💥 Attack Tracker¶
Newest first. Most entries are claims listed on actors' leak sites, not confirmed breaches — flagged 🟥 unverified until corroborated. Verify before acting; see Methodology. Colour bands mark each month; each actor links to its battle card.
September 2026
Sep 11
Agencia Estatal de Meteorología (AEMET)
Panzer
Panzer, a newly observed RaaS operation running since Aug 5 2026 with 16-21 claimed victims across 11 countries in its first month, lists Spain's national meteorological agency, claiming roughly 5GB exfiltrated with a 20-21 day publication deadline. No agency confirmation yet; verify before treating as a breach. · Sources: EscudoDigital · Ransomware.live
Sep 10
i2k2 Networks
Vexy
New Delhi-based Indian cloud computing, web hosting, managed IT and disaster-recovery provider listed on Vexy's leak site Sep 10; over 100GB claimed exfiltrated, scope reported as employee and user records. Vexy is a newly observed group with only a handful of named victims to date; no vendor statement. 🟥 unverified DLS claim. · Sources: Ransomware.live
Sep 10
General Santos Doctors Hospital
Rhysida
Rhysida lists a 280-bed Level 3 tertiary hospital in South Cotabato, claiming roughly 3.5M files (2.44TB) exfiltrated including name-tagged diagnostic scans, cancer-center records with PhilHealth IDs, lab quotations with birth dates, and a staff register with PRC license numbers. No hospital confirmation yet; verify before treating as a breach. · Sources: Ransomware.live
Sep 08
Mathspace
Unknown
Unauthorized access to internal Metabase reporting system (SQLi in unpatched Metabase instance) exposed names, emails, usernames and account metadata for 1,079,819 students, parents and staff across Australia and New Zealand; no passwords, academic records or API credentials taken. Fourth confirmed victim of the same unpatched-Metabase pattern after Framework, Tally and Kilo Code in August. · Sources: https://www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/ · https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
Sep 08
Florida DAVID (Highway Safety and Motor Vehicles)
ShinyHunters
ShinyHunters claims access to Florida's DAVID driver/vehicle lookup database via a password-reset flaw compromising DMV-employee and FBI-agent accounts; ~200,000 driver records allegedly pulled by iterating IDs starting around Sep 3. Proof includes a screenshot of Jeffrey Epstein's DMV record. Verify before treating as a confirmed breach — FLHSMV has not confirmed the claim; leak-site deadline set for Sep 11. · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
Sep 08
Veradigm
The Gentlemen
Chicago-based EHR/e-prescribing/practice-management vendor confirms an attacker used compromised third-party vendor credentials to access a specific Veradigm API and download patient data, including Social Security numbers for a subset of customers; no clinical/medical data, network or server compromise. The Gentlemen posted Veradigm to its leak site Sep 5, asserting 3.5M patient records (names, addresses, SSNs, emails, phones) were taken, and set a Sep 11 publication deadline absent ransom negotiation. The access itself is company-confirmed; the 3.5M-record scope is the attacker's own figure. · Sources: BleepingComputer · The Record
Sep 08
GT Distributors
Play
Austin, Texas-based national distributor of tactical gear, firearms accessories and uniforms for law enforcement, military and public-safety agencies; listed on Play's leak site Sep 8 claiming internal data theft. Play uses double extortion (no upfront ransom demand in the leak note); data scope and impact unconfirmed. · Sources: RedPacketSecurity
Sep 07
ST Engineering
Metaencryptor
Singapore-based multinational technology, defence and engineering group (aerospace, smart city, defence and public security segments); Metaencryptor DLS claim Sep 7, 2026; data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.ransomware.live/id/U1QgRW5naW5lZXJpbmdAbWV0YWVuY3J5cHRvcg==
Sep 07
Lightcast
Direwolf
US-based provider of human resources / labor-market analytics software; Direwolf DLS claim Sep 7, 2026; data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/direwolf-ransomware-victim-lightcast/
Sep 07
United Group
Vexy
Indian diversified business group (food ingredients, nutraceuticals, industrial machinery, infrastructure, fashion, digital branding, packaging, automotive accessories); Vexy DLS claim Sep 7, 2026; Vexy is a newly emerged group (first seen Sep 2026); data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/vexy-ransomware-ransomware-victim-united-group/
Sep 07
Master Manufacturing Co., Inc.
Dark Project
Southern Indiana custom metal stamping, laser cutting, and wire bending manufacturer (founded 1970, IATF 16949 certified); Dark Project claims 36GB exfiltrated, including SQL databases with personal data and technical schematics; data-exfiltration claim, no encryption reported. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/dark-project-ransomware-victim-master-manufacturing-co-inc/
Sep 07
Conde Nast
Unknown
A dataset of 32,815,767 user records (names, emails, postal addresses, gender, DOB, phone numbers -- no passwords or payment data) listed for sale for $15,000 on a Russian-language cybercrime forum Sep 7, pitched as the full set behind the Dec 2025 WIRED subscriber leak (which itself totaled a fraction of this volume). Ransomnews sampled 5,000 records and found them consistent with genuine Conde Nast account data collected Sep-Oct 2025. Conde Nast has not confirmed the breach or the new sale listing. · Sources: SecurityAffairs · Cybernews
Sep 04
Manchester Airports Group
FulcrumSec
8.8M traveller records (email, phone, vehicle reg, postcodes) published Sep 4 after MAG refused ransom; FulcrumSec extracted 86GB compressed / 550GB uncompressed from MAG's Iterable marketing platform using API credentials embedded in publicly visible website JavaScript — no network intrusion required; covers Manchester, London Stansted, and East Midlands airports; parking, lounge, Fast Track, Wi-Fi data; payment-card data not accessed; MAG disclosed Aug 27, FulcrumSec claimed Sep 1, data published Sep 4; UK ICO notified · Sources: https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/ · https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
Sep 04
EDIF S.p.A.
Aurora
Italian wholesale distributor of electrical equipment, plumbing, and lighting systems; Aurora DLS claim Sep 4, attack estimated Aug 27; exposed data includes system passwords, certified email credentials, customer invoices, tax numbers, shipping records, CCTV configurations, financial databases, and a detailed 2024 financial report; 🟥 DLS claim only; verify before treating as a breach · Sources: https://www.dexpose.io/aurora-targets-italian-wholesale-distributor-edif-s-p-a/ · https://www.redpacketsecurity.com/aurora-ransomware-victim-edif-s-p-a/
Sep 04
Blanco & Etcheverry
Gunra
Uruguayan law firm (~$5M revenue); Gunra DLS claim Sep 4; no data scope or operational impact disclosed; 🟥 DLS claim only; verify before treating as a breach · Sources: https://ransomware.live/id/QmxhbmNvICYgRXRjaGV2ZXJyeUBndW5yYQ== · https://www.redpacketsecurity.com/gunra-ransomware-victim-blanco-etcheverry/
Sep 04
Occidental
Gunra
Venezuelan insurance company (~$157M revenue); Gunra DLS claim Sep 4; no data scope or operational impact disclosed; 🟥 DLS claim only; verify before treating as a breach · Sources: https://ransomware.live/id/T2NjaWRlbnRhbEBndW5yYQ== · https://www.redpacketsecurity.com/gunra-ransomware-victim-occidental/
Sep 04
Berlin Senate (urban development, transport, environment departments)
Rhysida
5.79 TB / 1.44M files published to dark web after Berlin refused 30 BTC ransom. Data includes critical infrastructure blueprints for Berlin water/power grids, police/LKA files, Bundeswehr documents, federal defense communication plans, CBRN threat assessments, 12,000+ personnel records. Exfiltration Aug 7-12; detection Aug 14; auction countdown ended Sep 4; data dumped Sep 4-5. 13 days before Sep 20 state election. · Sources: https://cybernews.com/news/stolen-berlin-government-files-dumped-on-dark-web-rhysida/ https://www.bankinfosecurity.com/berlin-rejects-rhysida-ransomware-blackmail-a-32731
Sep 03
DiaSorin S.p.A.
Settra
Settra DLS claim Sep 3 2026; Italian in vitro diagnostics multinational (EURONEXT Milan: DIA); data scope and volume not disclosed. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/settra-ransomware-attack-on-diasorin-s-p-a/
Sep 03
MedEvolve
Settra
Settra DLS claim Sep 3 2026; US medical billing and practice management software provider; ~820GB exfiltrated; estimated attack date Aug 11 2026. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/settra-ransomware-attack-on-medevolve/
Sep 03
Complete Packaging Solutions
Qilin
Qilin DLS claim Sep 3 2026; UK business services and packaging solutions provider. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/qilin-ransomware-targets-complete-packaging-solutions/
Sep 03
Katten Muchin Rosenman
SilentRansomGroup
Am Law firm claimed by SilentRansomGroup; DLS Sep 3; full-service US law firm; data scope and authenticity unverified. · Sources: https://www.redpacketsecurity.com/silentransomgroup-ransomware-victim-katten-muchin-rosenman/
Sep 03
IDScan.net
Unknown
153M+ US and Canadian driver's license scans (front/back, IR, UV images) offered on dark web via Nexus marketplace. FBI New Orleans field office opened investigation. Krebs traced data to IDScan.net (New Orleans, Louisiana). Nexus site went dark after Krebs reporting. Breach ongoing for over a year per seller claim. Clients include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment. · Sources: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ https://www.securityweek.com/153-million-driver-license-images-offered-on-dark-web/
Sep 02
Greenberg Traurig
SilentRansomGroup
Am Law firm claimed by SilentRansomGroup; DLS Sep 2; data scope and authenticity unverified; threat to publish if no contact made. · Sources: https://www.dexpose.io/silentransomgroup-compromises-greenberg-traurig/
Sep 01
Holland & Knight
SilentRansomGroup
Am Law firm claimed by SilentRansomGroup; DLS Sep 1; data scope and authenticity unverified; threat to publish if no contact. · Sources: https://www.hookphish.com/blog/ransomware-group-silentransomgroup-hits-holland-and-knight/
August 2026
Aug 30
AFSARD
Qilin
Qilin ransomware DLS claim posted August 30 2026. Organization based in Milton Keynes UK. Attack date not confirmed. · Sources: https://www.hookphish.com/blog/ransomware-group-qilin-hits-afsard/
Aug 29
Bandit Industries
Qilin
Qilin DLS claim Aug 29, 2026; US industrial equipment manufacturer; scope and data volume unconfirmed · Sources: https://www.ransomware.live/summary/
Aug 29
LAPoco Architects
Qilin
Qilin DLS claim Aug 29, 2026; architecture firm; scope and data volume unconfirmed · Sources: https://www.ransomware.live/summary/
Aug 28
Berlin State Government (Senate Department for Mobility and Environment)
Rhysida
Rhysida DLS claim Aug 28, 2026: 5.79TB exfiltrated Aug 7-12 from Berlin's Senate Department for Mobility, Transport, Climate Protection and Environment; 80K administrative offence proceedings and 46.5K contracts claimed; 30 BTC ransom demand (approx EUR 2M); Berlin refuses to pay; auction countdown started Aug 28; September 20 Abgeordnetenhaus election context; Interior Senator says election data not affected · Sources: https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
Aug 27
Manchester Airports Group
Unknown
Cyberattack disclosed Aug 27 on Manchester, Stansted, and East Midlands airports; 8.7M customer records exposed including WiFi registrations, email addresses, phone numbers, vehicle registrations, parking/lounge bookings; payment data and passwords not stored on affected system; ransom demanded but not paid; actor unattributed · Sources: https://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943 · https://cybernews.com/security/manchester-airport-cyber-attack-9-million-wifi-data-breach/
Aug 27
Providence Investments
Qilin
DLS posting Aug 27; no data volume or proof of exfiltration provided; 🟥 unverified claim · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-providence-investments/ · https://ransomware.live/group/qilin
Aug 27
Displaydata
Qilin
DLS posting Aug 27; UK-based tech company specialising in electronic shelf labels; no data volume or proof of exfiltration provided; 🟥 unverified claim · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-displaydata/ · https://ransomware.live/id/RGlzcGxheWRhdGFAcWlsaW4=
Aug 26
Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)
Qilin
Qilin posted ATF (atf.gov) to DLS Aug 26. ATF confirmed 'major cybersecurity incident' on a standalone system isolated from enterprise network. DOJ designated it a major incident under federal guidelines. No data samples published by Qilin. Standalone system; eForms and enterprise network unaffected. · Sources: https://cybernews.com/news/qilin-ransomware-bureau-alcohol-tobacco-firearms-atf-cyberattack/
Aug 26
Air International Thermal Systems
Qilin
Qilin DLS posting Aug 26. Air International Thermal Systems is a US provider of thermal management and HVAC solutions for industrial and defense applications. Unverified DLS claim; no data samples published. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-air-international-thermal-systems/
Aug 26
Metal Conversions
Qilin
Qilin DLS posting Aug 26. Metal Conversions is a US metals manufacturing company. Unverified DLS claim; no data samples published. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-metal-conversions/
Aug 25
National Kidney Registry
Direwolf
Organ donor-recipient matching nonprofit; DLS claim Aug 25. Five healthcare victims for Direwolf in 16 days. 🟥 Unverified DLS claim. · Sources: https://www.ransomware.live/group/direwolf
Aug 25
Johnson City Honda
Global Secret Group
Car dealership, Tennessee. DLS claim Aug 25. 🟥 Unverified DLS claim. · Sources: https://ransomware.live/
Aug 25
PCA Group Sdn. Bhd.
Majinahanashi
Malaysian company. DLS claim Aug 25 by Majinahanashi group. 🟥 Unverified DLS claim. · Sources: https://ransomware.live/
Aug 25
McKesson Corporation
ShinyHunters
ShinyHunters claimed theft of 284M patient data records via third-party application compromise; McKesson confirmed the incident in an SEC 8-K and launched investigation; data allegedly includes names, SSNs, DOBs, patient IDs, Medicaid numbers, medical records, medications — 284M is raw record count, unique individual count TBD; claim unverified · Sources: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
Aug 25
Boston Scientific
Unknown
Cyberattack caused global IT disruption; systems supporting order processing and shipment affected; Cork Ireland manufacturing facility workers sent home; investigation by third-party incident response firm ongoing; actor unattributed; timeline for restoration unknown · Sources: https://techcrunch.com/2026/08/26/medical-device-maker-boston-scientific-says-a-cyberattack-is-causing-a-global-disruption-to-its-operations/
Aug 24
Espac
The Gentlemen
Chilean construction company; The Gentlemen DLS claim Aug 24 threatening sensitive data exposure · Sources: https://www.dexpose.io/thegentlemen-ransomware-attack-on-espac/
Aug 23
Clear Align
Qilin
Optical engineering company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-ransomware-attack-on-clear-align/
Aug 23
Difor
Qilin
Chilean distribution/retail company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-ransomware-group-strikes-chilean-company-difor/
Aug 23
Aurore Development S.p.A.
