Signals before
impact.
An operational map of data leaks, extortion, and public exposure, with a confidence level on every signal.
Incident stream
Updated just now · 383 events · Toronto time
Schumacher Homes
AIQilin claims to have breached construction firm Schumacher Homes, according to a listing on Ransomware.live.
Huntress
AIIcarus claims to have breached technology firm Huntress, per an unverified extortion listing on ransomware.live.
HDS (Hdscorp)
AIIcarus claims to have listed HDS (Hdscorp) on Ransomware.live's extortion site; the listing is unverified.
Gms-net
AIIcarus claims to have compromised Gms-net, a technology firm, in an unverified listing on Ransomware.live.
Cqcrm
AIIcarus claims to have listed Cqcrm, a business services firm, on the Ransomware.live extortion site. The claim is unverified.
Cbassociations
AIIcarus claims to have data from Cbassociations, a business services firm, as listed on their extortion site.
EON Meditech Pvt
AICMD Organization claims to have breached EON Meditech Pvt, a healthcare company, per an unverified listing on Ransomware.live.
graymont.com
AIChaos claims to have breached manufacturing firm graymont.com, listing it on its extortion site. The claim is unverified.
eggetttax.ca
AIBrainCipher claims to have data from eggetttax.ca, an agriculture and food production organization, per a listing on Ransomware.live. This claim is unverified.
sterlinggloballtd.com
AIBrainCipher claims to have breached sterlinggloballtd.com, listing the business services firm on its extortion site.
sisacloud.com
Historical breach catalogued by RansomLook: sisacloud.com exposing 992,887 records (148.68 M), originally indexed 2026-06-03.
cocacolaep.com
Historical breach catalogued by RansomLook: cocacolaep.com exposing 13,370,207 records (2 G), originally indexed 2026-06-03.
urssaf.fr
Historical breach catalogued by RansomLook: urssaf.fr exposing 689,415 records (152.59 M), originally indexed 2026-06-03.
ultracube-mc
Historical breach catalogued by RansomLook: ultracube-mc exposing 734 records (159.27 K), originally indexed 2026-05-26.
starblast-mc
Historical breach catalogued by RansomLook: starblast-mc exposing 22,917 records (8.33 M), originally indexed 2026-05-26.
velenhq-mc
Historical breach catalogued by RansomLook: velenhq-mc exposing 207 records (42.26 K), originally indexed 2026-05-26.
destinypvp-mc
Historical breach catalogued by RansomLook: destinypvp-mc exposing 2,596 records (408.13 K), originally indexed 2026-05-26.
heavennetwork-mc
Historical breach catalogued by RansomLook: heavennetwork-mc exposing 1,358 records (387.06 K), originally indexed 2026-05-26.
averfight-mc
Historical breach catalogued by RansomLook: averfight-mc exposing 2,008 records (777.62 K), originally indexed 2026-05-26.
andaria-mc
Historical breach catalogued by RansomLook: andaria-mc exposing 6,748 records (1.41 M), originally indexed 2026-05-26.
darkfight-mc
Historical breach catalogued by RansomLook: darkfight-mc exposing 638 records (244.12 K), originally indexed 2026-05-26.
snkmcfr-maria-mc
Historical breach catalogued by RansomLook: snkmcfr-maria-mc exposing 11,636 records (1.82 M), originally indexed 2026-05-26.
funcloud-mc
Historical breach catalogued by RansomLook: funcloud-mc exposing 256,141 records (36.99 M), originally indexed 2026-05-26.
venaria-mc
Historical breach catalogued by RansomLook: venaria-mc exposing 1,654 records (348.92 K), originally indexed 2026-05-26.
freegen-mc
Historical breach catalogued by RansomLook: freegen-mc exposing 9,712 records (4.38 M), originally indexed 2026-05-26.
odeliamc-mc
Historical breach catalogued by RansomLook: odeliamc-mc exposing 6,322 records (1.1 M), originally indexed 2026-05-26.
taliaxcold-mc
Historical breach catalogued by RansomLook: taliaxcold-mc exposing 4,948 records (887.47 K), originally indexed 2026-05-26.
sparksmc-mc
Historical breach catalogued by RansomLook: sparksmc-mc exposing 3,224 records (684.41 K), originally indexed 2026-05-26.
seasonsky-mc
Historical breach catalogued by RansomLook: seasonsky-mc exposing 2,192 records (468.47 K), originally indexed 2026-05-26.
nostalgiamc-mc
Historical breach catalogued by RansomLook: nostalgiamc-mc exposing 2,895 records (517.48 K), originally indexed 2026-05-26.
hardfight-mc
Historical breach catalogued by RansomLook: hardfight-mc exposing 2,044 records (784.97 K), originally indexed 2026-05-26.
nerdland-mc
Historical breach catalogued by RansomLook: nerdland-mc exposing 35,929 records (5.82 M), originally indexed 2026-05-26.
oneblock-mc
Historical breach catalogued by RansomLook: oneblock-mc exposing 14,018 records (2.38 M), originally indexed 2026-05-26.
xeonzia-mc
Historical breach catalogued by RansomLook: xeonzia-mc exposing 1,110 records (681.62 K), originally indexed 2026-05-26.
stormfight-mc
Historical breach catalogued by RansomLook: stormfight-mc exposing 3,699 records (1.39 M), originally indexed 2026-05-26.
ytalliumnetwork-mc
Historical breach catalogued by RansomLook: ytalliumnetwork-mc exposing 985 records (173.44 K), originally indexed 2026-05-26.
allforonesurvival-mc
Historical breach catalogued by RansomLook: allforonesurvival-mc exposing 3,272 records (599.57 K), originally indexed 2026-05-26.
pixworld-mc
Historical breach catalogued by RansomLook: pixworld-mc exposing 5,592 records (1.14 M), originally indexed 2026-05-26.
pixelax-mc
Historical breach catalogued by RansomLook: pixelax-mc exposing 8,173 records (2.17 M), originally indexed 2026-05-26.
skylord-mc
Historical breach catalogued by RansomLook: skylord-mc exposing 1,244 records (272.99 K), originally indexed 2026-05-26.
snkmcfr-shina-mc
Historical breach catalogued by RansomLook: snkmcfr-shina-mc exposing 7,305 records (1.2 M), originally indexed 2026-05-26.
