Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Meow is a financially motivated extortion operation first seen in 2022 using a strain derived from leaked Conti code; after a 2023 free decryptor it abandoned encryption for data-theft extortion, running a 'Meow Leaks' marketplace, before activity tapered off through 2025.
Meow ransomware was first identified in August 2022 and initially built on Conti's leaked ransomware source code. After a disruptive free decryptor became available in March 2023, the operation abandoned encryption and pivoted to data-only extortion, evolving into a data-marketplace model branded 'Meow Leaks' / 'Market Meow Leaks' where stolen data is listed and sold, reportedly with e-commerce-style interfaces and dynamic pricing.
Activity peaked in 2024, when trackers recorded 80+ claimed attacks and dozens of victims posted to its leak site in a single quarter, spanning healthcare, financial services and manufacturing. Attribution is complicated by name collisions with unrelated 'Meow' database-wiping incidents, a point vendors such as Bitdefender have flagged.
By late 2025 reporting indicated Meow's activity and operational tempo had tapered off, raising questions about its trajectory. Its MENA-relevant claims include Oman and the UAE. All such listings are extortion claims and should be treated as unverified unless corroborated by a reputable source or the victim organization.