Qilin
Italian business services company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-targets-aurore-development-s-p-a-in-ransomware-attack/
Aug 22
PenLink
Qilin
Qilin ransomware DLS claim August 2026; PenLink is a US surveillance technology company providing investigative tools to law enforcement; data scope unconfirmed · Sources: https://www.galaxywarden.com/blog/breach/penlink-qilin-2026-08
Aug 22
Agunsa
Qilin
Qilin ransomware DLS claim August 2026; Agunsa is a major Chilean port and logistics services company; data scope unconfirmed · Sources: https://www.galaxywarden.com/blog/breach/agunsa-qilin-2026-08
Aug 22
Thialf
The Gentlemen
TheGentlemen ransomware DLS claim August 22 2026; Thialf is an international speed skating venue in Heerenveen, Netherlands; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 22
Promatrix
The Gentlemen
TheGentlemen ransomware DLS claim August 22 2026; Promatrix is a US IT services firm; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 22
BOK Financial
ShinyHunters
ShinyHunters DLS claim Aug 22 2026; BOK Financial is a major US financial holding company (NASDAQ: BOKF, ~$50B assets, Tulsa OK); ransom deadline August 24; data scope not disclosed; 🟥 unverified DLS claim · Sources: DEXpose · RansomLook
Aug 22
NovoCure
ShinyHunters
ShinyHunters DLS claim Aug 22 2026; NovoCure (NYSE: NVCR) makes Tumor Treating Fields cancer-treatment devices; data scope and deadline not publicly confirmed; 🟥 unverified DLS claim · Sources: RansomLook
Aug 22
Integrated Health Systems
CoinbaseCartel
CoinbaseCartel DLS claim Aug 22 2026; Integrated Health Systems (ihs911.com) is a US healthcare provider; data-theft extortion with 48h contact window, 10-day payment deadline; data scope unconfirmed; 🟥 unverified DLS claim · Sources: DEXpose
Aug 22
RXPE Group
CoinbaseCartel
CoinbaseCartel DLS claim Aug 22 2026; RXPE Group (rxpe.com) is a Chinese energy company; data-theft extortion with 48h contact window, 10-day payment deadline; data scope unconfirmed; 🟥 unverified DLS claim · Sources: DEXpose
Aug 22
Vietnam Electricity (EVNHANOI)
Emperador
Emperador ransomware DLS claim Aug 22 2026; EVNHANOI is Vietnam's Hanoi Electricity Corporation, a state-owned critical infrastructure entity; Emperador is a lower-profile group with limited prior reporting; data scope unconfirmed; 🟥 unverified DLS claim · Sources: RansomLook
Aug 21
NTE Italia
Panzer
Panzer ransomware DLS claim August 21 2026; NTE Italia is an engineering and telecommunications service provider based in Catanzaro, Italy; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 21
JC Sales
Akira
Akira ransomware DLS claim August 21 2026; JC Sales is a full-service wholesaler based in Los Angeles; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 21
Apollo Global Management
Falcon/Helix/Pink/Redact
Social engineering attack July 6-10 2026; SSNs, names, DOBs, home addresses compromised from cloud systems; part of wider wave targeting major financial firms including Blackstone, Bridgewater, Bain Capital; disclosed Aug 21 / notified California AG Aug 20 · Sources: https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/
Aug 20
Kingston Technology
Everest
Everest ransomware DLS claim August 20 2026; 9,438 files / 138.49 GB claimed exfiltrated; data described as APAC-focused (Taiwan, Japan, Korea, Thailand, Vietnam, India, Australia, NZ, Malaysia, Singapore); Kingston said operations unaffected; Kingston manufactures DRAM and flash storage · Sources: https://www.cyberdaily.au/security/14078-exclusive-ram-maker-kingston-technology-investigating-ransomware-claims
Aug 20
Capgemini Engineering
Everest
Everest ransomware DLS listing August 20 2026 against Capgemini Engineering (formerly Altran, global engineering and technology services firm); data scope and impact unconfirmed · Sources: https://cypro.co.uk/insights/cyber-bulletins/everest-ransomware-claims-capgemini-engineering-listing/
Aug 20
Hospital for Sick Children (SickKids)
Unknown
Employee and job-applicant personal data exposed via vulnerability in unnamed third-party careers website software; clinical systems and patient data not affected; SickKids, Boomerang Health, SickKids Foundation employees and applicants impacted; vendor unnamed suggesting wider supply-chain exposure · Sources: CP24 · BleepingComputer · The Record
Aug 19
Senvest Capital
The Gentlemen
TheGentlemen ransomware group DLS claim Aug 19 2026 against international hedge fund and investment firm; data theft threatened; Senvest manages billions in public equities, private markets, and real estate; no public confirmation from Senvest · Sources: https://www.dexpose.io/thegentlemen-ransomware-targets-senvest-capital/
Aug 19
Babcock Africa
The Gentlemen
TheGentlemen ransomware DLS claim August 19 2026; Babcock Africa is a major engineering and asset management company serving critical infrastructure and heavy equipment across Africa; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://ransomware.live/id/QmFiY29ja0B0aGVnZW50bGVtZW4=
Aug 18
Zebra Technologies
Clop
Clop listed Zebra Technologies (ZEBRA.COM; global provider of RFID, barcode, and enterprise mobile computing solutions; ~.6B annual revenue) on its DLS around August 18, 2026, claiming exfiltration of 8TB of sensitive data including critical databases and CAD files, consistent with the PTC Windchill/FlexPLM campaign (CVE-2026-12569). 8TB would be the largest single-organization claim in this campaign. DLS claim — extent of access and veracity unverified. · Sources: https://www.dexpose.io/clop-ransomware-targets-zebra-com-in-major-data-breach/
Aug 18
Logitech
ShinyHunters
ShinyHunters DLS claim August 18 2026 against Logitech and its Streamlabs streaming platform; payment deadline set for August 21; data scope and scale unconfirmed; no public statement from Logitech as of August 21 · Sources: https://www.cyberdaily.au/security/14076-pay-or-leak-shinyhunters-delivers-ultimatum-to-logitech
Aug 18
R&D Machine and Engineering
DragonForce
DragonForce ransomware group posted R&D Machine and Engineering (rdmachine.com) on its DLS Aug 18; US aerospace and defense manufacturer; sensitive engineering data threatened for release. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/dragonforce-strikes-r-d-machine-and-engineering/
Aug 14
Direction Generale des Finances Publiques (DGFiP)
ZeroBytes (individual threat actor)
Hacker using alias ZeroBytes gained access via stolen internal VPN credentials in late June 2026; exfiltrated records of 678,000 individuals and businesses (names, reference income data, tax rates) in first breach (June); second theft (July) took 200,000 land-registry account details. DGFiP confirmed breach Aug 12 after ZeroBytes posted claim publicly. Data exposure creates targeted physical-robbery risk for high-income crypto holders in France given 30 violent wrench attacks in H1 2026. · Sources: https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
Aug 14
Baxter International
ShinyHunters
ShinyHunters DLS claim August 14 2026 against Baxter International; 7.1 million Salesforce records with PII claimed; extortion deadline was August 17; as of August 22 no data has been published · Sources: https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-baxter-international-inc/
Aug 13
D&J Beverage Service
Qilin
Qilin DLS claim August 13, 2026; scope unconfirmed. · Sources: https://www.ransomware.live/group/qilin
Aug 13
SIA Medical Centre
Rhysida
Rhysida DLS claim August 13, 2026; SIA Medical Centre Melbourne; scope unconfirmed. · Sources: https://www.ransomware.live/group/rhysida
Aug 13
CF Supply
Akira
Akira DLS claim August 13, 2026; industrial supply distributor; scope unconfirmed. · Sources: https://www.ransomware.live/group/akira
Aug 13
GB Group S.A.
DragonForce
DragonForce DLS claim August 13, 2026; scope and country unconfirmed. · Sources: https://www.ransomware.live/group/dragonforce
Aug 13
Shell
Clop
Clop listed Shell on DLS as part of mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed 89GB of engineering drawings, facility scans, test reports and project plans. Shell confirmed it is investigating a potential incident. DLS claim — breach not confirmed. · Sources: https://www.technadu.com/shell-and-philips-confirm-investigation-following-cl0p-data-theft-claims-targeting-nearly-50-companies-including-fiserv-and-ge/633182/
Aug 13
Philips
Clop
Clop listed Philips on DLS in mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed 13.5GB of PDF drawings, diagrams and blueprints. Philips confirmed an investigation is underway. DLS claim — breach not confirmed. · Sources: https://www.technadu.com/shell-and-philips-confirm-investigation-following-cl0p-data-theft-claims-targeting-nearly-50-companies-including-fiserv-and-ge/633182/
Aug 13
General Electric
Clop
Clop listed GE on DLS as part of mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed engineering data. GE has made no public statement. DLS claim — breach not confirmed. · Sources: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
Aug 12
B Wright Drywall
Qilin
DLS claim by Qilin (Aug 11-13 posting); Canadian construction firm; scope and data volume unverified · Sources: https://www.ransomware.live/group/qilin
Aug 12
Fiserv
Clop
Clop DLS claim August 12, 2026 against Fiserv (global fintech/payments processor); scope unconfirmed; first appeared in tracker August 14. · Sources: https://www.bleepingcomputer.com/news/security/
Aug 11
Pennsylvania Attorney General's Office
Unknown
Ransomware attack struck communications systems; 1,200 staff affected; courts granted case extensions; recovery ongoing August 11 · Sources: https://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery
Aug 11
Stade Français Paris
Qilin
Qilin DLS August 11, 2026; Aug 15 deadline; player passport/ID data published as proof-of-breach; club filed complaint with French authorities; no payment confirmed. · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-stade-francais/
Aug 11
Otter Tail County
INC Ransom
INC Ransom DLS claim posted August 17, 2026; attack estimated August 11. County government (population ~60,000, west-central Minnesota). Scope unconfirmed. · Sources: https://www.ransomware.live/id/T3R0ZXIgVGFpbCBDb3VudHksIE1pbm5lc290YUBpbmNyYW5zb20=
Aug 10
ATMS & Co. LLP
INC Ransom
Chartered accountant firm; INC_RANSOM DLS posting August 10, 2026; part of INC's SonicWall SMA 1000 exploitation campaign (CVE-2026-15409/CVE-2026-15410 CVSS 10.0); data scope unconfirmed · Sources: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Aug 10
Astro Electroplating
Qilin
Qilin DLS posting August 10, 2026; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10
Chung Tai Shin Chemical Industry Co.
Qilin
Qilin DLS posting August 10, 2026; chemicals and manufacturing sector; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10
AIMS Group
The Gentlemen
TheGentlemen DLS posting August 10, 2026; UAE-based conglomerate; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10
Canopy Support Services
The Gentlemen
TheGentlemen DLS posting August 10, 2026; Canadian nonprofit; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10
Actini Group
KRYBIT
KRYBIT ransomware DLS posting August 10, 2026; French industrial machinery manufacturer; data scope unconfirmed · Sources: https://www.redpacketsecurity.com/krybit-ransomware-victim-www-actini-com/
Aug 10
Unlimited Technology Systems
Unknown
Ohio-based healthcare revenue cycle management firm; breach Oct 5-10 2025; detected Oct 19 2025; HHS OCR notification filed late July 2026 confirming 3,803,750 individuals affected; SSNs DOBs medical/insurance data stolen; largest healthcare breach of 2026 YTD by victim count · Sources: https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/
Aug 10
Quironsalud
Direwolf
Spain's largest private hospital group (50+ hospitals, ~13,000 beds). Attack discovered Aug 10; DLS claim Aug 10-11. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/direwolf-ransomware-attack-on-quironsalud-spains-health-giant/
Aug 09
Studio Associato Tibaldi
Unknown
DLS claim posted August 9 on ransomware.live; Italian professional firm based in Rome; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 09
Siam Oil Product Co. Ltd.
Unknown
DLS claim posted August 9 on ransomware.live; Thai petroleum and industrial distributor; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 08
Filtronic plc
Qilin
Qilin DLS claim August 8 2026; UK-listed manufacturer of RF/microwave components for defence and telecoms infrastructure; no statement from Filtronic; data scope and impact unconfirmed · Sources: https://www.hendryadrian.com/ransom-filtronic-aug-2026/
Aug 08
Clausing Industrial
Qilin
Qilin DLS claim August 8 2026; Michigan-based metalworking machinery manufacturer; no statement from Clausing; data scope and impact unconfirmed · Sources: https://www.ransomware.live/group/qilin
Aug 08
CLLS Co Ltd
Qilin
Qilin DLS claim August 8 2026; sector and country of origin unconfirmed; no victim statement · Sources: https://www.ransomware.live/group/qilin
Aug 08
Louisville Bar Association
INC Ransom
INC Ransom DLS claim August 8 2026; Kentucky-based legal professional association; consistent with INC Ransom sustained 2026 legal-sector campaign; no victim statement; data scope unconfirmed · Sources: https://www.ransomware.live/group/incransom
Aug 08
Daily Trust
Unknown
DLS claim posted August 8 on ransomware.live; Nigerian national newspaper/news organization; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 07
Levi Strauss
Unknown
Social engineering of employee computers; attacker accessed corporate files; consumer data not affected; breach contained · Sources: https://therecord.media/levis-data-breach-social-engineering
Aug 07
IEH Corporation
Unknown
SEC cybersecurity disclosure; producer of components for military satellites, missiles, fighter jets; cyberattack discovered early August, containment actions taken · Sources: https://therecord.media/military-device-manufacturer-discloses-cyber-incident
Aug 07
Stade Français
Unknown
Paris-based Top 14 rugby club; systems restored after cyberattack; data leak under investigation · Sources: https://therecord.media
Aug 07
Morguard Corporation
Helix
Helix ransomware group (emerged July 2026; Microsoft OAuth/SharePoint data exfiltration, no custom malware) posted DLS claim Aug 7; 160GB claimed exfiltrated; negotiations broke down. Helix uses voice phishing and OAuth abuse targeting SharePoint. · Sources: https://ransomware.live/id/TW9yZ3VhcmRASGVsaXg=
Aug 06
Signature Services
Play
Play ransomware DLS listing, Aug 6 2026; files encrypted, data exfiltrated · Sources: https://ransomware.live/id/U2lnbmF0dXJlIFNlcnZpY2VzQHBsYXk=
Aug 06
TechVentures Bank S.A.
RansomHouse
RansomHouse DLS listing Aug 6 2026; double extortion · Sources: https://www.ransomware.live/group/ransomhouse
Aug 05
Allied Telesis
Everest
Everest posted Allied Telesis (global networking solutions provider, Tokyo) on its DLS on August 5 2026; estimated attack date July 17 2026. Group threatened data leak unless demands met. DLS claim — scope unverified. · Sources: https://www.dexpose.io/everest-ransomware-group-targets-allied-telesis/
Aug 05
FIS Global
Clop
Clop listed FIS Global (one of the world's largest financial technology providers, serving thousands of financial institutions) on its DLS on Aug 5, claiming 874GB of exfiltrated data including project files, CAD files, and Windchill-related engineering data — consistent with the PTC Windchill/FlexPLM campaign (CVE-2026-12569) that also hit Shell, GE, Philips, and Fiserv. FIS has not confirmed breach. DLS claim only — unverified. · Sources: https://malware.news/t/clop-ransomware-targets-fis-global/124620
Aug 04
Trulite Glass and Aluminum Solutions
INC Ransomware
INC Ransomware DLS claim August 4 2026; US glass and aluminium manufacturer; attack via SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410 CVSS 10.0); no statement from Trulite; data scope unconfirmed · Sources: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Aug 04
BLACKBURN's Physicians Pharmacy
Anubis
Anubis ransomware DLS claim approximately August 3-4 2026; US healthcare pharmacy; no statement from BLACKBURN's; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 04
RUPP Spritzguss
Qilin
Qilin DLS claim approximately August 4 2026; German plastics injection-moulding manufacturer; no statement from RUPP; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 04
North Carolina Ports (Wilmington, Morehead City, Charlotte Inland Port)
Unknown
Cyberattack detected Aug 4; ports operating manually with IT systems partially offline; NC DOIT, USCG, and external forensics engaged; no exfiltration confirmed · Sources: https://therecord.media/cyberattack-north-carolina-ports
Aug 03
Amgen
Unknown
Unauthorized access to third-party cloud systems detected July 2026; PHI and proprietary company data exfiltrated; Amgen disclosed via SEC 8-K filing approximately August 3; forensic investigation ongoing; no patient count disclosed; no operational disruption reported; no threat actor claimed credit · Sources: https://therecord.media/amgen-hackers-cyberattack-sec https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
Aug 03
Winn-Dixie
Anubis
Anubis ransomware DLS claim August 3 2026; major US Southeast grocery chain; no statement from Winn-Dixie; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 03
Cameron Regional Medical Center
Anubis
Anubis ransomware DLS claim August 3 2026; regional US medical centre; no statement from Cameron Regional; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 03
Service Electric
Qilin
Qilin DLS claim approximately August 3 2026; US regional telecom; no statement from Service Electric; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 02
Encore Enterprises
CRPxO
CRPxO DLS claim August 2 2026; US commercial real estate firm; attacker claims 700 GB exfiltrated. No victim statement; data not yet published. · Sources: https://www.ransomware.live/id/RW5jb3JlIEVudGVycHJpc2VzLCBJbmMuQENSUHhP
Aug 02
ProHealth Medical Group
Krybit
Krybit DLS claim August 2: 114 GB of data claimed exfiltrated from Singapore healthcare provider ProHealth Medical Group Pte Ltd (prohealth.sg). Patient and operational data scope unconfirmed; no victim statement. 🟥 DLS claim only. · Sources: https://www.dexpose.io/krybit-ransomware-targets-singapores-prohealth-medical-group/ · https://www.redpacketsecurity.com/krybit-ransomware-victim-www-prohealth-sg/
Aug 02
ProHealth Medical Group Pte Ltd
Krybit
Krybit ransomware posted DLS claim Aug 2; 114GB data claimed from Singapore primary healthcare provider (11 clinics). Krybit also targeted Actini Group (France) Aug 10. · Sources: https://www.dexpose.io/krybit-ransomware-targets-singapores-prohealth-medical-group/
Aug 01
Philippine Savings Bank
The Gentlemen
TheGentlemen claim on DLS August 1 2026; separate from January 2026 Qilin listing (different group, independent claim). No statement from PSBank; no data published. · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-philippine-savings-bank/
Aug 01
Sigma Plastics Group
Play
Play DLS claim August 1 2026; major US plastics manufacturer. No victim statement; no data published. · Sources: https://www.redpacketsecurity.com/play-ransomware-victim-sigma-plastics-group/
Aug 01
The Butcher Brothers
Play
Play DLS claim August 1 2026; US food processing/distribution. No victim statement; no data published; no data volume disclosed. · Sources: https://www.ransomware.live/id/VGhlIEJ1dGNoZXIgQnJvdGhlcnNAcGxheQ==
Aug 01
Questel SAS
ShinyHunters
ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 21M+ Salesforce records plus 147 GB internal corporate data; Questel is a major IP and patent management firm serving global enterprise clients; no statement from Questel; data not yet published · Sources: https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/ https://www.dexpose.io/shinyhunters-breach-questel-sas-french-ip-giant-under-siege/
Aug 01
Alcon Inc.