elitios-mc
Historical breach catalogued by RansomLook: elitios-mc exposing 695 records (124.39 K), originally indexed 2026-05-26.
wizardmc-mc
Historical breach catalogued by RansomLook: wizardmc-mc exposing 2,400 records (498.92 K), originally indexed 2026-05-26.
voltclicker-mc
Historical breach catalogued by RansomLook: voltclicker-mc exposing 582 records (294.24 K), originally indexed 2026-05-26.
over2craft-mc
Historical breach catalogued by RansomLook: over2craft-mc exposing 4,379 records (941.11 K), originally indexed 2026-05-26.
legacyfight-mc
Historical breach catalogued by RansomLook: legacyfight-mc exposing 5,178 records (894.01 K), originally indexed 2026-05-26.
soleriamc-mc
Historical breach catalogued by RansomLook: soleriamc-mc exposing 15,007 records (2.92 M), originally indexed 2026-05-26.
ironcraft-mc
Historical breach catalogued by RansomLook: ironcraft-mc exposing 7,185 records (3.49 M), originally indexed 2026-05-26.
energyfight-mc
Historical breach catalogued by RansomLook: energyfight-mc exposing 2,309 records (1.45 M), originally indexed 2026-05-26.
NEW PRINZ EUGEN SITE [NOT A CASE FILE]
AIPrinz Eugen claims to have listed NEW PRINZ EUGEN SITE on its extortion site. The claim is unverified.
Ntd Apparel
AIThe Akira ransomware group claims to have breached Ntd Apparel, a Consumer Services firm, per an unverified listing on Ransomware.live.
Omax Autos
AIAccording to RansomLook, Wallstreet claims to have listed Omax Autos on its extortion site. This claim is unverified.
Central Bank of Libya
AIQilin claims to have listed the Central Bank of Libya on its extortion site, per RansomLook; this claim is unverified.
MBO GmbH
AIThe Gentlemen group claims to have listed MBO GmbH on its extortion site.
bits-pilani.ac.in
AIDragonforce claims to have listed bits-pilani.ac.in (Education) on its extortion site. The claim is unverified.
mihana-v.com
AIDragonforce claims to have listed mihana-v.com on their extortion site, according to Ransomware.live (unverified claim).
CTM India Limited motherson INDIA
AIThe Gentlemen listed CTM India Limited (motherson INDIA) on its extortion site, claiming to have breached the organization. This is an unverified claim.
CTM India Limited
AIThe Gentlemen claims to have listed CTM India Limited, a manufacturing firm in India, on their extortion site.
GIA Partners
AIThe Gentlemen claims to have listed GIA Partners on its extortion site, per RansomLook. This is an unverified claim.
Hooke Laboratories
AIThe Gentlemen claims to have listed Hooke Laboratories on its extortion site, per RansomLook, but this is unverified.
Rowley Properties
AIThe Gentlemen claims to have listed Rowley Properties on its extortion site; the claim is unverified.
Canada Wide Media
AIThe Gentlemen group claims to have breached Canada Wide Media, a Canadian media company, according to a RansomLook extortion-site listing.
ErgoMed
AIThe Gentlemen claims to have listed ErgoMed on its extortion site, per RansomLook; the listing is unverified.
Royal Thai Navy Housing Cooperative
AIThe Gentlemen group claims to have compromised the Royal Thai Navy Housing Cooperative, a Thai government entity. This is an unverified extortion listing.
International Freight Services
AIThe Gentlemen claim to have compromised International Freight Services, according to an unverified listing on RansomLook.
NTP B.V. Civil Engineering Construction
AIThe Aurora ransomware group claims to have listed Dutch construction firm NTP B.V. on its extortion site; the claim is currently unverified.
Keywest Projects
AIThe Gentlemen listed Keywest Projects on their extortion site, claiming to have breached the organization.
Union Tractor
AIThe CMD Organization claimed to have breached Union Tractor, an agriculture and food production company, and listed it on its extortion site.
Kochs GmbH
AIAurora claims to have breached the manufacturing company Kochs GmbH and lists it on its extortion site.
NationsBuilders Insurance Services
AIAurora claims to have data from NationsBuilders Insurance Services, a financial services firm, according to an extortion-site listing on Ransomware.live.
jaggroup.com UPDATE-FULL DATA DUMP
AIStormous claims to have posted an updated full data dump from jaggroup.com in an unverified extortion listing.
Wall ISD
AICMD Organization claims to have listed Wall ISD, a US education entity, on its extortion site.
Belz Institutions
AIQilin claims to have listed Belz Institutions on RansomLook.
Tri-tec
AIQilin has listed Tri-tec on its extortion site, claiming to have breached the organization.
Taiwan Sintong Machinery Co., Ltd
AIQilin claims to have breached Taiwan Sintong Machinery Co., Ltd, a manufacturing firm, as listed on Ransomware.live.
Sivatel Bangkok
AIThe Qilin ransomware group claims to have compromised Sivatel Bangkok, a telecommunication firm, according to a listing on Ransomware.live.
Florida Engineering Services
AIQilin claims to have listed Florida Engineering Services, a construction firm
jktornel
AIINC Ransom claims to have breached jktornel, per a RansomLook extortion-site listing. The claim is unverified.
jaggroup.com UPDATE-FULL DATA DUMP
AIStormous claims to have listed a full data dump from jaggroup.com on Ransomware.live.
Lockers IT
AINova claims to have breached Lockers IT, a technology company, according to an unverified listing on Ransomware.live.
Artistic Smiles
AINightspire claims to have listed Artistic Smiles, a Consumer Services organization, on its extortion site. The claim is unverified.
Nhà Thành Phố
AINhà Thành Phố was claimed as a victim by threat actor Nova on the RansomLook extortion site. This claim is unverified.
DEADLINE MONDAY
AIIcarus claims to have breached DEADLINE MONDAY, as listed on RansomLook; the claim is unverified.
Newspaper Media Group
AIINC Ransom claims to have breached Newspaper Media Group, a consumer services firm, according to a listing on Ransomware.live.
L'Archevque & Rivest Ltée
AIWorldLeaks claims to have listed L'Archevque & Rivest Ltée on its extortion site, but the claim is unverified.
