as unverified unless confirmed by a reputable source.