ShinyHunters
ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 25M+ Salesforce records with PII; Alcon is a global ophthalmology medical device and pharmaceutical company; no statement from Alcon; data not yet published · Sources: https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-alcon-inc/ https://www.dexpose.io/shinyhunters-breach-alcon-inc/
Aug 01
Lumenis Ltd.
ShinyHunters
ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 1.1M+ customer and employee records plus 176 GB internal corporate data; Lumenis manufactures surgical and aesthetic laser systems; no statement from Lumenis; data not yet published · Sources: https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-lumenis-ltd/ https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/
July 2026
Jul 31
Brinks Home
ShinyHunters
ShinyHunters claims breach via Microsoft Entra vishing attack July 13; detected by Brinks July 20; claimed: 4.9M+ Salesforce records including 1.1M customer contacts, 3.8M customer support chat logs (Cresta), 4000+ employee PII rows; CEO confirmed breach, alarm monitoring unaffected · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/ https://www.theregister.com/security/2026/07/31/the-most-famous-brand-in-physical-security-got-pwned-by-shinyhunters/5281924
Jul 31
Kuveyt Turk / Finansbank / Anadolubank / Turkish Airlines (THY)
CRPxO
CRPxO ransomware posted wave of Turkish targets July 31: Kuveyt Turk (0.8 GB), Finansbank (2.3 GB), Anadolubank (0.4 GB), Turkish Airlines/THY (4.2 GB); also claimed Johnson & Johnson, Dogan Holding, Anadolu Sigorta, Hyundai · Sources: https://www.ransomware.live/
Jul 31
Hawaii Family Dental
Qilin
Qilin posted Hawaii Family Dental on DLS July 31; dental healthcare provider; Qilin exploiting CVE-2026-0257 (PAN-OS GlobalProtect) as primary initial access; 1358+ cumulative Qilin victims · Sources: https://www.ransomware.live/ https://cybersecuritynews.com/qilin-ransomware-claims-1358-victims/
Jul 31
Hyundai Motor Türkiye
CRPxO
CRPxO DLS claim July 31: 1.5 GB of recruitment and personnel data including interview answers, evaluation scores, and tracking logs. Part of the broader July 31 CRPxO Turkish wave. 🟥 DLS claim only; no victim statement. · Sources: https://gbhackers.com/crpx0-ransomware-claims-hyundai-turkey-breach/amp/ · https://cyberpress.org/crpx0-ransomware-claims-hyundai-turkey-breach/
Jul 31
Southeastern Oklahoma State University
Interlock
Interlock ransomware attack on public university in Durant OK; confidential financial records including unaudited earnings reports and tax files stolen; campus closed 3 days; 42,000 students locked out; DLS claim posted Aug 19 2026 · Sources: https://www.kxii.com/video/2026/08/03/southeastern-oklahoma-state-university-reopen-tuesday-after-cybersecurity-incident/
Jul 30
Indus Protech Solutions
The Gentlemen
TheGentlemen DLS claim July 30, 2026; Chennai-based bulk MRO and supply chain services provider for global trade; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-indus-protech-solutions/ · https://www.ransomware.live/
Jul 30
Malaysian Nuclear Agency
The Gentlemen
TheGentlemen DLS claim July 30, 2026; Malaysian government nuclear research and technology organisation; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 30
MicroPhase Corporation
The Gentlemen
TheGentlemen DLS claim July 30, 2026; US defense electronics and IT company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 30
Kontact Consortium India
INC Ransom
INC_RANSOM DLS claim July 30, 2026; Indian engineering and manufacturing company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 29
StellarRAD Systems
Space Bears
Posted to Space Bears DLS July 29; sector and data scope unconfirmed · Sources: https://www.ransomware.live/
Jul 29
Bretford Manufacturing
Aurora
Posted to Aurora ransomware DLS July 29; data scope unconfirmed · Sources: https://www.ransomware.live/
Jul 29
Administratia Nationala a Penitenciarelor (ANP)
Unknown
Romanian National Prison Administration posted to DLS July 29; group unconfirmed; data scope unknown · Sources: https://www.ransomware.live/
Jul 29
Analog Devices
ExfilSquad
Analog Devices filed SEC 8-K disclosing breach detected June 23 2026; ExfilSquad claimed 570,000+ records stolen; ADI says operations unaffected and no evidence data leaked or misused; investigation ongoing · Sources: https://www.securityweek.com/semiconductor-firm-analog-devices-discloses-data-breach/ https://www.bloomberg.com/news/articles/2026-07-29/analog-devices-discloses-data-breach-after-unauthorized-access
Jul 29
Accenture
888
Threat actor 888 (PwnForums) claimed theft of 35 GB including Azure DevOps source code, Azure access keys, tokens, RSA/SSH keys, and config files; Accenture confirmed incident was contained with no operational impact; disclosed approximately July 29 2026 · Sources: https://www.securityweek.com/accenture-confirms-data-breach-after-hacker-claims-source-code-theft/ https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
Jul 29
CEVA Logistics
Unknown
Cyberattack on 8 European warehouses (Jul 29 attack, Aug 1 notification); customer data (names, addresses, phones, emails, order data) exposed for clients including Valve/Steam, Ajax, banks, and retailers; Dutch DPA investigating; no ransomware deployed · Sources: https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
Jul 28
Affinia Healthcare
Termite
St. Louis multidisciplinary medical system; Termite ransomware DLS posting July 28 2026; class action investigation opened; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://www.redpacketsecurity.com/termite-ransomware-victim-affinia-healthcare/
Jul 28
Swiss Federal IT Office (FOITT/BIT)
Unknown
SharePoint exploitation chain (CVE-2026-55040 JWT bypass + CVE-2026-56164 EoP); ~200 user and technical accounts compromised; attack detected July 28, external access blocked, passwords reset, servers being rebuilt; no confirmed data exfiltration beyond compromised credentials; attackers described as previously unknown · Sources: https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
Jul 27
MCBS (Medical Computer Business Services)
PEAR
Healthcare revenue cycle management firm; 1,261,464 patients exposed across 7 healthcare providers; 3TB data allegedly exfiltrated; 5-day compromise Sep 22-26 2025; not detected until May 28 2026; PEAR operates without encryption (pure extortion) · Sources: https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/
Jul 27
Ernst and Young
ShinyHunters
Supply-chain compromise of third-party IT service management platform Mar 28-Apr 12 2026; yielded credentials to EY Jira, GitHub, Azure; client tax documents with SSNs and financial data; July 31 2026 deadline issued · Sources: https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
Jul 26
Multiple Minnesota Water and Wastewater Utilities (30+)
CyberAv3ngers
Coordinated OT attack on 30+ community water and wastewater systems including Plymouth, South St. Paul, Braham, and Maple Plain; automated control functions disrupted, some systems switched to manual; no water quality impact reported; MNIT activated statewide incident response; FBI investigating; pattern matches CyberAv3ngers/Iranian ICS tradecraft · Sources: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/ · https://www.securityweek.com/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks/
Jul 26
UK Police National Legal Database (PNLD)
ExfilSquad
Attack detected July 26 2026; PNLD confirmed breach; ExfilSquad claims 135,000 contact records of UK police officers, criminal justice staff, and government partners (names, organisations, email addresses); 14 total ExfilSquad victims across 5 countries in this wave; exposure of officers in sensitive investigations is primary concern · Sources: https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/amp/ https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
Jul 26
Wesco International
ExfilSquad
Data extortion group ExfilSquad claims to have exfiltrated 2.6M records from Wesco cloud CRM environment (Jul 26 attack); leaked via torrents Aug 7; customer lists, shipment details, project pricing exposed; Wesco confirmed incident Aug 11; no ransomware encryption · Sources: https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
Jul 25
Traffic Control and Road Safety Services
Qilin
DLS posting July 25 2026 by Qilin. Sector and country unconfirmed from snippets. · Sources: https://www.ransomware.live/
Jul 25
Guntert & Zimmerman
Qilin
DLS posting July 25 2026 by Qilin. Guntert & Zimmerman manufactures heavy concrete paving equipment. Country inferred from name. · Sources: https://www.ransomware.live/
Jul 25
Plitvicka Jezera Nacionalni Park
Qilin
Plitvice Lakes National Park (Croatia), UNESCO World Heritage Site. DLS posting July 25 2026 by Qilin. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25
Principle Diagnostics Laboratory
Qilin
DLS posting July 25 2026 by Qilin. Diagnostic laboratory; sector confirmed, country unconfirmed. · Sources: https://www.ransomware.live/
Jul 25
GURR Abdichtungstechnik GmbH
Qilin
German waterproofing/sealing technology firm. DLS posting July 25 2026 by Qilin. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25
Yourway Transportation
Moneymessage
DLS posting July 25 2026 by Moneymessage. US transportation company. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25
SistNet
Nova
DLS posting July 25 2026 by Nova group. IT services firm. Country and data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25
Jubilee Jobs
Qilin
DLS posting July 25 2026 by Qilin. Employment/staffing services firm. Country and data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25
The Myers Y Cooper
Qilin
DLS posting July 25 2026 by Qilin. Professional services firm; sector and country unconfirmed from snippets. · Sources: https://www.ransomware.live/
Jul 25
Health Law Advocates
INC Ransom
Boston non-profit legal organization; INC Ransom DLS posting July 26 2026, estimated attack date July 25; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://www.ransomware.live/
Jul 25
AnMed Health System
Unknown
79 of 106 facilities closed including oncology, radiation, infusion, and imaging services; 72-hour ransom demand issued; FBI and SLED investigating; class action investigations underway · Sources: https://www.hipaajournal.com/anmed-closes-almost-80-facilities-while-it-grapples-with-cyberattack/ · https://www.healthcareitnews.com/news/anmed-given-72-hours-respond-demands-ransomware-incident
Jul 24
Bank of Baroda
Triple X
Triple X DLS claim July 24; ~1 TB data alleged exfiltrated; estimated attack date May 12, 2026; government-owned second-largest public-sector bank in India. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 23
Origin Energy
Unattributed
4.8 million customer records breached; names, addresses, DOBs, phone numbers, partial payment card/bank account details. Company engaged ACSC and Australian Federal Police. · Sources: https://therecord.media/australia-origin-energy-data-breach
Jul 23
Czech Philharmonic
The Gentlemen
TheGentlemen DLS claim July 23; data volume not yet disclosed; cultural heritage institution based in Prague. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 23
LAXAI Life Sciences
Krybit
Krybit DLS claim July 23, 2026; LAXAI Life Sciences Pvt. Ltd. is a Contract Research, Development, and Manufacturing Organization (CRDMO) based in India; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.dexpose.io/krybit-ransomware-targets-laxai-life-sciences-in-india/ · https://www.cyfirma.com/news/weekly-intelligence-report-31-jul-2026/
Jul 22
Nidec Corporation
Blackfield
Blackfield ransomware group claimed Nidec Corporation (major Japanese manufacturer of electronic components for automotive and computing sectors) on DLS July 22, 2026; M ransom demand; full encryption plus exfiltration model; 🟥 unverified DLS claim only · Sources: https://www.bleepingcomputer.com/
Jul 22
South Korean National Diplomatic Academy
Unattributed (suspected DPRK)
South Korean Ministry of Foreign Affairs diplomatic training academy compromised; ~10,000 current and former diplomat records exfiltrated (names, IDs, email, encrypted passwords, job titles, affiliations); dwell time ~9-10 months (Apr/May 2025 – Feb 2026); zero-day + misconfigured security settings; South Korean officials describe exfiltration scope as 'unprecedented'; North Korean link under investigation; 🟨 attribution unverified · Sources: https://therecord.media/south-korea-cyberattack-foreign-ministry
Jul 22
Estee Lauder
Clop
Clop exploited Oracle E-Business Suite zero-day CVE-2025-61882 to access EL HR systems (attack Aug 9 2025, discovered Jun 19 2026, disclosed via CA AG filing Jul 22 2026); exposed SSNs, passport numbers, bank account details, health info, payroll and performance data for employees; 24 months Kroll identity monitoring offered · Sources: https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
Jul 22
Recsa
Qilin
Qilin DLS claim posted Jul 22-23; data leak threatened if no negotiations. Unverified — verify before treating as confirmed breach. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-recsa-in-south-africa/
Jul 22
Ingersoll Rand
Everest
Everest ransomware DLS claim posted August 8 2026, estimated attack date July 22 2026; attribution disputed — separate DeXpose report attributes incident to '0apt ransomware'; Ingersoll Rand has not issued a statement; this is at least their second ransomware-related incident of 2026 (ALP-001 March 2026) · Sources: https://x.com/FalconFeedsio/status/2079991407490851128 · https://www.dexpose.io/0apt-ransomware-attack-targets-ingersoll-rand/
Jul 21
Fairlife (Coca-Cola subsidiary)
Anubis
Anubis RaaS (emerged Dec 2024) claimed the July 16 Fairlife ransomware attack on its DLS July 21, 2026; claims ~1TB exfiltrated corporate data with ransom deadline end of week; Coca-Cola confirmed attack via SEC filing (third-party access to Fairlife IT environment); US dairy production suspended; Canadian operations unaffected; 🟥 data scope and exfiltration volume unverified · Sources: BleepingComputer · Cybernews · Coca-Cola SEC filing
Jul 21
Stadler Rail
Everest
Everest data-theft gang breached supplier-shared data-exchange platform; CHF 10M (~2.3M) ransom demand rejected; criminal complaint filed; technical/manufacturing data targeted, no personal data claimed. Stadler refused to pay and terminated the compromised platform July 21-23, 2026. · Sources: https://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/
Jul 20
Advantage Home Health Care
The Gentlemen
US home healthcare company claimed by The Gentlemen extortion group July 20; no confirmation from organization · Sources: https://www.ransomware.live/
Jul 20
Adventus
LockBit
Singapore-based IT company claimed on LockBit DLS July 20; no confirmation from organization · Sources: https://www.ransomware.live/ · https://www.breachsense.com/breaches/
Jul 20
Alzone Software
Everest
India-based IT and software company claimed on Everest ransomware DLS July 20; no confirmation from organization · Sources: https://www.ransomware.live/ · https://www.breachsense.com/breaches/
Jul 20
Caterpillar Inc.