Editora Irmãos Vitale
AIThe Payload ransomware group claims to have breached Brazilian publisher Editora Irmãos Vitale, listing them on their extortion site.
Preferred Properties
AIPayload has listed Preferred Properties on its extortion site, claiming to have breached the organization.
Pacific Lamp & Supply
AIQilin claims to have breached Pacific Lamp & Supply, a manufacturing firm, and listed it on its extortion site (unverified).
Super Finishing
AIWorldLeaks claims to have data from manufacturing firm Super Finishing.
ENB Versicherungen | myenb.ch
AIPayload claims to have targeted financial services firm ENB Versicherungen (myenb.ch), as per an unverified extortion-site listing.
Qualiflex Solutions | qualiflex.solutions
AIPayload ransomware group claims to have breached Qualiflex Solutions, a business services firm, as listed on Ransomware.live.
Go2Joy (go2joy.vn)
AIRansomexx claims to have data from Go2Joy, a hospitality and tourism firm, per an unverified extortion listing on Ransomware.live.
Dosab
AINova ransomware group claims to have breached Dosab, a manufacturing company, according to an extortion listing on Ransomware.live.
Hosab
AIThe ransomware group Nova claims to have breached business services firm Hosab, according to an unverified listing on Ransomware.live.
MIT HJERTE
AIUnverified claim: Nova listed MIT HJERTE (healthcare) on its extortion site, claiming a breach.
One Believing Interiors
AINova claims to have breached One Believing Interiors, a consumer services firm, according to an unverified extortion-site listing.
Pinnacle Re-Tec
AICMD Organization claims to have breached Pinnacle Re-Tec, a business services company, listing them on their extortion site.
majorcineplex.com
AILockBit 5 claims to have breached majorcineplex.com, a hospitality and tourism firm, per an unverified extortion listing.
parkviewtaipei.com
AILockBit 5 claims to have breached parkviewtaipei.com, a hospitality and tourism entity, as listed on Ransomware.live.
ponce-benzo.com
AILockBit 5 claims to have breached ponce-benzo.com, as per an unverified extortion site listing on Ransomware.live.
parampackaging.com
AILockBit 5 claims to have attacked parampackaging.com, a manufacturing firm, according to a listing on Ransomware.live.
primelinkbio.com
AILockBit 5 claims to have listed healthcare organization primelinkbio.com on their extortion site, per Ransomware.live.
saico.co.th
AILockBit 5 claims to have compromised saico.co.th, a Business Services firm. The listing is unverified.
sanatoriodelta.com
AILockBit 5 claims to have breached sanatoriodelta.com, a healthcare entity, according to an unverified listing on Ransomware.live.
saude.mt.gov.br
AILockBit 5 listed saude.mt.gov.br (Public Sector) on its extortion site, claiming a breach. The claim is unverified.
sparkinter.com
AILockBit 5 claims to have listed sparkinter.com, a Technology sector company, on its extortion site.
teleton.org.hn
AILockBit 5 claims to have breached teleton.org.hn (healthcare), per an unverified listing on Ransomware.live.
union-chemical.co.th
AILockBit 5 claims to have breached manufacturing company union-chemical.co.th, per a listing on its extortion site. [unverified]
venelectronics.com
AILockBit 5 claims to have listed venelectronics.com, a manufacturing company, on their ransomware extortion site.
weinwurm.cc
AILockBit 5 claims to have listed weinwurm.cc on its extortion site, per Ransomware.live. This is an unverified claim.
nundungopee.mu
AILockBit 5 claims to have breached nundungopee.mu, per an unverified extortion listing on Ransomware.live.
utb.edu.vn
AILockBit 5 claims to have targeted utb.edu.vn, listed on its extortion site as an unverified breach.
hiddenn
AIThegentlemen listed hiddenn on their extortion site, claiming to have breached the organization.
Vera Chimie Management
AIThegentlemen claims to have listed manufacturing firm Vera Chimie Management on their extortion site via Ransomware.live, an unverified claim.
Alexander Buch Bilanzbuchhalter
AIAn unverified claim by Thegentlemen states they have listed Alexander Buch Bilanzbuchhalter (business services) on their extortion site.
SGS Malaysia
AIThegentlemen claims to have breached SGS Malaysia, a business services firm, in an unverified extortion listing.
Ty Thac Co
AIThegentlemen claims to have data from Ty Thac Co, as listed on Ransomware.live, but this is an unverified claim.
Amigest
AIThegentlemen has listed Amigest, an agriculture and food production company, on their extortion site, claiming a breach. This claim is unverified.
Yudu Technology
AIThegentlemen claims to have listed Yudu Technology on their extortion site; the claim is unverified according to Ransomware.live.
Burris MacOmber
AIThegentlemen claims to have listed Burris MacOmber (Business Services) on its extortion site, per Ransomware.live, an unverified claim.
Sertrans
AIThegentlemen claims to have listed transportation/logistics firm Sertrans on its extortion site; the claim is unverified.
Cofaq
AIThegentlemen claims to have breached Cofaq, as listed on Ransomware.live.
Al Khaja Holding
AIThegentlemen claims to have breached Al Khaja Holding, a business services firm, according to an unverified listing.
Southern design RV
AICMD Organization listed Southern design RV on its extortion site, claiming to have breached the consumer services firm. This claim is unverified.
Athens Orthopedic Clinic
AIThegentlemen claims to have breached Athens Orthopedic Clinic, a healthcare organization, according to an unverified extortion listing.
JCPenney
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later publi…
aasa.ae
AIKrybit claims to have breached aasa.ae, per a listing on RansomLook, but this claim is unverified.
coemi.com.br
AIKrybit claims to have breached coemi.com.br, as listed on RansomLook's extortion site. This claim is unverified.
themintgaming.com
AIBrainCipher claims to have data from themintgaming.com, a consumer services firm, according to a listing on Ransomware.live. This claim is unverified.
www.mupras.com
AIThe Krybit group has listed the business services firm www.mupras.com on its extortion site, claiming to have breached its systems.
Athens Orthopedic Clinic
AIThe Gentlemen claims to have listed Athens Orthopedic Clinic on their extortion site.
Roth Industries
AIRoth Industries, a manufacturing firm, was listed on Qilin's extortion site, claiming to have breached their data.