CoinbaseCartel
CoinbaseCartel (pure data-theft/extortion, no encryption; 160+ victims since Sept 2025) claimed Caterpillar Inc. July 20, 2026; initial access via credential reuse from infostealer logs; data scope unconfirmed; 🟥 unverified · Sources: DeXpose · HookPhish
Jul 20
Stroebel Gruppe
SafePay
SafePay DLS claim July 20, 2026; part of coordinated 7-victim Germany spree on same date; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 20
TimeTEX GmbH
SafePay
German educational supplies company; SafePay DLS claim July 20, 2026; part of coordinated 7-victim Germany spree on same date; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 20
L&A Transport
Akira
US trucking company; Akira DLS claim July 20, 2026; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 20
Brinks Home
Unknown
Dallas-based alarm and home security firm; unauthorized access detected July 20 2026; company disclosed July 28; outside cybersecurity experts engaged; blackmail threat reported; incident does not involve alarm products or monitoring services; customer data scope not yet disclosed; 🟨 confirmed by company · Sources: https://hoodline.com/2026/07/dallas-alarm-giant-brinks-home-shaken-by-cyber-heist-and-blackmail-threat-6930961/
Jul 19
Eana
Qilin
Qilin DLS posting July 19; data claimed exfiltrated; unverified — no public statement from Eana · Sources: https://www.ransomware.live
Jul 19
Synergy Products
Qilin
Qilin DLS posting July 19; data claimed exfiltrated; unverified — no public statement from Synergy Products · Sources: https://www.ransomware.live
Jul 19
MER-AL
Nova
Nova DLS posting July 19; data claimed exfiltrated; unverified — no public statement from MER-AL · Sources: https://www.ransomware.live
Jul 19
Dephub
Nova
Nova DLS posting July 19; Indonesian government transportation and ports authority entity; data claimed exfiltrated; unverified — no public statement from Dephub · Sources: https://www.ransomware.live
Jul 18
Droguería Martorani
Qilin
Argentine medical and hospital products importer/distributor, Buenos Aires; Qilin DLS claim Jul 18, 2026; founded 1970 by Luis Alberto Martorani; distributes medical equipment nationally; 🟥 unverified · Sources: https://ransomware.live/id/RHJvZ3VlcsOtYSBNYXJ0b3JhbmlAcWlsaW4=
Jul 18
Abbott Laboratories (Exact Sciences)
ShinyHunters
Abbott confirmed Jul 18, 2026 unauthorized access to limited systems in Cancer Diagnostics (Exact Sciences) business; ShinyHunters DLS claim alleges exfil of Microsoft Entra/ServiceNow/SharePoint/Databricks/Coupa data; claims: 30M+ rows customer PII, 1M+ SSNs, 22M+ medical order records, doctor-patient notes, NDAs; DLS deadline extended to Jul 21; ShadowByt3$ claims separate LabCentral portal breach under parallel investigation; Abbott has not confirmed data theft scope; 🟥 unverified · Sources: https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/ · https://cybernews.com/news/abbott-laboratories-breach-shinyhunters/ · https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business
Jul 18
Salina Supply
Qilin
Qilin DLS posting July 18; data claimed exfiltrated; unverified — no public statement from Salina Supply · Sources: https://www.ransomware.live
Jul 18
Reatile Group
INC Ransom
INC Ransom DLS posting July 18; data claimed exfiltrated; unverified — no public statement from Reatile Group · Sources: https://www.ransomware.live
Jul 18
D.MAG New Material Technology
INC Ransom
INC Ransom DLS posting July 18; data claimed exfiltrated; unverified — no public statement from D.MAG · Sources: https://www.ransomware.live
Jul 18
NewNet S.A.
DragonForce
Colombian IT/business-services company claimed on DragonForce DLS July 18; no confirmation from organization · Sources: https://www.ransomware.live/group/dragonforce
Jul 18
PCL Holding Public Co. Ltd
RansomHouse
RansomHouse DLS claim; Thai holding company; estimated attack date July 18 2026; no statement from PCL; data scope unconfirmed · Sources: https://www.ransomlook.io/recent
Jul 17
Acosol
Qilin
Spanish public water utility; Qilin DLS claim Jul 17, 2026; company confirmed cyberattack, activated security protocols, warned subscribers personal data including national ID numbers, contract info, and payment methods may be compromised; NIS2-classified critical infrastructure · Sources: https://www.ransomware.live/id/QWNvc29sQHFpbGlu · https://www.hendryadrian.com/acosol-suffers-cyberattack-urges-customers-to-stay-alert/
Jul 17
Cafar
Qilin
Argentine organisation; Qilin DLS claim Jul 17, 2026; cafar.org.ar; sector unconfirmed; 🟥 unverified · Sources: https://ransomware.live/id/Q2FmYXJAcWlsaW4=
Jul 17
Ecopetrol
Unattributed
Colombia's national oil company; unauthorized access to cloud-based file storage environments of approximately 15 subsidiaries; data from ~3,300 user accounts exfiltrated including financial records, customer data, and internal files; ransomware encryption attempt blocked by existing controls; external actor communicated extortion demands; no data published on leak sites as of July 20; criminal complaint filed with Colombian Attorney General; investigation ongoing with insurers and outside experts · Sources: https://www.prnewswire.com/news-releases/ecopetrol-reports-cybersecurity-incident-302828952.html https://colombiaone.com/2026/07/18/colombia-cyberattack-company-ecopetrol/
Jul 17
Danone
Qilin
Qilin DLS claim July 17: 221 GB claimed (91,558 files) including year-end financial summaries, customer account database, NDAs, and quarterly sales reports 2023-2025. Danone has not confirmed; treat as claim only. · Sources: https://cybernews.com/news/danone-evian-silk-international-delight-qilin-ransomware-attack/ · https://www.ransomware.live/group/qilin
Jul 16
Fairlife LLC (Coca-Cola subsidiary)
Unattributed
Coca-Cola subsidiary Fairlife detected unauthorised third-party access to production-related systems on July 16 2026; ransomware event halted all US dairy production including Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan; Canada operations unaffected; no actor claimed responsibility; no data theft confirmed; investigation ongoing with outside advisors; law enforcement notified · Sources: https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/ · https://www.theregister.com/cyber-crime/2026/07/17/ransomware-curdles-production-at-coca-colas-fairlife-dairy-biz/5274157 · https://www.helpnetsecurity.com/2026/07/17/coca-cola-fairlife-ransomware-attack/
Jul 16
Converting Equipment International
Interlock
UK-based manufacturing company (converting equipment). Attack date July 16 2026; DLS posting July 2026. Data leaked to Interlock's Worldwide Secrets Blog. · Sources: https://socradar.io/free-tools/ransomware-intelligence/victims/converting-equipment-international-interlock-bc57bbfc
Jul 15
Nihon Kotsu Co., Ltd.
AiLock
Malware attack July 11 disrupted taxi dispatch, hire-car reservation, and internal IT systems for Japan's largest taxi and limousine operator; no confirmed data exfiltration as of Jul 15 but investigation ongoing. Claimed on AiLock DLS July 15. · Sources: https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/
Jul 15
Ferrovial
AiLock
Global infrastructure and mobility operator claimed on AiLock DLS July 15; 147 compromised employees and 16 users listed, 106 third-party credentials. No public statement from Ferrovial. · Sources: https://ransomware.live/id/RmVycm92aWFsQEFpTG9jaw==
Jul 15
BRAC
The Gentlemen
World's largest NGO listed on The Gentlemen DLS July 15; no public statement from BRAC. Unverified claim. · Sources: https://www.ransomware.live/group/the-gentlemen
Jul 15
ATCOM Technology
DragonForce
Telecommunications manufacturer claimed on DragonForce DLS July 15. Country unconfirmed. No public statement. · Sources: https://www.ransomware.live/group/dragonforce
Jul 15
Panasonic Avionics Corporation
Coinbasecartel
US-based Panasonic subsidiary supplying in-flight entertainment and connectivity systems to commercial airlines; Coinbasecartel DLS claim Jul 15, 2026; claimed data includes employee records, user accounts, third-party credentials, external attack surface; no encryption confirmed — data-theft-first extortion model; 🟥 unverified · Sources: https://ransomware.live/id/UGFuYXNvbmljQWVyb0Bjb2luYmFzZWNhcnRlbA== · https://www.breachsense.com/breaches/panasonic-avionics-data-breach/
Jul 15
Fidelity Services Group
Ransomhouse
Southern Africa's largest integrated security solutions provider (guarding, cash management, fire protection, 60+ years); Ransomhouse DLS claim Jul 15, 2026; estimated attack date Jul 12; 🟥 unverified · Sources: https://ransomware.live/id/RmlkZWxpdHkgU2VydmljZXMgR3JvdXBAcmFuc29taG91c2U=
Jul 15
Ernst & Young (EY)
Unattributed
EY disclosed on July 15 that client data was accessed via a compromised third-party IT support platform used for UK client engagements; breach window estimated March-April 2026; exposed data includes client tax records, investment data, and Social Security Numbers for affected individuals; EY notified affected clients directly; investigation ongoing with external forensics; no ransomware group has claimed the breach; attack vector believed to be credential theft at the third-party vendor · Sources: https://www.bleepingcomputer.com/news/security/ey-discloses-data-breach-exposing-client-tax-and-financial-records/
Jul 14
Asimar (Asian Marine Service PCL)
DragonForce
Thailand's leading shipyard claimed on DragonForce DLS July 14; data type and volume unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 14
Momenta
DragonForce
Chinese AI and autonomous-driving company claimed on DragonForce DLS July 14; group claims access to source code, financial documents, and configuration files; unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 14
Sedemi
Qilin
Claimed on Qilin DLS July 14; sector and country unconfirmed · Sources: https://www.ransomware.live/group/qilin
Jul 14
Cedar Crest College
NightSpire
Liberal arts college in Allentown PA listed on NightSpire DLS July 14. Estimated attack date July 13. No public statement from Cedar Crest College. · Sources: https://ransomware.live/group/nightspire
Jul 14
Edison Global Networks Limited
DragonForce
Hong Kong-based IT systems integrator and MSP claimed on DragonForce DLS July 14; internal files alleged exfiltrated. No public statement. · Sources: https://www.hookphish.com/blog/ransomware-group-dragonforce-hits-edison-global-networks-limited/
Jul 13
Allied Plumbing Heating & Cooling
Qilin
HVAC/plumbing services company claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 13
Access Group International
DragonForce
Business services company claimed on DragonForce DLS July 13; data type and volume unconfirmed · Sources: ransomware.live · purpleops.io
Jul 13
Nichirei Corporation
RansomHouse
Ransomware attack disrupted 140 cold-chain distribution centers; impact on KFC Japan (1,300+ restaurants), Aeon, Kura Sushi supply chains. DLS claim posted Jul 22-23; data theft scope unverified. · Sources: https://www.japantimes.co.jp/business/2026/07/22/companies/nichirei-cyberattack-ransomhouse/
Jul 12
Retelit SpA
Qilin
Italian IT services and telecommunications infrastructure provider claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · undercodenews.com
Jul 12
Carolina Agri-Power
Qilin
Agricultural equipment dealer claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 12
Century Equities
Qilin
Real estate company claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 11
Alan F. Burke CPA
Qilin
Qilin DLS claim July 11, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 11
Bronken's Distributing
Qilin
Qilin DLS claim July 11, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 11
Carita
The Gentlemen
French luxury skincare and cosmetics brand claimed on The Gentlemen data leak site July 11; data type and volume unconfirmed; company has not issued a public statement · Sources: ransomware.live · breachsense.com
Jul 11
Nihon Kotsu
Unattributed
Japan's largest taxi and chauffeur operator; malware infection via unauthorised external access detected July 11; taxi dispatch, hire car web order/reservation management, and internal IT systems shut down for containment; no data exfiltration confirmed as of July 14; no group has claimed responsibility · Sources: https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/ https://www.scworld.com/brief/japans-largest-taxi-operator-suffers-cyberattack-disrupts-services
Jul 10
The Schuett Companies
Qilin
Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10
Eurodefi
Qilin
Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10
Sintax
Qilin
Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10
Commune de Castries
Payload
French municipality (Castries, Hérault); Payload DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/payload · Sources: [ransomware.live]
Jul 10
Robroy Industries
Brain Cipher
US manufacturing company; Brain Cipher DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jul 10
Finance Yorkshire
CMD
UK regional finance provider supporting business growth across Yorkshire and the Humber; CMD DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/cmdorganization · Sources: [ransomware.live]
Jul 10
Envision Unlimited
MoneyMessage
Chicago-based nonprofit providing residential, day, and community-based services for adults with intellectual and developmental disabilities; MoneyMessage DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/moneymessage · Sources: [ransomware.live]
Jul 10
Lidl
Unattributed
Third-party IT service provider breach; customer data from Lidl online shops in Germany, Belgium, and Netherlands exfiltrated; names, phone numbers, email addresses, dates of birth, customer numbers, and salutations exposed; passwords, billing/delivery addresses, bank details, and payment information potentially compromised; Lidl notified affected customers July 10; Dutch and Belgian data protection authorities notified; forensic investigation ongoing · Sources: BleepingComputer · Help Net Security · SC Media
Jul 09
Inter Power Engineering
Qilin
Qilin DLS claim July 9, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 09
IAC International
Brain Cipher
US industrial services company; Brain Cipher DLS claim July 9, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jul 09
Greene County Government (GA)
Incrandom
Greene County Georgia government; county servers taken offline after incident detected July 9 2026; Incrandom DLS posting July 28 2026; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://hoodline.com/2026/07/cyber-scare-knocks-greene-county-computers-offline/
Jul 09
Canadian Armed Forces (forces.gc.ca)
Bavaqai
Bavaqai (MedusaLocker/BAVACAI variant) listed the Canadian Armed Forces domain forces.gc.ca on its 'File Manager' DLS on approximately July 9 2026. Some tracker feeds index this under the medusalocker group slug. DLS claim — scope and exfiltrated data not confirmed. · Sources: https://socradar.io/data-breach/forces-medusalocker-ransomware-2026/
Jul 08
Accelirate Inc.
Qilin
Qilin DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/qilin · Sources: [SharkStriker] · [ransomware.live]
Jul 08
S.J. Louis Construction
Qilin
Qilin DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/qilin · Sources: [SharkStriker] · [ransomware.live]
Jul 08
Ample Surveyor Services
DragonForce
DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08
HIVE360
DragonForce
DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08
Dignity Health St. Mary's Medical Center
Akira
acute-care hospital (232 beds); Akira DLS claim April 2026; 41 GB claimed including employee passports, SSNs, government IDs, contracts, NDAs; victim notification letters sent July 2026; attack date estimated April 2026; 🟥 unverified — hospital has not issued public statement confirming breach · Sources: [ClassAction.org] · [BleepingComputer]
Jul 08
Wade's Dairy
Akira
Akira DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/akira · Sources: [SharkStriker] · [ransomware.live]
Jul 08
Aesthetic Surgical Images
INC Ransom
INC Ransom DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/incransom · Sources: [SharkStriker] · [ransomware.live]
Jul 08
Printronix
Brain Cipher
industrial printer manufacturer; Brain Cipher DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jul 08
PCCC Realty LLC
NightSpire
NightSpire DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/nightspire · Sources: [ransomware.live]
Jul 08
Shanghai Xuerong Biotechnology Co., Ltd.