Sparkle Pools
AIQilin claims to have breached Sparkle Pools, a Consumer Services firm, per an unverified extortion-site listing.
mlit.com.my UPDATE-FULL DATA DUMP 10GB
AIStormous claims to have a 10GB data dump from public sector org mlit.com.my (listed on Ransomware.live). Unverified claim.
PJ Daly Contracting
AIThe Qilin ransomware group claims to have breached construction firm PJ Daly Contracting, listing them on their extortion site.
Desert Micro
AIExtortion group Nova claims to have breached Desert Micro, a technology company, according to a listing on Ransomware.live.
Optimum First Mortgage
AIPear claims to have data from Optimum First Mortgage, listed on its extortion site. This claim is unverified.
Hagerman & Company
AIAurora claims to have breached Hagerman & Company (Business Services) in an unverified extortion site listing on Ransomware.live.
KTR Real Estate Advisors
AIAnubis claims to have compromised KTR Real Estate Advisors, a financial services firm, in an unverified extortion site listing.
ALS Global
AIAurora claims to have listed ALS Global on its extortion site (unverified).
Klue.com
AIIcarus listed Klue.com on its extortion site, claiming to have breached the technology company.
icsecurity.com
AIShinyHunters claims to have breached icsecurity.com, as listed on the RansomLook extortion site. The claim is unverified.
legendsmn(Blue Ox, Paul Bunyan, Lumberjack Electric)
AINightspire claims to have listed legendsmn (Blue Ox, Paul Bunyan, Lumberjack Electric) on its extortion site; the claim is unverified.
dean cosmetic dentistry
AINightspire claims to have breached Dean Cosmetic Dentistry and listed it on its extortion site. This is an unverified claim.
Ralph Lauren
In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140…
ra-vogeler.de
AICloak listed ra-vogeler.de on its extortion site, claiming to have breached the German business services firm.
Operation Endgame 4.0
On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies wi…
THL PROJECT MANAGEMENT SDN. BHD.
AIBusiness services firm THL PROJECT MANAGEMENT SDN. BHD. claims to have been breached by the Qilin ransomware group, as listed on Ransomware.live.
Homes By J Anthony
AIQilin claims to have listed Homes By J Anthony (construction) on its extortion site; the claim is unverified.
ATCOM Outsourcing
AIThe Qilin ransomware group claims to have listed ATCOM Outsourcing, a business services firm, on its extortion site
B & B Trading
AIThe Pear ransomware group claims to have listed B & B Trading on its extortion site, per an unverified RansomLook entry.
Release Marine, Inc.
AIRelease Marine, Inc. is listed by the Pear group on RansomLook as an unverified extortion claim.
Kirbor Homes
AIThreat actor Pear listed Kirbor Homes on its extortion site, claiming to have breached the organization, per RansomLook.
Skupina Don Don - GRUPO BIMBO
AIQilin claims to have listed Skupina Don Don - GRUPO BIMBO (Agriculture and Food Production) on its extortion site.
Berg Lilly
AIAkira claims to have breached Berg Lilly and listed the organization on its extortion site.
hiidden
AIThe Gentlemen claims to have listed hiidden on its extortion site, per RansomLook. This is an unverified claim.
Lawson Roofing
AIRhysida claims an unverified breach of construction firm Lawson Roofing, per an extortion site listing
Makel Companies Group
AIThe Qilin ransomware group claims to have listed construction firm Makel Companies Group on its extortion site. This claim is unverified.
SELECT WINES
AIThe Bravox ransomware group claims to have listed SELECT WINES, an agriculture and food production company, on its extortion site.
www.someco.com
AILynx has listed www.someco.com on their extortion site, claiming to have breached the organization.
Ty Thac Co
AIThe Gentlemen claims to have data from Ty Thac Co, per an extortion site listing tracked by RansomLook (unverified).
Amigest
AIThe Gentlemen has listed Amigest as a victim on their extortion site (per RansomLook), claiming a breach.
Yudu Technology
AIThe Gentlemen listed Yudu Technology on their extortion site, claiming to have breached the organization.
Burris MacOmber
AIThe Gentlemen group claims to have listed Burris MacOmber on their extortion site, per RansomLook.
Sertrans
AIThe Gentlemen group claims to have listed Sertrans on its extortion site, as observed on RansomLook. This listing is unverified.
Cofaq
AIThe Gentlemen claims to have listed Cofaq on their extortion site, but this claim is unverified.
Al Khaja Holding
AIThe Gentlemen group claims to have breached Al Khaja Holding, based on an unverified RansomLook extortion-site listing.
sweetome.com
AILockBit 5 claims to have data from sweetome.com, listed on RansomLook's extortion site. The claim is unverified.
probat.ag
AILockBit 5 claims to have breached probat.ag, according to an unverified listing on RansomLook.
delano.k12.mn.us
AILockBit 5 listed delano.k12.mn.us on an extortion site, claiming a breach, though the claim is unverified.
eternal.hk
AILockBit 5 claims to have breached eternal.hk, according to an unverified claim on the RansomLook extortion site.
5deagosto.com.br
AILockBit 5 claims to have listed 5deagosto.com.br on their extortion site, per RansomLook. Unverified claim.
abandw.com
AIRansomLook reports that LockBit 5 claims to have listed abandw.com on its extortion site.
ag-360.ca
AILockBit 5 claims to have breached ag-360.ca, as listed on its extortion site (unverified).
elematic.com
AIThreat actor LockBit 5 claims to have listed elematic.com on its extortion site, according to RansomLook.
amc.co.th
AILockBit 5 claims to have listed amc.co.th on its extortion site, according to RansomLook; an unverified claim.
casaandina.com.co
AILockBit 5 listed casaandina.com.co on its RansomLook extortion site, claiming a breach. This is an unverified claim.
bvi.co.bw
AILockBit 5 claims to have breached bvi.co.bw, listing it on their extortion site, according to RansomLook.
comta.com.tw
AIAccording to RansomLook, LockBit 5 claims to have listed comta.com.tw on its extortion site. The claim is unverified.
daikyonishikawa.co.jp
AILockBit 5 claims to have listed daikyonishikawa.co.jp on its extortion site as an unverified breach.