KRYBIT
KRYBIT DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/krybit · Sources: [SharkStriker] · [ransomware.live]
Jul 08
Shelby Manufacturing de México
KRYBIT
KRYBIT DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/krybit · Sources: [SharkStriker] · [ransomware.live]
Jul 08
Conway Data
Everest
Everest DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/everest · Sources: [SharkStriker] · [ransomware.live]
Jul 08
Greenbotz
Everest
Everest DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/everest · Sources: [SharkStriker] · [ransomware.live]
Jul 07
Next Clinics
Qilin
Qilin DLS claim July 7, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 07
Excalibur Rentals
Akira
Akira DLS claim July 7, 2026; 45 GB claimed including employee PII (SSNs, passports), contracts, and customer data; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/akira-ransomware-strikes-excalibur-rentals/ · https://www.ransomware.live/group/akira · Sources: [DeXpose] · [ransomware.live]
Jul 07
RISE Architecture
Akira
Akira DLS claim July 7, 2026; 57 GB claimed including employee PII, client files, financial records, and project documents; data scope unconfirmed; 🟥 unverified · https://www.galaxywarden.com/blog/breach/rise-architecture-akira-2026-07 · https://www.ransomware.live/group/akira · Sources: [GalaxyWarden] · [ransomware.live]
Jul 07
Chisholm, Persson & Ball, PC
Akira
Akira DLS claim July 7, 2026; 45 GB claimed including client passports, visas, SSNs, court files, and police reports; data scope unconfirmed; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-akira-hits-chisholm-persson-and-ball/ · https://www.ransomware.live/group/akira · Sources: [HookPhish] · [ransomware.live]
Jul 07
Mercado Libre
The Gentlemen
Latin America's largest e-commerce and fintech platform; The Gentlemen DLS claim July 7, 2026; approximately 118,244 users reportedly affected; company has not issued a public statement; data scope and impact unconfirmed; 🟥 unverified — verify before treating as breach · https://www.escudodigital.com/en/cybersecurity/mercado-libre-hit-by-ransomware-attack.html · https://blog.rankiteo.com/mer1783492030-mercado-libre-ransomware-july-2026/ · https://www.ransomware.live/id/TWVyY2FkbyBMaWJyZUB0aGVnZW50bGVtZW4= · Sources: [EscudoDigital] · [Rankiteo] · [ransomware.live]
Jul 07
YMCA of Western North Carolina
Interlock
Interlock DLS claim July 7, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · Sources: [ransomware.live]
Jul 06
Precision Steel Services
Qilin
Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-attack-on-precision-steel-services/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06
Wood Ellis & Wood CPA
Qilin
Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-attack-on-wood-ellis-wood-cpa/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06
Max Fordham
Qilin
independent building engineering consultancy (MEP/sustainability; clients include museums, schools, housing); Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-targets-max-fordham-in-uk-cyberattack/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06
Grupo Inteca
Qilin
Qilin DLS claim July 6, 2026; internal files claimed exfiltrated; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 06
CSEC RATP
The Gentlemen
The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 06
Arabia Falcon Insurance Company
The Gentlemen
The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 06
Ahmet Aydeniz Group
APT73
APT73/Bashe DLS claim July 6, 2026; data scope and impact unconfirmed; APT73 noted for fabricating some high-profile claims — 🟥 unverified pending independent confirmation · https://www.ransomware.live/group/apt73 · Sources: [ransomware.live]
Jul 06
CNW Electronics Pte Ltd
Unattributed
PEAR DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/pear · Sources: [ransomware.live]
Jul 06
AC Beverage
Unattributed
PEAR DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/pear · Sources: [ransomware.live]
Jul 06
Apex Agro LLC
Genesis
Genesis DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/genesis · Sources: [ransomware.live]
Jul 06
Asisken
Wallstreet
Wallstreet DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/wallstreet · Sources: [ransomware.live]
Jul 04
Sisint
Qilin
Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04
Sitmatic GmbH
Qilin
Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04
TQ Financial Services
Qilin
Qilin DLS claim July 3–4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04
Md Lewis
Qilin
Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04
Goodwill Manasota
Qilin
Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04
Chemco
Qilin
Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04
Locati Architects
Play
Play DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/play · Sources: [ransomware.live]
Jul 04
Silvestri & Associates Insurance
Play
Play DLS claim July 4, 2026; data leak threatened; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/play-ransomware-targets-silvestri-associates-insurance/ · Sources: [DeXpose]
Jul 04
US government entity
Kairos
2TB of sensitive records exfiltrated including SSNs, fingerprints, financial data, and passport scans; ~$1M (~9.44 BTC) ransom paid July 4, 2026 to prevent publication; victim identity not publicly disclosed; pure data-extortion model — no encryption, no operational disruption; 🟨 payment confirmed, victim identity unconfirmed · https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html · https://securityaffairs.com/194750/security/u-s-government-agency-paid-1m-to-data-extortion-group-kairos.html · Sources: [The Hacker News] · [Security Affairs]
Jul 04
Baraga County Memorial Hospital
Wallstreet
Baraga County Memorial Hospital in L'Anse, Michigan; Wallstreet DLS claim July 4, 2026; data scope and impact unconfirmed; attack in reduced-staffing US Independence Day holiday window; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04
Edgewood Police Department
Wallstreet
Edgewood Police Department, Pierce County, Washington; Wallstreet DLS claim July 4, 2026; law enforcement targeting during holiday window; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04
Gold Standard Automotive
Wallstreet
Wallstreet DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04
Deutsche Bank
UnSafe
UnSafe DLS claim July 4–6, 2026; Deutsche Bank is Germany's largest bank by assets; UnSafe is a brand-new group with no established track record or prior leak history; data scope, attack vector, and impact entirely unconfirmed; 🟥 EXTREMELY LOW CONFIDENCE — verify through Deutsche Bank communications only before treating as breach · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04
Abbott Laboratories (LabCentral)
ShadowByt3dollar
API exfiltration of LabCentral customer portal from July 4; actor claims CE certificates, manufacturing specs, regulatory documents. Distinct from ShinyHunters Exact Sciences SSO incident (seq 478). Abbott investigating both simultaneously. · Sources: https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/
Jul 03
Prince George County
RansomHouse
county systems encrypted June 10 2026; phone, internet, and online payment systems disrupted; 911 unaffected; PII possibly exposed (names, addresses, DOBs, driver's licence numbers, SSNs); credit monitoring offered; FBI Cyber Crimes Division and CISA notified; RansomHouse claims encryption and posted evidence pack; county has not officially confirmed ransomware attribution or data theft; 🟥 unverified · https://www.wric.com/news/local-news/prince-george/county-government-cybersecurity-incident/ · https://www.govtech.com/security/prince-george-county-va-discloses-recent-cyber-attack · https://ransomware.live/id/UHJpbmNlIEdlb3JnZSBDb3VudHlAcmFuc29taG91c2U= · https://www.redpacketsecurity.com/ransomhouse-ransomware-victim-prince-george-county/ · Sources: [WRIC ABC 8News] · [GovTech] · [ransomware.live] · [RedPacket Security]
Jul 03
Oak Park
INC Ransom
Metro Detroit suburb in Oakland County; INC Ransom DLS claim July 3, 2026; attack estimated July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03
City of Acworth, Georgia
INC Ransom
suburban Atlanta city northwest of the city; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03
Carvalima Transportes
INC Ransom
road transport and logistics company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03
Estrutural Zortéa
INC Ransom
Brazilian construction and infrastructure company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03
CUI Agency
The Gentlemen
US insurance agency based in Utah; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 03
MakoLab S.A.
The Gentlemen
Polish IT and digital transformation consultancy providing software development, cloud, and data analytics services; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 03
Shamrock
The Gentlemen
The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 03
Ferrum AG
Anubis
one of the largest family-owned manufacturing companies in Switzerland; Anubis DLS claim July 3, 2026; Anubis now totals 91 claimed victims (11 in June alone); data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.ransomlook.io/group/anubis · Sources: [ransomware.live] · [RansomLook]
Jul 02
Dixie Beverage West
Qilin
Qilin DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 02
Pennant Hills Golf Club
Qilin
Qilin DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · https://www.hendryadrian.com/ransom-pennant-hills-golf-club-jul-2026/ · Sources: [ransomware.live] · [hendryadrian.com]
Jul 02
A. Bianchini Ingeniero S.A.
LockBit
Spanish industrial engineering company; LockBit DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/lockbit · Sources: [ransomware.live]
Jul 02
AWO Kreisverband Südost e.V.
SafePay
German social welfare organization; SafePay DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jul 02
DIA179
SafePay
German architecture firm; SafePay DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jul 02
COMHAR
WorldLeaks
Irish non-profit providing community mental health, disability, and social services; WorldLeaks DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/worldleaks · Sources: [ransomware.live]
Jul 02
Treet Group of Companies
WorldLeaks
Pakistani conglomerate spanning razor blades (Treet Razors), textiles (Treet Fabrics), and power generation (Liberty Power Tech); WorldLeaks DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ransom-treet-group-of-companies-jul-2026/ · https://www.ransomware.live/group/worldleaks · Sources: [hendryadrian.com] · [ransomware.live]
Jul 02
Service IT
WorldLeaks
Brazilian IT services company; WorldLeaks DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ransom-service-it-jul-2026/ · https://www.ransomware.live/group/worldleaks · Sources: [hendryadrian.com] · [ransomware.live]
Jul 02
Fluke Corporation
ShinyHunters
global manufacturer of electronic test and measurement equipment (subsidiary of Fortive Corporation; >3,000 employees); ShinyHunters DLS claim July 2, 2026 — over 21 million Salesforce records claimed including employee/customer PII; group described failed negotiations with victim before publishing; data scope unconfirmed; no Fluke or Fortive public statement; 🟥 unverified · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-fluke-corporation/ · https://www.ransomware.live/group/shinyhunters · Sources: [RedPacket Security] · [ransomware.live]
Jul 02
Ingram Content Group
ShinyHunters
major US book distribution, print-on-demand, and publishing-services company serving thousands of publishers worldwide; ShinyHunters DLS claim July 2, 2026; group alleged failed negotiations with victim; Salesforce data exfiltration claimed; data scope unconfirmed; no public statement from Ingram; 🟥 unverified · https://breachnews.com/breaches/shinyhunters-adds-ingram-content-group-and-fluke-corporation-to-leak-site/ · https://www.hendryadrian.com/ransom-ingram-content-group-inc-jul-2026/ · Sources: [BreachNews] · [hendryadrian.com]
Jul 02
AAI
Krybit
Krybit DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/krybit · Sources: [ransomware.live]
Jul 02
DISS
Krybit
Krybit DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/krybit · Sources: [ransomware.live]
Jul 02
Colorado Rehabilitation & Occupational Medicine
INC Ransom
Colorado-based rehabilitation and occupational medicine practice; INC Ransom DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 02
Tofutown
Payload
traditional organic food manufacturer (est. 1981; vegan spreads, tofu, seitan products); Payload DLS claim July 2, 2026 (07:26 UTC); data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/payload · https://www.hendryadrian.com/ransom-tofutown-jul-2026/ · Sources: [ransomware.live] · [hendryadrian.com]
Jul 02
Quest Healthcare Solutions
Anubis
employee data and internal files claimed exfiltrated; Anubis DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ransom-quest-healthcare-solutions-jul-2026/ · https://www.ransomware.live/group/anubis · Sources: [hendryadrian.com] · [ransomware.live]
Jul 02
Amtivo
SETTRA
ANAB-accredited ISO and management system certification body (formerly Orion, ASR, CMA, Audit3, QSR, ISA in North America); offers ISO 9001, 14001, 27001, 45001 certification and training; SETTRA DLS claim July 1–2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071991911431426416 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jul 02
X-Copper Professional Corporation
MoneyMessage
Canadian law firm specialising in traffic ticket defence, minor criminal charges, and licence-related legal matters; MoneyMessage DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ · Sources: [hendryadrian.com]
Jul 02
A. Bianchini
LockBit
Spanish galvanized steel wire manufacturer (abianchini.es, founded 1908) listed on LockBit 5.0 DLS approximately July 2 2026. DLS claim unverified. · Sources: https://ransomware.live/id/YWJpYW5jaGluaS5lc0Bsb2NrYml0NQ==
Jul 02
JS Hotels
LockBit
Spanish hospitality group (jshotels.com) operating 10 hotel properties in Majorca; listed on LockBit 5.0 DLS approximately July 2 2026. DLS claim unverified. · Sources: https://www.ransomware.live/id/anNob3RlbHMuY29tQGxvY2tiaXQ1
Jul 01
Dennis Waters Rental Properties
Qilin
residential rental property company; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01
Dynamic Laser Solutions Ltd.
Qilin
UK-based laser cutting and industrial machinery solutions company; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01
Laughlin Nunnally Hood & Crum
Qilin
US law firm; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01
Gies Dienstleistungen
LockBit
German facility management and building services company; LockBit 5.0 DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
Refinery Hotel
Akira
luxury boutique hotel near Bryant Park (197 rooms, Parker & Quinn restaurant, Refinery Rooftop bar); Akira DLS claim July 1, 2026; 15 GB claimed including employee PII (passports, driver's licenses, SSNs, W-9 forms), guest information, financials, contracts and agreements, and NDAs; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.redpacketsecurity.com/akira-ransomware-victim-refinery-hotel/ · https://www.hookphish.com/blog/ransomware-group-akira-hits-refinery-hotel/ · https://ransomware.live/id/UmVmaW5lcnkgSG90ZWxAYWtpcmE= · Sources: [RedPacket Security] · [HookPhish] · [ransomware.live]
Jul 01
Starpool
WorldLeaks
Italian designer and manufacturer of premium wellness cabins, saunas, steam rooms, and hydromassage systems; WorldLeaks DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/worldleaks · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jul 01
B'Laofood Joint Stock Company
KRYBIT
KRYBIT DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/krybit-ransomware-attack-on-blaofood-joint-stock-company/ · https://www.ransomware.live/id/Ymxhb2Zvb2QuY29tQGtyeWJpdA · Sources: [DeXpose] · [ransomware.live]
Jul 01
Azienda Ospedaliera Moscati
Krybit
Italian public hospital; Krybit DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/krybit · Sources: [ransomware.live]
Jul 01
Roundshield Partners LLP
INC Ransom
UK-based private equity firm focused on special situations and credit investments; INC Ransom DLS claim July 1, 2026; 400 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01
Boyne City
The Gentlemen
City of Boyne City, northern Michigan municipality; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
FAC Logistique
The Gentlemen
French logistics company; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
Centre Ophtalmologique d'Ermont
The Gentlemen
French ophthalmology centre; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
CTM India Limited motherson INDIA
The Gentlemen
Motherson Group subsidiary; precision metalworking and automotive component manufacturer; The Gentlemen DLS claim July 1, 2026; estimated attack June 22, 2026; data scope unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-ctm-india-limited-motherson-india/ · https://ransomware.live/id/Q1RNIEluZGlhIExpbWl0ZWQgbW90aGVyc29uIElORElBQHRoZWdlbnRsZW1lbg== · Sources: [RedPacket Security] · [ransomware.live]
Jul 01
Golden State Orthopedic
Brain Cipher
orthopedic healthcare provider; Brain Cipher DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01
Digital Dynamics Inc.
Brain Cipher
US technology company; Brain Cipher DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01
CQCRM
Icarus
Icarus DLS claim July 1, 2026; 🟥 unverified · https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data · Sources: [Dark Reading]
Jul 01
CBAssociates
Icarus
Icarus DLS claim July 1, 2026; 🟥 unverified · https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data · Sources: [Dark Reading]
Jul 01
AeroVision Avionics, Inc.
KRYBIT
KRYBIT DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/krybit-ransomware-strikes-aerovision-avionics-inc/ · https://www.ransomware.live/group/krybit · Sources: [DeXpose] · [ransomware.live]
Jul 01
DISS Corporation / DISS Analytics
KRYBIT
KRYBIT DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://socradar.io/free-tools/ransomware-intelligence/victims/diss-analytics · https://www.ransomware.live/group/krybit · Sources: [SOCRadar] · [ransomware.live]
Jul 01
City Lumber Company
SETTRA
building materials supplier based in Tennessee; SETTRA DLS claim June 30–July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-strikes-city-lumber-company/ · https://x.com/FalconFeedsio/status/2071991911431426416 · Sources: [DeXpose] · [FalconFeeds]
Jul 01
Orion Registrar Inc.
SETTRA
US-based management system certification registrar; SETTRA DLS claim June 30–July 1, 2026; claimed exposure of sensitive financial documents; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-targets-orion-registrar-inc/ · Sources: [DeXpose]
Jul 01
Nidec Chaun Choung Technology Co., Ltd.
Blackfield
Taiwan-based subsidiary of Japan's Nidec Corporation (global precision motor and electronics manufacturer; Tokyo Stock Exchange Prime Market); Blackfield DLS claim confirmed July 1, 2026 (BleepingComputer); attack date June 22, 2026; $2M ransom demand; 2TB exfiltrated claimed; no Nidec public statement; 🟥 unverified · https://www.bleepingcomputer.com/news/security/blackfield-ransomware-targets-nidec-subsidiary-with-2m-ransom-demand/ · https://www.dexpose.io/ · Sources: [BleepingComputer] · [DeXpose]
Jul 01
Dolrad
MedusaLocker
69 emails claimed exfiltrated; MedusaLocker DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/medusalocker-ransomware-victim-dolrad/ · https://ransomware.live/id/RG9scmFkQG1lZHVzYWxvY2tlcg== · Sources: [RedPacket Security] · [ransomware.live]
Jul 01
Penticton and District Society for Community Living
MedusaLocker
nonprofit organisation providing residential, employment, and social services for adults with developmental disabilities in the Penticton (BC) region; MedusaLocker DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/medusalocker-ransomware-victim-penticton-and-district-society-for-community-living/ · https://ransomware.live/id/UGVudGljdG9uIGFuZCBEaXN0cmljdCBTb2NpZXR5IGZvciBDb21tdW5pdHkgTGl2aW5nQG1lZHVzYWxvY2tlcg== · Sources: [RedPacket Security] · [ransomware.live]
Jul 01
ComTRI GmbH
LockBit
German IT services provider listed on LockBit 5.0 DLS approximately July 1 2026. DLS claim unverified by independent source. · Sources: https://www.ransomware.live/
Jul 01
Hotel de la Bourse
LockBit
Hotel in Mulhouse, France (hotel-bourse.com) listed on LockBit 5.0 DLS approximately July 1 2026, discovered July 11 2026. DLS claim unverified. · Sources: https://ransomware.live/id/aG90ZWwtYm91cnNlLmNvbUBsb2NrYml0NQ==
Jul 01
Marquis Software
Unknown
Financial software company serving community banks; ransomware attack compromised data for 670,000+ individuals across dozens of bank customers including Artisans Bank and VeraBank; no ransomware group claimed credit publicly (suggesting possible payment); attack date not precisely specified · Sources: https://therecord.media/marquis-bank-vendor-data-breach
June 2026
Jun 30
KALIACT ANCHETA et Associés
Qilin
French legal advisory firm; Qilin DLS June 30, 2026; data scope unconfirmed; 🟥 unverified · https://socradar.io/free-tools/ransomware-intelligence/victims/kaliact-ancheta-et-associs-67e467e9 · https://www.ransomware.live/id/S0FMSUFDVCBBTkNIRVRBIGV0IEFzc29jaXNAcWlsaW4 · Sources: [SOCRadar] · [ransomware.live]
Jun 30
KUNERT Fashion
Qilin
German legwear and hosiery manufacturer; Qilin DLS June 30, 2026; data scope unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/qilin-ransomware-victim-kunert-fashion/ · https://www.ransomware.live/group/qilin · Sources: [RedPacket Security] · [ransomware.live]
Jun 30
Chamco
Qilin
Canadian manufacturing company; Qilin DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jun 30
Western Construction
Play
Play DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/V2VzdGVybiBDb25zdHJ1Y3Rpb25AcGxheQ== · Sources: [ransomware.live]
Jun 30
Agroprime
DragonForce
developer of specialised SaaS software for automating agribusiness management and monitoring field personnel across Brazil; DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/YWdyb3ByaW1lQGRyYWdvbmZvcmNl · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30
Hwa Seng Water Resources Biotech Co., Ltd.