rubbercompounding.com
AILockBit 5 claims to have listed rubbercompounding.com on the RansomLook extortion site. This is an unverified claim.
drwu.com
AILockBit 5 claims to have breached drwu.com, as listed on RansomLook. The claim is unverified.
felizhotelboracay.com
AILockBit 5 listed felizhotelboracay.com on their extortion site, claiming to have data from the organization.
greyhighschool.com
AILockBit 5 has listed greyhighschool.com on its extortion site, claiming to have breached the organization.
idefeey.yucatan.gob.mx
AILockBit 5 claims to have compromised idefeey.yucatan.gob.mx, per an extortion-site listing on RansomLook.
inspeqingenieria.com
AILockBit 5 claims to have listed inspeqingenieria.com on its extortion site, per RansomLook. This is unverified.
majorcineplex.com
AILockBit 5 claims to have listed majorcineplex.com on its extortion site, per RansomLook. This is an unverified claim.
parkviewtaipei.com
AILockBit 5 claims to have listed parkviewtaipei.com on its extortion site; the claim is unverified.
parampackaging.com
AILockBit 5 claims to have breached parampackaging.com, per a listing on RansomLook. The claim is unverified.
primelinkbio.com
AIAccording to RansomLook, LockBit 5 claims to have listed primelinkbio.com on its extortion site. This claim is unverified.
saico.co.th
AILockBit 5 claims to have listed saico.co.th on its extortion site, per RansomLook. This claim is unverified.
sanatoriodelta.com
AILockBit 5 claims to have compromised sanatoriodelta.com, as per a listing on its extortion site. The claim is unverified.
saude.mt.gov.br
AILockBit 5 claims to have listed saude.mt.gov.br on its extortion site, per RansomLook, though this is unverified.
sparkinter.com
AILockBit 5 claims to have listed sparkinter.com on its extortion site. The claim is unverified.
teleton.org.hn
AILockBit 5 claims to have listed teleton.org.hn on its extortion site per RansomLook; the claim is unverified.
union-chemical.co.th
AILockBit 5 claims to have breached Union Chemical (union-chemical.co.th) and listed it on their extortion site.
venelectronics.com
AILockBit 5 claims to have compromised venelectronics.com, as listed on a ransomware extortion site.
weinwurm.cc
AILockBit 5 claims to have listed weinwurm.cc on its extortion site (RansomLook), but the claim is unverified.
nundungopee.mu
AILockBit 5 claims to have listed nundungopee.mu on their extortion site; the claim is unverified.
SGS Malaysia
AIThe Gentlemen group claims to have breached SGS Malaysia, according to an unverified extortion-site listing on RansomLook.
TERRIO Therapy Fitness
AIAn unverified claim from the ransomware group The Gentlemen lists TERRIO Therapy Fitness on its extortion site.
Vera Chimie Management
AIThe Gentlemen claims to have listed Vera Chimie Management on their extortion site.
Alexander Buch Bilanzbuchhalter
AIThe Gentlemen has listed Alexander Buch Bilanzbuchhalter on its extortion site, claiming to have breached the organization.
Apptricity
AIThe Akira ransomware group claims to have breached Apptricity, a business services company, as listed on its extortion site. The claim is unverified.
www.eastersealsia.org
AILynx claims to have listed Eastersealsia (Healthcare) on its extortion site, per Ransomware.live. The claim is unverified.
United Personnel (a division of Masis Staffing Solutions)
AIUnverified claim: Genesis claims to have listed United Personnel (a division of Masis Staffing Solutions) on extortion site RansomLook.
The Associated Builders and Contractors of Indiana/Kentucky
AIIn an unverified claim, Genesis listed The Associated Builders and Contractors of Indiana/Kentucky on its extortion site, claiming to possess data from the organization.
Horizon Family Medical Group
AIINC Ransom claims to have breached Horizon Family Medical Group, a healthcare provider, as listed on its extortion site.
www.wolfconstruction.net
AILynx claims to have breached construction firm Wolf Construction (www.wolfconstruction.net). This is an unverified listing claim.
Amazon owned OneMedical.com
AIShinyHunters claims to have data from healthcare provider Amazon-owned OneMedical.com in an unverified listing on Ransomware.live.
NAIC.org
AIShinyHunters claims to have listed NAIC.org, a business services organization, on its extortion site. The claim is unverified.
CFGI
In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign . The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k u…
neuwoges.de
AIINC Ransom claims to have listed neuwoges.de on its extortion site, per RansomLook; the claim is unverified.
seinordovest.it
AISafepay claims to have breached seinordovest.it, according to their extortion site listing; the claim is unverified.
Prince George County
AIRansomhouse claims to have breached Prince George County, as listed on RansomLook. This claim is unverified.
Greg Crosslin
AIPlay ransomware group claims to have listed Greg Crosslin on its extortion site; the claim is unverified.
harcourts.net
AIHarcourts.net, a Consumer Services organization, was claimed to be listed by the Safepay group on their extortion site.
zaunsysteme.de
AISafepay claims to have breached zaunsysteme.de, a manufacturing firm, in an unverified extortion site listing.
brscappuccio.it
AISafepay claims to have breached brscappuccio.it, a Consumer Services organization, according to a listing on its extortion site (Ransomware.live). This is an unverified claim.
gut-heckenhof.de
AISafepay listed gut-heckenhof.de, an organization in agriculture and food production, on its extortion site in an unverified claim.
Great Foods
AIThe Lamashtu group claims to have breached Great Foods, an agriculture and food production company, as listed on its extortion site.
Integrated Technologies
AIThe Play ransomware group claims to have breached Integrated Technologies and listed it on its extortion site. This claim is unverified.
eurOptimum
AIPlay ransomware group listed technology company eurOptimum on its extortion site, claiming a breach.
Smith Filter
AIAkira claims to have listed Smith Filter on their extortion site.
Chebib Control
AISpace Bears claims to have listed Chebib Control as a victim in an extortion-site listing, an unverified claim.
www.courdescomptes.sn
AIKrybit claims to have breached courdescomptes.sn per a RansomLook extortion listing. The claim is unverified.
MHE9 Logística Ltda
AIGunra claims to have listed MHE9 Logística Ltda on its extortion site (RansomLook); the claim is unverified.