DragonForce
DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30
Advanced Business Systems
Akira
regional office technology solutions and managed services provider; Akira DLS claim June 30, 2026; 31 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jun 30
Primed Halberstadt Medizintechnik GmbH
Aur0ra
German manufacturer of medical devices (founded 1946; part of PE-backed PP Medtech group); Aur0ra DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/UHJpbWVkIEhhbGJlcnN0YWR0IE1lZGl6aW50ZWNobmlrQGF1cm9yYQ== · Sources: [ransomware.live]
Jun 30
On-us
Gunra
DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/gunra-strikes-on-us-in-new-ransomware-attack/ · Sources: [DeXpose]
Jun 30
Pou Sheng International Holdings
The Gentlemen
China-based athletic footwear retailer and Yue Yuen Group subsidiary; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jun 30
SDEZ
The Gentlemen
historic French family-owned company (est. 1816) specialising in industrial rental and maintenance of professional linen, workwear, and hygiene equipment; national network of industrial laundries across France and Belgium; 700+ employees; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/U0RFWkB0aGVnZW50bGVtZW4= · Sources: [ransomware.live]
Jun 30
Mondottica
The Gentlemen
global luxury eyewear company specialising in design, production, and worldwide distribution of premium sunglasses and optical frames under licensed brand names; international operations across Europe and APAC; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-mondottica/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30
Melcor Developments Ltd
The Gentlemen
diversified real estate developer and asset manager headquartered in Edmonton, Alberta; community development, commercial property, and residential construction across Western Canada; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-melcor-developments-ltd/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30
Indra Group
The Gentlemen
one of Europe's largest defense, aerospace, and technology companies; €5B annual revenue; 62,000 employees; operates in 140+ countries; first Spanish company to join NATO's cyberdefence coalition; provides critical defense systems, air traffic management, space infrastructure, and IT to governments, militaries, and CNI operators worldwide; The Gentlemen DLS claim June 30, 2026; Indra confirmed attack was limited to a non-critical subsidiary environment; CSIRT protocols activated; operations unaffected; data type and volume unknown; data publication deadline July 9, 2026; 🟥 unverified · https://cybernews.com/security/indra-group-ransomware-attack-data-leak/ · https://www.cybersecurity-insiders.com/the-gentleman-ransomware-targets-prominent-european-nato-contractor/ · https://socradar.io/free-tools/ransomware-intelligence/victims/indra-group-9773ee2c · Sources: [Cybernews] · [Cybersecurity Insiders] · [SOCRadar]
Jun 30
PAI Pharma
Brain Cipher
Brain Cipher DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jun 30
Boston Orthotics & Prosthetics
Anubis
leading employee-owned orthotics and prosthetics provider with multiple clinic locations across the northeastern US; ANUBIS DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30
ESMS Global
Anubis
specialised healthcare services company; ANUBIS DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30
Port Angeles Composite LLC
CMD
structural composite manufacturer headquartered in Port Angeles, WA; produces composite structures for Boeing, Bombardier, and Honda Aircraft Company; acquired by Honda Aircraft Company October 2025; CMD DLS claim June 30, 2026 (~09:52 UTC); data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/group/cmdorganization · Sources: [ransomware.live]
Jun 30
Medlink Georgia
CMD
federally qualified health center providing comprehensive care with sliding-fee scale for uninsured and underinsured patients; CMD DLS claim June 30, 2026; sensitive data threatened for release unless negotiations initiated; data scope and impact unconfirmed; 🟥 unverified — no Medlink Georgia public statement · https://www.dexpose.io/cmdorganization-strikes-medlink-georgia-in-latest-ransomware-attack/ · https://ransomware.live/id/TWVkbGluayBHZW9yZ2lhQGNtZG9yZ2FuaXphdGlvbg== · Sources: [DeXpose] · [ransomware.live]
Jun 30
Aflac Life Insurance Japan Ltd.
Scattered Spider
unauthorized access June 15–25, 2026; 4.38M customer records exposed (names, addresses, phone numbers; bank account details for ~230K); access vector undisclosed; actor officially unattributed but TTPs consistent with Scattered Spider per industry analysis; Aflac disclosed June 30, 2026; Japan FSA and police notified; no misuse confirmed at disclosure; 🟥 unverified attribution · https://www.securityweek.com/aflac-japan-data-breach-impacts-4-38-million/ · https://www.bleepingcomputer.com/news/security/insurance-giant-aflac-discloses-data-breach-after-subsidiary-hack/ · https://www.japantimes.co.jp/business/2026/06/30/aflac-hack-4-million/ · Sources: [SecurityWeek] · [BleepingComputer] · [Japan Times]
Jun 30
Abans Group
BlackNevas
diversified global financial services conglomerate; BlackNevas DLS claim June 30, 2026; estimated attack date June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/QWJhbnMgR3JvdXBAYmxhY2tuZXZhcw== · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30
Arkın Group
BlackNevas
diversified hospitality and gaming conglomerate in Northern Cyprus (casino resorts, hotels); BlackNevas DLS claim June 30, 2026; 1.4 TB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/blacknevas · https://www.redpacketsecurity.com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 30
Brooklyn Defender Services
Genesis
New York City public defender organization providing legal representation to low-income individuals; Genesis DLS claim June 30, 2026; estimated attack date June 23, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · https://www.redpacketsecurity.com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 30
Owensboro Grain Company
SETTRA
US agricultural business specialising in grain processing and commodity trading; SETTRA DLS claim June 30, 2026; estimated attack date June 19, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-strikes-owensboro-grain-company/ · https://www.redpacketsecurity.com/settra-ransomware-victim-owensborograin-com/ · https://ransomware.live/id/b3dlbnNib3JvZ3JhaW4uY29tQHNldHRyYQ== · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 30
Tour Edge
SETTRA
US-based golf equipment manufacturer producing irons, woods, hybrids, and wedges across multiple premium lines; SETTRA DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-targets-golf-manufacturer-tour-edge/ · https://www.ransomware.live/group/settra · Sources: [DeXpose] · [ransomware.live]
Jun 30
Ilex Paysages et Urbanisme
SETTRA
distinguished French landscape architecture and urban planning firm; SETTRA DLS claim June 30, 2026; estimated attack date June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-attack-targets-ilex-paysages-et-urbanisme/ · https://www.redpacketsecurity.com/settra-ransomware-victim-ilex-paysages-com/ · https://www.ransomware.live/id/aWxleC1wYXlzYWdlcy5jb21Ac2V0dHJh · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 30
Wilfley
SETTRA
A.R. Wilfley & Sons, manufacturer of centrifugal slurry pumps for mining, chemical, and industrial applications; SETTRA DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/settra · Sources: [ransomware.live]
Jun 30
Petra Diamonds
SETTRA
London-listed diamond mining company operating mines in Tanzania (Williamson) and South Africa (Cullinan, Finsch, Koffiefontein); SETTRA DLS claim June 30, 2026; estimated attack June 24, 2026; claimed "THE DIAMOND ARCHIVE" incl. employee directory; data scope and impact unconfirmed; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-settra-hits-petradiamonds-com/ · https://www.redpacketsecurity.com/settra-ransomware-victim-petradiamonds-com/ · https://x.com/FalconFeedsio/status/2071991911431426416 · Sources: [HookPhish] · [RedPacket Security] · [FalconFeeds]
Jun 30
Joy Construction Corp
SETTRA
US-based construction and affordable housing developer ($1.3B+ in affordable housing projects; projects in multiple US states); SETTRA DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 30
VCNY Home
SETTRA
US-based home textiles company (bedding, bath, and decorative products; distributed through major US retail chains); SETTRA DLS claim June 30, 2026; estimated attack date June 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/id/dmNueWhvbWUuY29tQHNldHRyYQ== · Sources: [FalconFeeds] · [ransomware.live]
Jun 30
Cedrick Frank Associates
SETTRA
SETTRA DLS claim June 30, 2026; sector and data scope unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 30
May Trucking Company
Embargo
family-owned interstate carrier founded 1945, headquartered in Brooks, Oregon; operates dry-van truckload, intermodal, and refrigerated freight services across the continental US; Embargo DLS claim June 30, 2026 (07:59 UTC); 1 TB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/id/d3d3Lm1heXRydWNraW5nLmNvbUBlbWJhcmdv · https://www.redpacketsecurity.com/embargo-ransomware-victim-www-maytrucking-com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 29
Axionlog
Qilin
Qilin DLS claim June 29, 2026; sector and data scope unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 29
NASCO
Qilin
NASCO provides Blue Cross Blue Shield plan administrative data processing for multiple BCBS plans nationwide; Qilin DLS claim June 29, 2026; data scope unconfirmed; 🟥 unverified — verify before treating as a breach · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 29
Bristol Place Corporation
Qilin
family-owned healthcare services organization; Qilin DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/QnJpc3RvbCBQbGFjZUBxaWxpbg== · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 29
Musashino University
Qilin
Qilin DLS claim June 29, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.redpacketsecurity.com/qilin-ransomware-victim-musashino-university/ · Sources: [RedPacket Security]
Jun 29
STNI Co., Ltd.
DragonForce
DragonForce DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/dragonforce-strikes-south-korean-virtual-tech-innovator-stni-co-ltd/ · https://www.ransomware.live/group/dragonforce · Sources: [DeXpose] · [ransomware.live]
Jun 29
Bonacio Construction
RansomHouse
full-service construction and real estate development company specialising in commercial and residential projects in upstate New York (Bonacio Steel fabrication division); RansomHouse DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/Qm9uYWNpb0ByYW5zb21ob3VzZQ== · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 29
Nissan North America
ShinyHunters
53,000+ current and former employees across four countries; data includes SSNs (US), Social Insurance Numbers (Canada), payroll records, banking/direct-deposit details, W-2/tax data, and dependent/beneficiary info; Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) attack window May 27–June 9, 2026; Nissan activated IR and engaged external cybersecurity specialists; notified law enforcement; multi-country regulatory exposure under US state notification laws, Canada PIPEDA, Mexico LFPDPPP, and Brazil LGPD · https://www.theregister.com/security/2026/06/29/nissan-says-oracle-peoplesoft-break-in-may-have-spilled-payroll-records-ssns/5263534 · https://www.scworld.com/brief/nissan-confirms-employee-data-exposed-in-oracle-peoplesoft-cyberattack · https://www.infosecurity-magazine.com/news/employees-social-security-nissan/ · Sources: [The Register] · [SC Media] · [Infosecurity Magazine]
Jun 29
GDN AR
INC Ransom
Argentine grocery store operator headquartered in Ciudad Autónoma de Buenos Aires; INC Ransom DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/R0ROIEFSKERvcmlua2EpQGluY3JhbnNvbQ · Sources: [ransomware.live]
Jun 29
Clínica La Sabana
Payload
Colombian medical clinic; Payload DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.breachsense.com/breaches/2026/june/ · https://www.ransomware.live/group/payload · Sources: [Breachsense] · [ransomware.live]
Jun 29
Canopy Brands
SETTRA
SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/Y2Fub3B5YnJhbmRzLnVzQHNldHRyYQ== · https://x.com/FalconFeedsio/status/2070588706558550063 · Sources: [ransomware.live] · [FalconFeeds]
Jun 29
Total Monitoring Services Inc.
SETTRA
SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 29
Doosan
SETTRA
Doosan Group (heavy industry, power, construction equipment, hydrogen); SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 29
HMC Farms
SETTRA
SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 29
DyStar Group
SETTRA
leading global manufacturer of specialty chemicals, reactive dyes, and textile process chemicals serving the apparel, home textiles, and technical textiles industries; SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 29
Quality Dining Inc.
SETTRA
one of the largest US Burger King and Chili's franchise operators (Indiana-based); SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/settra · Sources: [ransomware.live]
Jun 29
Virginia Glass Products
SETTRA
SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/dmEtZ2xhc3MuY29tQHNldHRyYQ== · Sources: [ransomware.live]
Jun 28
1-800-Dentist
Qilin
US national dental referral and appointment-scheduling service (connects patients with 25,000+ dentist offices nationwide); Qilin DLS claim June 28, 2026; estimated attack date June 28; data scope and impact unconfirmed; 🟥 unverified — verify before treating as a breach · https://www.redpacketsecurity.com/qilin-ransomware-victim-1-800-dentist/ · https://www.ransomware.live/id/MS04MDAtZGVudGlzdEBxaWxpbg== · Sources: [RedPacket Security] · [ransomware.live]
Jun 28
TransCore
Qilin
nationwide electronic toll collection and intelligent transportation systems provider (~$420M revenue, 2,068 employees; ST Engineering subsidiary; serves 8 of 10 largest US tolling agencies and provides traffic management systems worldwide); Qilin DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 28
Higuchi Inc.
Stormous
Japanese industrial manufacturer; full financial statements including balance sheets and asset records exfiltrated; Stormous DLS claim June 28, 2026; data scope confirmed via ransomware.live indexed entry · https://www.hookphish.com/blog/ransomware-group-stormous-hits-higuchi-inc-co-jp/ · https://socradar.io/free-tools/ransomware-intelligence/victims/higuchi-inc-co-jp-fb4252a8 · Sources: [HookPhish] · [SOCRadar]
Jun 28
HIGUCHI USA, INC.
Stormous
US subsidiary of Higuchi Inc. with offices in Dallas, Hong Kong, and Los Angeles; corporate financial and operational data exfiltrated; Stormous DLS claim June 28, 2026; 🟥 unverified — no independent victim statement · https://ransomware.live/id/SElHVUNISSBVU0EsIElOQ0BzdG9ybW91cw== · Sources: [ransomware.live]
Jun 28
EOGB Energy Products Ltd
Stormous
leading UK manufacturer and distributor of oil, gas, and dual-fuel burners (14kW to 45MW), based in St Neots, Cambridgeshire; attackers gained deep access to Microsoft Dynamics GP containing complete corporate accounting, invoices, vendor details, and internal legal and partnership documents; Stormous DLS claim June 28, 2026; 🟥 unverified — no EOGB statement · https://ransomware.live/id/ZW9nYi5jby51a0BzdG9ybW91cw== · Sources: [ransomware.live]
Jun 28
ESHA Research/ESHA Cloud Services
Stormous
food and beverage nutrition database and regulatory compliance software company (Salem, Oregon); core product development databases allegedly accessed; Stormous DLS claim June 28, 2026; 🟥 unverified — no vendor statement · https://www.hookphish.com/blog/ransomware-group-stormous-hits-eshacloudqa-com/ · https://socradar.io/free-tools/ransomware-intelligence/victims/eshacloudqa-com-352c7808 · Sources: [HookPhish] · [SOCRadar]
Jun 28
Monoprix.tn
Stormous
Tunisian supermarket and retail chain (monoprix.tn); Stormous DLS claim June 28, 2026; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/id/bW9ub3ByaXgudG5Ac3Rvcm1vdXM · Sources: [ransomware.live]
Jun 28
Thyssenkrupp Marine Systems (TKMS) GmbH / Atlas Elektronik
The Gentlemen
TKMS is Germany's principal naval shipbuilding group; Atlas Elektronik is its naval electronics subsidiary (HQ Bremen), specialising in submarine sonar systems, acoustic measurement, and heavyweight torpedo guidance for the German Navy and allied export customers; The Gentlemen DLS claim June 28, 2026; estimated attack date June 25, 2026; data scope unconfirmed; 🟥 unverified — no TKMS or Atlas Elektronik public statement · https://www.ransomware.live/id/VGh5c3NlbmtydXBwIE1hcmluZSBTeXN0ZW1zIChUS01TKSBHbWJIIC8gQXRsYXMgRWxla3Ryb25pa0B0aGVnZW50bGVtZW4= · https://www.ransomware.live/summary/ · Sources: [ransomware.live] · [ransomware.live summary]
Jun 28
Ford Motor Company Mexico
KRYBIT
Mexican subsidiary of Ford Motor Company; KRYBIT DLS claim June 28, 2026; estimated attack June 28, 2026; data scope and impact unconfirmed; 🟥 unverified — no Ford Mexico public statement · https://www.ransomware.live/id/Zm9yZC5teEBrcnliaXQ · https://socradar.io/free-tools/ransomware-intelligence/victims/ford-mx-906485b3 · Sources: [ransomware.live] · [SOCRadar]
Jun 28
FCCI Insurance Group
REDACT
specialty commercial insurance company; REDACT DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/redact · https://www.redpacketsecurity.com/redact-ransomware-victim-fcci-insurance-group/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 28
Hologic, Inc.
REDACT
global medical technology company (~$4B revenue; breast health, diagnostics, GYN surgical products); REDACT DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/redact-ransomware-victim-hologic/ · Sources: [RedPacket Security]
Jun 28
Turbo Data Systems
SETTRA
data aggregation and consumer intelligence company; SETTRA DLS claim June 28, 2026; estimated attack June 17, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/settra · https://www.redpacketsecurity.com/settra-ransomware-victim-turbodata-com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 28
Conduril Engenharia S.A.
SETTRA
major Portuguese civil infrastructure contractor; SETTRA DLS claim June 28, 2026; estimated attack June 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/Y29uZHVyaWwucHRAc2V0dHJh · https://socradar.io/free-tools/ransomware-intelligence/victims/conduril-pt-b8d0b1d8 · Sources: [ransomware.live] · [SOCRadar]
Jun 28
LifeVantage Corporation
SETTRA
publicly traded direct-sales nutritional supplement company (NASDAQ: LFVN); SETTRA DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-hits-lifevantage-corporation/ · https://ransomware.live/id/bGlmZXZhbnRhZ2UuY29tQHNldHRyYQ== · Sources: [DeXpose] · [ransomware.live]
Jun 28
PChome Online Inc.
SETTRA
one of Taiwan's largest online retail and e-commerce platforms; breach estimated June 10, 2026 via infostealer malware compromising employee and customer accounts; 35,000+ users and employees' credentials and personal data exposed; SETTRA DLS claim June 28, 2026; 🟥 unverified — no PChome public statement · https://www.dexpose.io/settra-ransomware-attack-on-pchome-online-inc/ · https://www.galaxywarden.com/blog/breach/pchome-settra-ransomware-june-2026 · https://socradar.io/free-tools/ransomware-intelligence/victims/pchome-com-tw-bcdbab3d · Sources: [DeXpose] · [GalaxyWarden] · [SOCRadar]
Jun 28
KDDI Corporation
Unattributed
Japan's second-largest mobile carrier; 14.22 million email subscriber accounts compromised across six ISPs managed by KDDI (Chuokai, Johoku Communications, KCN Kyoto, Okayama Information Highway, Sanin Godo Bank Net, Tokai Broadband); root cause: vulnerability in third-party email management software; email subscriber account records (addresses, associated metadata) affected; KDDI confirmed breach and began customer notifications June 24-28, 2026; actor unattributed · https://therecord.media/ · https://www.securityweek.com/ · Sources: [The Record] · [SecurityWeek]
Jun 27
Kuhnline
Play
Play DLS claim June 27, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/S3VobmxpbmVAcGxheQ== · https://www.facebook.com/CyberNewsLive/photos/play-claims-to-have-targeted-kuhnline-kuhnlinecom-a-construction-company-this-re/1349093380535328/ · Sources: [ransomware.live] · [Cyber News Live]
Jun 27
hellmold-plank.de
SafePay
long-established German manufacturer (roots to 1904); SafePay DLS claim June 27, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jun 27
Aptora
DragonForce
field service management platform used by contractors and service businesses; DragonForce DLS claim June 27, 2026; attackers allege databases of 100+ Aptora client companies exfiltrated; data scope unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · Sources: [ransomware.live]
Jun 26
Tokyo Civil Co., Ltd.
SafePay
public infrastructure specialist (river works, bridges, foundation engineering, water supply systems, government-related construction; established 2020; Edogawa City, Tokyo); SafePay DLS claim June 26, 2026; internal org data, employee info, and operational files claimed; 🟥 unverified — no Tokyo Civil statement · https://www.cyfirma.com/news/weekly-intelligence-report-26-jun-2026/ · https://www.ransomware.live/group/safepay · Sources: [CYFIRMA] · [ransomware.live]
Jun 26
Precise Forms, Inc.
Akira
aluminum forming products manufacturer; Akira DLS claim June 26, 2026; ~10 GB claimed; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/akira-ransomware-strikes-precise-forms-inc/ · https://www.ransomware.live/group/akira · Sources: [DeXpose] · [ransomware.live]
Jun 26
NSW Rural Fire Service
Nova
New South Wales Rural Fire Service; Nova DLS claim June 26, 2026; 300 GB claimed; RFS confirmed the breach June 24 but stated emergency operations were unaffected; no evidence of operational impact · https://www.cyberdaily.au/security/13817-exclusive-nova-ransomware-group-takes-responsibility-for-nsw-rfs-hack · https://www.ransomware.live/group/nova · Sources: [Cyber Daily] · [ransomware.live]
Jun 26
VSL Marine Technology Pvt. Ltd.
Nova
marine technology and underwater survey services provider; Nova DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/nova-ransomware-attack-targets-vsl-marine-technology-pvt-ltd/ · https://www.ransomware.live/group/nova · Sources: [DeXpose] · [ransomware.live]
Jun 26
callhorton.com
INC Ransom
personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26
johndufourlaw.com
INC Ransom
personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26
Life Bridges
INC Ransom
non-profit organisation supporting individuals with intellectual and developmental disabilities; INC Ransom DLS claim June 25-26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/incransom-targets-life-bridges-non-profit-in-ransomware-attack/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 26
Salters Propane
SpaceBears
propane fuel distributor; SpaceBears DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/ · https://www.hendryadrian.com/ · Sources: [RedPacket Security] · [hendryadrian.com]
Jun 26
Ingerman
Chaos
multifamily developer and property management company; Chaos DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/chaos-strikes-ingerman-in-ransomware-attack/ · https://www.redpacketsecurity.com/chaos-ransomware-victim-ingerman-com/ · Sources: [DeXpose] · [RedPacket Security]
Jun 26
911 Driving School
PrinzEugen
national driving school chain; PrinzEugen DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 26
Mosaic Partners
Payload
Swiss IT services provider specialising in software development, systems engineering, CRM, cloud computing, and process management solutions; Payload DLS claim June 26, 2026; sensitive data publication threatened unless negotiations begin; 🟥 unverified — no victim statement · https://www.dexpose.io/payload-ransomware-attack-on-mosaic-partners/ · https://www.redpacketsecurity.com/payload-ransomware-victim-mosaic-partners/ · https://www.ransomware.live/id/TW9zYWljIFBhcnRuZXJzQHBheWxvYWQ= · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 26
Software Arge
Payload
Turkish enterprise data analytics and cloud platform company (founded 2016; cloud analytics, data visualisation, integration and management solutions for enterprise clients); Payload DLS claim June 26, 2026; sensitive data publication threatened unless negotiations initiated; 🟥 unverified — no victim statement · https://www.dexpose.io/payload-ransomware-strikes-software-arge/ · https://www.redpacketsecurity.com/payload-ransomware-victim-software-arge/ · Sources: [DeXpose] · [RedPacket Security]
Jun 26
Payload Corporation
Payload
B2B automated payment processing platform serving real estate, legal, insurance, and SaaS sectors (founded 2019; co-founders Ian Halpern and Ryan Rybolt); Payload DLS claim June 26, 2026; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.dexpose.io/payload-ransomware-breach-at-payload-corporation/ · https://www.ransomware.live/group/payload · Sources: [DeXpose] · [ransomware.live]
Jun 26
Nachlass Nord
Anubis
Anubis/Booba joint DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 26
Clearview Eye Centre
Interlock
ophthalmic clinic and eye care centre; Interlock DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · https://www.dexpose.io/interlock-ransomware-attack-on-clearview-eye-centre/ · Sources: [ransomware.live] · [DeXpose]
Jun 26
MagMutual Insurance Company
LeakNet
mutual insurance company focused on healthcare professionals; LeakNet DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 26
Policía de Turismo
KRYBIT
Dominican Republic tourist police force; KRYBIT DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 26
Hokua Suites
AiLock
upscale resort-style ocean-view residential condominium on the Oahu coast; AiLock DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ailock-ransomware-group-attacks-hokua-luxury-condominiums/ · https://www.redpacketsecurity.com/ailock-ransomware-victim-hokua/ · https://www.ransomware.live/id/SG9rdWFAQWlMb2Nr · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 25
ISOPLUS
Qilin
Greek pharmaceutical company; Qilin DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.dexpose.io/qilin-ransomware-targets-greek-pharma-leader-isoplus/ · https://www.hendryadrian.com/ransom-isoplus-jun-2026/ · Sources: [DeXpose] · [hendryadrian.com]
Jun 25
JMS Southeast
Akira
temperature measurement and control products distributor (thermocouples, RTDs, thermowells, transmitters); Akira DLS claim June 25, 2026; ~25 GB claimed including employee PII (names/addresses), payment data, NDAs, project contracts, agreements with government entities, and customer information · https://www.redpacketsecurity.com/akira-ransomware-victim-jms-southeast/ · https://malware.news/t/akira-ransomware-attack-targets-jms-southeast/108233 · Sources: [RedPacket Security] · [malware.news]
Jun 25
Padget Technologies
Akira
robotics and automation company specialising in engineered machinery, assembly solutions, and robotic palletizing cells; Akira DLS claim June 25, 2026; data upload pending, includes employee records (government IDs, tax forms), payment details, and NDAs · https://www.redpacketsecurity.com/akira-ransomware-victim-padget-technologies/ · https://malware.news/t/akira-ransomware-targets-padget-technologies/108234 · Sources: [RedPacket Security] · [malware.news]
Jun 25
San Silvestre School
Krybit
148.75 GB claimed; 🟥 unverified — possible re-listing of prior Qilin-targeted school; treat as claimed only pending victim statement · https://x.com/FalconFeedsio/status/2070123961552371874 · Sources: [FalconFeeds]
Jun 25
impulso-store.com
Stormous
Italian online retail platform; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25
Au Vieux Campeur
The Gentlemen
French outdoor gear chain (24 stores, 180,000+ members); company confirmed cyberattack June 2, 2026 and mobilised incident response; DLS claim appeared June 25 after 23-day negotiation window closed without ransom payment; data scope unconfirmed · https://frenchbreaches.com/alertes/au-vieux-campeur-mq5ponk61juevh4e5fj · https://www.cyberattaque.org/au-vieux-campeur-victime-dune-cyberattaque-une-enquete-est-en-cours/ · https://www.ransomware.live/ · Sources: [FrenchBreaches] · [Cyberattaque.org] · [ransomware.live]
Jun 25
Al-Dhow
The Gentlemen
Kuwaiti multi-sector business conglomerate; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25
Gegenbauer Elektrotechnik & IT
The Gentlemen
Austrian electrical engineering and IT services company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25
BDS CZ
The Gentlemen
Czech real estate agency; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25
Bell Hardware
The Gentlemen
family-owned commercial hardware company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25
Beran Concrete, Inc.
The Gentlemen
concrete construction and materials company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25
I-SYS
AuditTeam
Russian IT and systems integration company; AuditTeam DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25
Delegal Poindexter & Underkofler, P.A.
Morpheus
employment law firm; Morpheus DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-morpheus-hits-delegal-poindexter-and-underkofler-p-a/ · https://www.dexpose.io/morpheus-ransomware-targets-delegal-poindexter-underkofler-p-a/ · Sources: [HookPhish] · [DeXpose]
Jun 25
Frosty Acres Brands
Booba
US-based national foodservice cooperative and purchasing organisation (member-owned, c.5,000+ restaurants and foodservice operators); Booba DLS claim June 25, 2026; data scope unconfirmed; group warned full data leak unless negotiations initiated; no victim statement · https://www.dexpose.io/booba-ransomware-strikes-frosty-acres-brands/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 24
Cash Canada
Qilin
DLS claim June 24, 2026; data scope and impact unconfirmed · https://www.redpacketsecurity.com/qilin-ransomware-victim-cash-canada/ · https://www.ransomware.live/group/qilin · Sources: [RedPacket Security] · [ransomware.live]
Jun 24
Miami Machine Inc.
Akira
DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 24
JIT-EX LLC
Akira
regional and local truckload carrier (dedicated fleets, crossdock, transloading, storage trailer services); ~40GB claimed; includes employee SSNs, W-9 forms, driver's license documents, passport copies, and credit card details · https://www.redpacketsecurity.com/akira-ransomware-victim-jit-ex/ · https://www.ransomware.live/group/akira · Sources: [RedPacket Security] · [ransomware.live]
Jun 24
Adapt
ShinyHunters
ShinyHunters DLS claim June 24, 2026; final warning issued with data-leak deadline June 25, 2026 midnight NY time; data volume and type unconfirmed; no victim statement; 🟥 unverified · https://www.dexpose.io/shinyhunters-launches-ransomware-attack-on-adapt/ · Sources: [DeXpose]
Jun 24
Alexandria
Nova
teleinfrastructure platform; DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/ · Sources: [ransomware.live]
Jun 24
LP Group
Nova
completed ~1 million sq metres of projects; DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/ · Sources: [ransomware.live]
Jun 24
Transvill SRL
Nova
national and international road transport and cargo logistics; DLS claim June 24, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.redpacketsecurity.com/nova-ransomware-victim-transvill-com-pe/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 24
montechiaro-store.com
Stormous
DLS claim June 24, 2026; "complete customer and buyer data" claimed; scope unconfirmed · https://www.redpacketsecurity.com/stormous-ransomware-victim-montechiaro-store-com/ · Sources: [RedPacket Security]
Jun 24
mlit.com.my
Stormous
DLS claim June 24, 2026; full 10GB data dump claimed including "highly sensitive internal information and financial records"; scope unconfirmed · https://www.redpacketsecurity.com/stormous-ransomware-victim-mlit-com-my-update-full-data-dump-new-link-10gb/ · Sources: [RedPacket Security]
Jun 24
lorenzoni-store.com
Stormous
Lorenzoni brand of Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969; Italian family-run knitwear manufacturer with three brands: Lorenzoni, Montechiaro, Impulso); DLS claim June 24, 2026; "complete data" belonging to customers and buyers claimed; part of the same parent-company incident as montechiaro-store.com (June 24) and impulso-store.com (June 25) · https://www.redpacketsecurity.com/stormous-ransomware-victim-lorenzoni-store-com/ · https://x.com/FalconFeedsio/status/2069899152281207018 · Sources: [RedPacket Security] · [FalconFeeds]
Jun 24
maglificioliliana.com
Stormous
parent company Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969, Montichiari; specialises in high-quality knitwear, operates three brands: Lorenzoni, Montechiaro, Impulso); 400+ GB of sensitive data claimed exfiltrated, including product designs, orders, and customer and operational records; DLS claim June 24, 2026; scope of all four brand/domain listings suggests a full-group compromise · https://www.hookphish.com/blog/ransomware-group-stormous-hits-maglificioliliana-com/ · https://x.com/FalconFeedsio/status/2069899152281207018 · Sources: [HookPhish] · [FalconFeeds]
Jun 24
Stadttheater Giessen
The Gentlemen
municipal theatre serving the city of Giessen in the Mittelhessen region; publicly funded civic cultural venue; The Gentlemen DLS claim June 24, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-stadttheater-giessen/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 24
Quest Health Solutions
Anubis
239 GB of sensitive operational data claimed exfiltrated including employee data, internal files, and additional undisclosed materials; Anubis announced attack June 24, 2026, and threatened to publish data within 2-3 days; Go-based malware with dual-threat encryption and wipe model; Quest Health Solutions has not issued a public statement · https://www.dexpose.io/anubis-ransomware-group-targets-quest-health-solutions/ · https://www.hookphish.com/blog/ransomware-group-anubis-hits-quest-health-solutions/ · https://www.ransomware.live/id/UXVlc3QgSGVhbHRoIFNvbHV0aW9uc0BhbnViaXM · Sources: [DeXpose] · [HookPhish] · [ransomware.live]
Jun 24
Sapporo Holdings
Unattributed
Sapporo Holdings Ltd. disclosed June 24, 2026 that two overseas subsidiaries sustained suspected unauthorized access: Pokka Corporation Singapore (regional food and beverage company) and Sleeman Breweries (Canadian craft brewer); suspicious network activity detected, affected systems shut down pending investigation; no confirmed data exfiltration as of initial disclosure; no confirmed domestic (Japan) impact; actor unattributed; part of broader wave of cyberattacks against Japanese multinationals in June 2026 (alongside Aflac Japan, KDDI, Nidec) · https://therecord.media/japan-cyber-breaches-aflac-sapporo-nidec-kddi · https://www.ppln.co/en/post/japan-cyber-incidents-june-2026-eng · Sources: [The Record] · [Pipeline.co]
Jun 23
Lee International
Qilin
DLS claim June 23, 2026; data scope and impact unconfirmed; no Qilin proof sample or ransom demand publicly published · https://www.redpacketsecurity.com/qilin-ransomware-victim-lee-international/ · https://www.ransomware.live/group/qilin · Sources: [RedPacket Security] · [ransomware.live]
Jun 23
IH Engineers, P.C.