Suárez&Clavera
AIGunra claims to have listed Suárez&Clavera on its extortion site, per an unverified RansomLook listing.
ersa.com.py
AIRansomware group Krybit claims to have listed manufacturing firm ersa.com.py on its extortion site, per Ransomware.live. The claim is unverified.
Gerencial
AISpace Bears claims to have breached Gerencial, as listed on a ransomware extortion site.
Service Notice: Scheduled Maintenance and Infrastructure Upgrades
AIShinyHunters claims to have data from "Service Notice: Scheduled Maintenance and Infrastructure Upgrades" in an unverified extortion site listing.
Promepla
AIRansomhouse claims to have listed Promepla on its extortion site, according to RansomLook. This is an unverified claim.
jasperplastics.info
AIINC Ransom claims to have compromised jasperplastics.info, according to an unverified extortion-site listing tracked by RansomLook.
Ralph Lauren
AIShinyHunters claims to have breached Ralph Lauren and listed the organization on their extortion site.
framesiprofessional.com
AIINC Ransom listed framesiprofessional.com on its extortion site, claiming a breach. The claim is unverified.
TINYpulse NINTENDO BREACH (nintendo.com)
AIShadowbyt3$ claims to have breached TINYpulse and Nintendo (nintendo.com), according to an unverified listing on RansomLook.
Novo Nordisk
AIFulcrumsec claims to have listed Novo Nordisk on RansomLook; the claim is unverified.
Tecfi SpA
AIRansomware group Dragonforce claims to have compromised Tecfi SpA, as listed on an extortion site.
Allan Brothers Fruit
AIThe Aurora ransomware group claims to have listed Allan Brothers Fruit on its extortion site, per an unverified RansomLook listing.
Diamond Truck Centres
AIThreat actor Aurora claims to have listed Diamond Truck Centres on its extortion site, per RansomLook, in an unverified claim.
Sumitomo Electric Bordnetze
AIAurora claims to have breached Sumitomo Electric Bordnetze, per an unverified extortion-site listing on RansomLook.
Insite Architects
AIAkira claims to have listed Insite Architects on its extortion site, according to RansomLook.
Golfview Developmental Center
AIQilin claims to have compromised Golfview Developmental Center, listing the organization on its extortion site (unverified claim).
Sunass
AIAccording to RansomLook, Nova has listed Sunass on its extortion site in an unverified claim.
Central Texas ***** *****
AINightspire has listed an unverified claim on RansomLook against an organization described as 'Central Texas ***** *****'.
Ri***** Co**** Europe S.r.l.
AINightspire claims to have breached Ri***** Co**** Europe S.r.l., listed on RansomLook. This claim is unverified.
ra-*******e
AIRansomLook reports that Cloak claims to have listed organization ra-*******e on their extortion site. This claim is unverified.
d**********e
AICloak claims to have listed d**********e on RansomLook in an unverified extortion claim.
W******S*******D
AICloak claims to have breached W******S*******D, as listed on RansomLook. This claim is unverified.
Guy E******* & F*******, P.A
AINightspire claims to have listed Guy E******* & F*******, P.A on its extortion site, per RansomLook (unverified).
thecreditpros.com
AIIcarus group claims to have listed thecreditpros.com on its extortion site, as reported by RansomLook.
Notice
AIDeadlock claims to have listed Notice on its extortion site per RansomLook, though the claim is unverified.
SPORTON International Inc.
AIPayload claims to have breached SPORTON International Inc. and listed the organization on its extortion site. The claim is unverified.
ECOVACS
AISpace Bears claims to have breached ECOVACS, according to a listing on the RansomLook extortion site.
Q Link Wireless
AIQilin claims to have listed Q Link Wireless on its extortion site.
Misericórdia de Santo Tirso
AIUnverified claim: Qilin claims to have listed Misericórdia de Santo Tirso on their extortion site.
Kedah
AIThe Nova group claims to have compromised Kedah, according to an unverified extortion-site listing tracked by RansomLook.
icc.edu
AIShinyHunters listed icc.edu on their extortion site, claiming a breach. This claim is unverified.
moody.edu
AIShinyHunters claims to have breached moody.edu, listed on its extortion site (unverified).
glendale.edu
AIShinyHunters claims to have listed glendale.edu on RansomLook, an extortion-site listing. The claim is unverified.
3
AIINC Ransom has listed Organization 3 on its extortion site, according to RansomLook. This claim is unverified.
****** Agency
AIThe Gentlemen claims to have breached an agency, in an unverified extortion-site listing on RansomLook.
hughstirling.co.uk
AISafepay claims to have breached hughstirling.co.uk, listing the organization on its extortion site. This claim is unverified.
tokyocivil.co.jp
AISafepay claims to have data from tokyocivil.co.jp, listing it on its extortion site. The claim is unverified.
kawaius.com
AIThreat actor Safepay has listed kawaius.com on RansomLook, claiming to have attacked the organization. The listing is unverified.
musenet.co.jp
AISafepay claims to have listed musenet.co.jp on its extortion site, per RansomLook; this is an unverified claim.
bautz-maschinenbau.de
AISafepay listed bautz-maschinenbau.de on its extortion site, claiming to have breached it. The claim is unverified.
aquaclean.com
AISafepay claims to have listed aquaclean.com on its extortion site; the claim is unverified.
hoodriversheriff.com
AISafepay listed hoodriversheriff.com on its extortion site, claiming to have breached the organization. The claim is unverified.
B****S I******t***l
AINightspire has listed B****S I******t***l on its extortion site, according to RansomLook; the claim is unverified.
Sheraton Miramar Resort El Gouna
AIThe Nightspire group claims to have listed Sheraton Miramar Resort El Gouna on its extortion site, though the claim is unverified.
G**** R****l*e
AINightspire claims to have breached organization G**** R****l*e, as listed on RansomLook. The claim is unverified.
CUI Agency
AIThe Gentlemen claims to have listed CUI Agency on its extortion site, per RansomLook.
anglomoil.com
AIBrain Cipher claimed to have breached anglomoil.com, listing the company on their extortion site. The claim is unverified.
alu-rex.com
AIBrain Cipher claims to have listed alu-rex.com on its extortion site, as reported by RansomLook.
Grupo Indi
AIThe ransomware group Qilin claims to have listed Grupo Indi on its extortion site. This claim is unverified.
Can Healthcare Group
AIQilin claims to have listed Can Healthcare Group on its extortion site, per RansomLook.
Cng Ty Cp T Vn Xd Tng Hp
AIQilin claims to have data from Cng Ty Cp T Vn Xd Tng Hp in an extortion-site listing on RansomLook, but the claim is unverified.
MAVA Healthcare
AIThe ransomware group Qilin has listed MAVA Healthcare on its extortion site, claiming to have stolen data from the organization.
June 2026 Stealer Logs
In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been…
KoMiCo
AIAnubis claims to have listed KoMiCo on their extortion site, per RansomLook, though the claim remains unverified.
W****e
AIPayoutsking claims to have listed W****e on its extortion site, per RansomLook. This claim is unverified.
Zhangjiagang Fortune Chemical Co. Ltd. Singapore
AIDeadlock listed Zhangjiagang Fortune Chemical Co. Ltd. Singapore on its extortion site. The claim is unverified.
Summa4
AIDeadlock claims to have breached Summa4, as listed on RansomLook. The claim is unverified.
Hornavan Hotell
AIDeadlock claims to have listed Hornavan Hotell on its extortion site, per RansomLook.
TeleFinity
AIDeadlock claims to have breached TeleFinity, according to an unverified listing on RansomLook.
donjon
AIDeadlock claims to have listed donjon on its extortion site. This claim is unverified.
CH Paper
AIDeadlock claims to have listed CH Paper on RansomLook's extortion site, though the claim is unverified.
Nobani Co
AIDeadlock claims to have breached Nobani Co, as listed on RansomLook extortion site.
Fidelity Pension Managers
AIDeadlock claims to have breached Fidelity Pension Managers, listed on RansomLook, but the claim is unverified.
CAD93
AIDeadlock claims to have compromised CAD93, according to a listing on RansomLook.
SECiL
AIDeadlock claims to have listed SECiL on its RansomLook extortion site. The listing is an unverified claim.
Direção Estacionamentos S.A.
AIAccording to RansomLook, Deadlock listed an unverified claim against
EDISA and INVERTIGE
AIDeadlock claims to have listed EDISA and INVERTIGE on its extortion site, per RansomLook; the claim is unverified.
Breda Energia
AIDeadlock claims to have breached Breda Energia, according to an unverified extortion-site listing on RansomLook.
Muzeum Valassko
AIDeadlock listed Muzeum Valassko on its extortion site, claiming to have data from the organization. The claim is unverified.
bERS
AIDeadlock claims to have breached bERS, according to an extortion-site listing on RansomLook (unverified claim).
NXIT and Franco Vago S.p.a. and Traconf Srl
AIDeadlock claims to have listed NXIT, Franco Vago S.p.a., and Traconf Srl on its extortion site.
AFWorkshop
AIDeadlock claims to have listed AFWorkshop on its extortion site (RansomLook).
Finam Gabon
AIDeadlock claims to have breached Finam Gabon. The extortion-site listing, tracked by RansomLook, is unverified.
iASK
AIThe Deadlock group claims to have listed iASK on its extortion site, according to RansomLook. This claim is unverified.
Noega and Esnova
AIDeadlock claims to have listed data from Noega and Esnova on its extortion site, according to RansomLook.
IFC Eur
AIDeadlock claims to have breached IFC Eur, listing the organization on its RansomLook extortion site. The claim is unverified.
TPToys
AIDeadlock claims to have listed TPToys on its extortion site, according to RansomLook; this claim is unverified.
EXPRESOKNA SP. Z O.O.
AIDeadlock claims to have breached EXPRESOKNA SP. Z O.O., as listed on its extortion site. This claim is unverified.
Bär Cargolift Polska Sp. z o.o.
AIDeadlock claims to have listed Bär Cargolift Polska Sp. z o.o. on its RansomLook extortion site; the claim is unverified.
Grupolider | Grupo Actual
AIDeadlock listed Grupolider | Grupo Actual on its extortion site (RansomLook), though the claim is unverified.
Dyhrberg AG Switzerland
AIDeadlock listed Dyhrberg AG Switzerland on its extortion site; the claim is unverified.
SKK Networks Sp. z o.o. and UNICARD Systems Sp. z o. o. and SKK SA
AIDeadlock claims to have breached SKK Networks, UNICARD Systems, and SKK SA. This is an unverified extortion listing.
PB Sprinkler Engineering Sp. z o.o. and PLISZKA Fire Protection Engineering
AIDeadlock claims to have listed PB Sprinkler Engineering Sp. z o.o. and PLISZKA Fire Protection Engineering on its extortion site.
8.2 Group e.V.
AIDeadlock has listed 8.2 Group e.V. on RansomLook, claiming to have its data in an unverified extortion site listing.
Integra and Operosa
AIDeadlock claims to have breached Integra and Operosa, per an unverified extortion-site listing on RansomLook.
JOSO
AIDeadlock listed JOSO on its extortion site, claiming to have breached the organization.
GEOPARTNER Sp. z o.o. and GEOPARTNER GEOMATICS Sp. z o.o.
AIDeadlock claims to have listed GEOPARTNER Sp. z o.o. and GEOPARTNER GEOMATICS Sp. z o.o. on its extortion site, an unverified claim.
FIRESTA
AIDeadlock claims to have breached FIRESTA, according to an unverified extortion listing on RansomLook.
UFL
AIDeadlock claims to have breached UFL, listing the organization on its extortion site.
Picassent
AIDeadlock has claimed to breach Picassent, listing the organization on its extortion site. This claim is unverified.
Starconn
AIDeadlock claims to have compromised Starconn, according to a listing on its extortion site.
EFCA
AIAccording to RansomLook, the Deadlock group claims to have listed EFCA on its extortion site.
AKSV
AIDeadlock claims to have listed AKSV on its extortion site, per RansomLook; the claim is unverified.
Bridgeport S.p.A.
AIDeadlock claims to have listed Bridgeport S.p.A. on RansomLook; the
SH Hoteles (Spain)
AIDeadlock claims to have listed SH Hoteles (Spain) on its extortion site.
Bombas Ideal
AIDeadlock claims to have listed Bombas Ideal on its extortion site, according to RansomLook. The claim is unverified.
Ring Textile Production RTP SRL
AIDeadlock claims to have listed Ring Textile Production RTP SRL on its extortion site, according to RansomLook (unverified claim).
ADM Value Barcelona
AIDeadlock claims to have listed ADM Value Barcelona on its extortion site. The claim is unverified.
Consulting Valladolid
AIDeadlock listed Consulting Valladolid on its RansomLook extortion site, claiming an attack; the claim is unverified.
ONE Contact
AIDeadlock claims to have compromised ONE Contact, according to an unverified extortion-site listing on RansomLook.
Elmoris
AIRansomware group Deadlock claims to have breached Elmoris, according to a listing on RansomLook. The claim is unverified.
Gerusia S.L.
AIDeadlock has listed Gerusia S.L. on its extortion site, an unverified claim.
Maxplast AND Senoco
AIDeadlock listed Maxplast and Senoco on its extortion site, claiming to have breached them.
Grupo Mercurio
AIDeadlock claims to have listed Grupo Mercurio on its extortion site, as reported by RansomLook. This remains an unverified claim.
Zaffrani Srl
AIDeadlock claims to have listed Zaffrani Srl on its extortion site; the claim is unverified.
Eko-Flor Plus d.o.o.
AIDeadlock claims to have listed Eko-Flor Plus d.o.o. on its extortion site; the claim is unverified.
VBW Makelaars and Taxateurs
AIDeadlock claims to have listed VBW Makelaars and Taxateurs on its extortion site, per RansomLook. This is an unverified claim.
Industrie Tecnologiche it
AIDeadlock has listed Industrie Tecnologiche it on its extortion site, claiming to have breached the organization.
LIVISTO
AIDeadlock claims to have listed LIVISTO on its extortion site, according to RansomLook; the claim is unverified.
Anidaport - Investimentos Imobiliários Lda., Lisbon, Portugal
AIDeadlock claims to have leaked data from Anidaport - Investimentos Imobiliários Lda., listing the Portuguese firm on its extortion site (unverified).
Optimal Care SA
AIDeadlock claims to have breached Optimal Care SA and listed it on its extortion site (source: RansomLook). Unverified claim.
BARCELONA URBAN PROPERTY CHAMBER
AIDeadlock claims to have listed the Barcelona Urban Property Chamber.
Židlochovice city
AIDeadlock listed Židlochovice city on RansomLook, claiming an intrusion. This claim is unverified.
Werken Química Brasil S.A.
AIDeadlock claims to have breached Werken Química Brasil S.A., listing them on their extortion site. This claim is unverified.
3Gi Solutions, is an IT Services Provider located in Montreal, Quebec.
AIDeadlock claims to have listed 3Gi Solutions, an IT services provider in Montreal, on its extortion site. The claim is unverified.
Güven Mühendislik Makina
AIDeadlock claims to have breached Güven Mühendislik Makina, as listed on its extortion site.
Abhay Prabhavana
AIDeadlock has listed Abhay Prabhavana on their extortion site, per RansomLook; the claim is unverified.
Quetzal Química
AIDeadlock ransomware group claims to have compromised Quetzal Química, listing them on their extortion site. The claim is unverified.
CIATI
AIDeadlock claims to have breached CIATI, listing the organization on its extortion site RansomLook, but the claim is unverified.
ACU - The Automobile Club of Uruguay
AIDeadlock claims to have breached ACU - The Automobile Club of Uruguay, with the organization listed on its extortion site.
DOCTUS USA Inc
AIDeadlock group claims to have data from DOCTUS USA Inc, as listed on RansomLook extortion site (unverified).
WH Müller
AIDeadlock claims to have breached WH Müller and listed the organization on its extortion site.
Grupo Vanguardia
AIDeadlock claims to have listed Grupo Vanguardia on their extortion site, according to RansomLook.
WiBeats S.r.l.
AIDeadlock claims to have listed WiBeats S.r.l. on its extortion site.
Schlenker and Cantwell, P.A.
AIDeadlock claims to have listed Schlenker and Cantwell, P.A., but the claim is unverified.
LA SEVILLANITA SRL
AIDeadlock has listed LA SEVILLANITA SRL on its extortion site, claiming to have data from the organization. This is an unverified claim.
The Morton Grove Park District
AIDeadlock claims to have compromised the Morton Grove Park District, according to a listing on RansomLook. The claim is unverified.
Weinberg ''93 Építő Kft.
AIThe Deadlock group claims to have listed Weinberg ''93 Építő Kft. on its extortion site, per RansomLook. This claim is unverified.
Catcorp
AIDeadlock claims to have listed Catcorp on its extortion site, as reported by RansomLook. This claim is unverified.
Ktunaxa Nation Council: Breach Highlights Growing Risks Facing Public Institutions
AILeaknet claims to have compromised the Ktunaxa Nation Council, listed on its extortion site.
Röben Tonbaustoffe GmbH
AIAilock claims to have listed Röben Tonbaustoffe GmbH on its extortion site. This claim is unverified.
hccs.edu
AIShinyHunters claims to have breached hccs.edu, as listed on their extortion site and tracked by RansomLook.
kodak.com
AIShinyHunters claims to have listed kodak.com on RansomLook, an extortion-site listing, as an unverified breach.
Deep Well Services
AIShinyHunters has listed Deep Well Services on its extortion site, claiming to have stolen data. This is an unverified claim.
Sysco Corporation
AISysco Corporation was listed by ShinyHunters on RansomLook; this is an unverified claim.
Bd
AIThreat actor Bavacai claims to have listed organization Bd on their extortion site. This claim is unverified.
Berkadia
In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k uniq…
Infinite Campus
In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along w…
University of Nottingham
In June 2026, the University of Nottingham was the target of a cyber attack , later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with e…
Baker Distributing
In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site . In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Sa…
BCD Travel
In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email…
DentaQuest
In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2…
Edmunds
In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached . Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses…
Atlas Menu
In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresse…
Charter
In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group later published the data, wh…
Kemper
In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign . The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part o…
Mytheresa
In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The…
Ameriprise
In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environme…
7-Eleven
In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters , with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers…
No signals found
Try removing a filter or searching for another term.