Akira
https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 23
Nike, Inc.
WorldLeaks
1.4TB claimed; 188,347 files alleged to include R&D technical packs, bill-of-materials (BoMs), product prototypes, manufacturing schematics, and internal documents; WorldLeaks DLS claim June 23, 2026; full data dump published live; Nike confirmed it is investigating the incident and has engaged external cybersecurity experts; scope and authenticity not independently verified; 🟨 breach under investigation · https://www.infosecurity-magazine.com/news/worldleaks-ransomware-14tb-nike/ · https://www.darkreading.com/cyberattacks-data-breaches/worldeaks-extortion-group-stole-1-4tb-nike-data · https://www.computing.co.uk/news/2026/security/nike-confirms-investigation-of-1-4tb-nike-data · Sources: [Infosecurity Magazine] · [Dark Reading] · [Computing]
Jun 23
FTL-Fast Transit Line
Nova
Belgian logistics company; DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.dexpose.io/nova-ransomware-targets-ftl-fast-transit-line/ · https://www.ransomware.live/group/nova · Sources: [DeXpose] · [ransomware.live]
Jun 23
Aerospace & Advanced Composites GmbH
Aur0ra
https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23
Belpointe Asset Management
INC Ransom
https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23
Horizon Eye Care
INC Ransom
comprehensive eye exam and corrective-vision services provider (LASIK, cataract, contact lens, designer eyewear); DLS claim June 23; data scope and impact unconfirmed; no Horizon Eye Care statement · https://www.redpacketsecurity.com/incransom-ransomware-victim-horizoneye-com/ · https://www.ransomware.live/group/incransom · Sources: [RedPacket Security] · [ransomware.live]
Jun 23
Randa Apparel & Accessories
Chaos
global apparel and accessories manufacturer (Dockers, Tommy Hilfiger, PGA TOUR licensed brands); DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.dexpose.io/chaos-ransomware-strikes-randa-apparel-accessories/ · https://www.ransomware.live/group/chaos · Sources: [DeXpose] · [ransomware.live]
Jun 23
(Jun 22-23 DLS batch: 15 new victims claimed past 24h incl. healthcare×3, hospitality, manufacturing, transportation
The Gentlemen
https://purple-ops.io/blog/gentlemen-ransomware-victims · Sources: [PurpleOps]
Jun 23
Canada Wide Media
The Gentlemen
https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23
GIA Partners LLC
The Gentlemen
https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23
OneTrust
Icarus
Salesforce CRM data · https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ · Sources: [SecurityWeek]
Jun 23
Global Message Services
Icarus
Salesforce-related data exfiltrated and compressed; new Icarus DLS posting June 23 (distinct from Klue supply-chain victims) · https://www.redpacketsecurity.com/icarus-ransomware-victim-gms-net/ · https://www.ransomware.live/group/Icarus · Sources: [RedPacket Security] · [ransomware.live]
Jun 23
LastPass
Icarus
customer names, phone numbers, email addresses, physical addresses, and Salesforce support-case data accessed via Klue OAuth integration; vaults and core product infrastructure unaffected; LastPass disabled Klue access, rotated OAuth tokens, notified law enforcement; 12th confirmed downstream Klue supply-chain victim · https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/ · https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/ · https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response · Sources: [BleepingComputer] · [TechCrunch] · [LastPass Blog]
Jun 23
Reynella East College
Interlock
all IT systems offline; 1,900+ students and staff at risk; school disclosed breach June 9 in letter to parents; Interlock DLS claim posted June 23; investigation ongoing, data exposure unconfirmed · https://www.cyberdaily.au/security/13731-parents-warned-after-cyber-security-breach-at-south-australia-s-reynella-east-college · https://www.ransomware.live/ · Sources: [Cyber Daily] · [ransomware.live]
Jun 23
Gov.br
APT73
official state digital platform and domain zone of the Brazilian Federal Government claimed on DLS; impact scope unconfirmed; APT73 previously targeted siapenet.gov.br (April 2026) · https://www.blackfog.com/cybersecurity-101/apt73-ransomware-group/ · https://www.ransomware.live/group/apt73 · https://www.redpacketsecurity.com/apt73-ransomware-victim-www-siapenet-gov-br/ · Sources: [BlackFog] · [ransomware.live] · [RedPacket Security]
Jun 23
KliknKlik.com
APT73
online retailer and distributor of computer hardware; APT73 DLS claim June 23; data exposure scope unconfirmed; APT73 (aka Bashe) noted for fabricating some high-profile claims — treat as 🟥 unverified pending confirmation · https://www.ransomware.live/group/apt73 · https://www.dexpose.io/apt73-bashe-ransomware-attack-on-medika-plaza/ · https://www.cloudsek.com/blog/unmasking-media-hungry-ransomware-groups-bashe-apt73 · Sources: [ransomware.live] · [DeXpose] · [CloudSEK]
Jun 23
Flughafen Wien AG
APT73
Austria's largest airport; APT73/Bashe DLS claim June 23, 2026; group alleges 500,000+ emails and 4,473 files exfiltrated including cargo manifests and weapons-transport records; airport confirmed targeted attack but stated incident was limited and did not affect flight operations; published documents described as outdated fragments posing no operational risk; no widespread encryption occurred — 🟥 unverified: airport disputes scope · https://www.dexpose.io/apt73-bashe-targets-vienna-airport-in-ransomware-attack/ · https://aviation.direct/erpressergruppe-bashe-mutmasslicher-cyberangriffs-auf-die-flughafen-wien-ag/ · Sources: [DeXpose] · [Aviation.Direct]
Jun 23
Coldstat Refrigeration
CMD
refrigeration installation and maintenance for commercial clients (restaurants, retail chains, cafes); DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.ransomware.live/id/Q29sZHN0YXQgUmVmcmlnZXJhdGlvbkBjbWRvcmdhbml6YXRpb24= · Sources: [ransomware.live]
Jun 23
AYA Bank
Lapsus$
claimed full dump of main banking platform + customer PII; Lapsus$ stated data will be sold on dark markets if ransom not paid; AYA Bank has not issued a public statement; 🟥 unverified — treat as claimed only · https://www.ransomware.live/id/QVlBIEJBTktAbGFwc3VzJA · https://www.redpacketsecurity.com/lapsus-ransomware-victim-aya-bank/ · https://www.hookphish.com/blog/ransomware-group-lapsus-hits-aya-bank/ · Sources: [ransomware.live] · [RedPacket Security] · [HookPhish]
Jun 22
Central Bank of Libya
Qilin
ransomware confirmed; SWIFT payment system components targeted; virtual infrastructure and internal systems hit; CBL isolated affected systems June 22; investigations ongoing; no confirmed customer data breach or correspondent bank data exposure · https://www.ransomware.live/id/Q2VudHJhbCBCYW5rIG9mIExpYnlhQHFpbGlu · https://libyaobserver.ly/news/cbl-cyberattack-contained-investigations-ongoing-no-signs-impact-customer-accounts · Sources: [ransomware.live] · [Libya Observer]
Jun 22
NationsBuilders Insurance Services
Aur0ra
US-based specialty insurance risk management firm offering surplus and specialty lines coverage; Aur0ra DLS claim June 22, 2026; over 2.7 million file-tree entries compromised claimed; data scope and victim statement not confirmed · https://www.dexpose.io/aurora-ransomware-attack-on-nationsbuilders-insurance-services/ · Sources: [DeXpose]
Jun 22
NTP B.V. Civil Engineering Construction
Aur0ra
Dutch civil engineering contractor (road building, cable laying, sewers, ground works; HQ Hattem, Gelderland; ~150-200 employees; offices in Hattem, Enschede, Zevenaar); Aur0ra DLS claim June 22, 2026; file server contents claimed including 10+ years of operations, HR/payroll exports, employee personal files, network device configurations, project bids, and financial records; data scope and victim confirmation pending · https://www.dexpose.io/aurora-ransomware-targets-ntp-b-v-civil-engineering/ · https://www.ransomware.live/id/TlRQIEIuVi4gQ2l2aWwgRW5naW5lZXJpbmcgQ29uc3RydWN0aW9uQGF1cm9yYQ · https://www.redpacketsecurity.com/aurora-ransomware-victim-ntp-b-v-civil-engineering-construction/ · Sources: [DeXpose] · [ransomware.live] · [RedPacket Security]
Jun 22
Hooke Laboratories
The Gentlemen
preclinical contract research supplier specialising in autoimmune disease model kits (Hooke Kits) used by academic and pharma research laboratories; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-hooke-laboratories/ · https://www.ransomware.live/id/SG9va2UgTGFib3JhdG9yaWVzQHRoZWdlbnRsZW1lbg== · https://www.breachsense.com/breaches/hooke-laboratories-data-breach/ · Sources: [RedPacket Security] · [ransomware.live] · [Breachsense]
Jun 22
Royal Thai Navy Housing Cooperative
The Gentlemen
cooperative managing housing projects, financial services, and welfare programs for Royal Thai Navy personnel and their families; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-royal-thai-navy-housing-cooperative/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 22
Klue
Icarus
OAuth integration credential compromised June 11-12; malicious code pushed to harvest customer OAuth tokens; Salesforce integrations revoked June 12; CrowdStrike engaged for IR · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [SecurityWeek] · [BleepingComputer]
Jun 22
Huntress
Icarus
Salesforce CRM data exfiltrated (business contacts, pricing, sales comms, opportunity notes); no threat data/passwords/engineering data affected · https://www.huntress.com/blog/klue-breach-investigation · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · Sources: [Huntress] · [SecurityWeek]
Jun 22
Recorded Future
Icarus
client contact names, email addresses, potential contract info · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · Sources: [SecurityWeek]
Jun 22
Tanium
Icarus
Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22
Jamf
Icarus
Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22
HackerOne
Icarus
Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22
Snyk
Icarus
Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22
Kudelski Security
Icarus
Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22
Insurity
Icarus
Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22
Gong
Icarus
Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22
Sprout Social
Icarus
Salesforce CRM data accessed through Klue OAuth integration · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ · Sources: [BleepingComputer]
Jun 22
HDS Corp
Icarus
HD Supply Holdings; Icarus DLS claim June 22, 2026; exfiltrated compressed Salesforce data claimed via Klue supply chain OAuth token compromise; 🟥 unverified — no HD Supply public confirmation · https://www.dexpose.io/icarus-ransomware-attack-on-hds-corp/ · https://www.ransomware.live/group/icarus · Sources: [DeXpose] · [ransomware.live]
Jun 22
KTR Real Estate Advisors
Anubis
client database claimed; attack est. 2026-06-19 · https://www.dexpose.io/anubis-ransomware-group-strikes-ktr-real-estate-advisors/ · https://www.redpacketsecurity.com/anubis-ransomware-victim-ktr-real-estate-advisors/ · Sources: [DeXpose] · [RedPacket Security]
Jun 22
Xsolis, Inc.
Unattributed
1,396,519 individuals; names, DOB, addresses, SSNs, health insurance info, medical treatment data; phishing attack January 20, 2026, detected January 22; actor unattributed · https://www.securityweek.com/xsolis-data-breach-affects-1-4-million-individuals/ · https://www.hipaajournal.com/xsolis-data-breach/ · https://databreaches.net/2026/06/22/xsolis-breach-affected-1396519-of-its-clients-patients/ · Sources: [SecurityWeek] · [HIPAA Journal] · [DataBreaches.net]
Jun 22
AryStinger botnet
Unattributed
logged as an enabling-access infrastructure event · https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/ · https://www.malwarebytes.com/blog/news/2026/06/thousands-of-d-link-routers-under-control-of-arystinger-botnet · Sources: [BleepingComputer] · [Malwarebytes]
Jun 21
jktornel
INC Ransom
client data, proprietary information claimed · Sources: ransomware.live DLS
Jun 21
JAG Group
Stormous
US-based business services company; corporate emails (@jaggroup.com), Active Directory domain logins with clear-text passwords, complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration data exfiltrated; full data dump published June 29, 2026 (new link posted after June 24 initial dump); estimated attack date June 20 · https://www.dexpose.io/stormous-ransomware-breach-exposes-jag-group-data/ · https://www.redpacketsecurity.com/stormous-ransomware-victim-jaggroup-com-update-full-data-dump/ · https://www.ransomware.live/id/amFnZ3JvdXAuY29tIFVQREFURS1GVUxMIERBVEEgRFVNUEBzdG9ybW91cw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 21
Artistic Smiles
NightSpire
https://www.redpacketsecurity.com/nightspire-ransomware-victim-artistic-smiles/ · Sources: ransomware.live DLS / [RedPacket Security]
Jun 21
Texas Parks and Wildlife Dept.
Unattributed
3,087,721 individuals exposed: driver's license numbers, passport numbers, email, phone, residential address; no SSNs/DOB/financial data; actor unattributed · https://www.techtimes.com/articles/318790/20260621/texas-data-breach-hits-3-million-drivers-licenses-passport-numbers-stolen-hunting-vendor.htm · Sources: [TechTimes]
Jun 20
Pacific Lamp & Supply
Qilin
industrial lighting and electrical supply company; Qilin DLS claim June 20, 2026; data scope and impact unconfirmed; 🟥 unverified — verify before treating as breach · https://www.redpacketsecurity.com/qilin-ransomware-victim-pacific-lamp-supply/ · https://www.ransomware.live/id/UGFjaWZpYyBMYW1wICYgU3VwcGx5QHFpbGlu · Sources: [RedPacket Security] · [ransomware.live]
Jun 20
BITS Pilani
DragonForce
https://www.redpacketsecurity.com/dragonforce-ransomware-victim-bits-pilani-ac-in/ · https://www.ransomware.live/group/dragonforce · Sources: [RedPacket Security] · [ransomware.live]
Jun 20
Super Finishing
WorldLeaks
metal parts finishing and surface treatment company; DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.dexpose.io/worldleaks-targets-brazilian-manufacturer-super-finishing/ · Sources: [DeXpose]
Jun 20
L'Archevêque & Rivest Ltée
WorldLeaks
Canadian general contractor and civil engineering services firm; DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.dexpose.io/worldleaks-hits-larcheveque-rivest-ltee-in-ransomware-attack/ · Sources: [DeXpose]
Jun 20
One Believing Interiors
Nova
interior design studio specializing in built spaces including National Gallery projects; DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-nova-hits-one-believing-interiors/ · https://www.ransomware.live/id/T25lIEJlbGlldmluZyBJbnRlcmlvcnNAbm92YQ== · Sources: [HookPhish] · [ransomware.live]
Jun 20
MIT HJERTE
Nova
DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-nova-hits-mit-hjerte/ · https://www.ransomware.live/group/nova · Sources: [HookPhish] · [ransomware.live]
Jun 20
Dosab
Nova
organized industrial zone operator in Bursa, Turkey; Nova DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.redpacketsecurity.com/nova-ransomware-victim-dosab/ · https://www.ransomware.live/group/nova · Sources: [RedPacket Security] · [ransomware.live]
Jun 20
Newspaper Media Group
INC Ransom
US-based local news organization operating community newspapers and magazines across Central and South Jersey; DLS claim June 20, 2026; data scope and impact unconfirmed; no public statement from victim · https://www.redpacketsecurity.com/incransom-ransomware-victim-newspaper-media-group/ · Sources: [RedPacket Security]
Jun 20
Preferred Properties
Payload
DLS claim June 20, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/payload-ransomware-victim-preferred-properties/ · Sources: [RedPacket Security]
Jun 20
AmiGest
The Gentlemen
French IT integrator specialising in cloud, network, and managed services for SME clients; The Gentlemen ransomware DLS claim June 20, 2026; data scope and impact unconfirmed; attribution confirmed by DeXpose reporting · https://www.dexpose.io/theGentlemen-ransomware-attack-on-amigest/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 19
PJ Daly Contracting
Qilin
construction contractor; DLS claim June 19, 2026; data scope and impact unconfirmed · https://www.redpacketsecurity.com/qilin-ransomware-victim-pj-daly-contracting/ · https://ransomware.live/id/UEogRGFseSBDb250cmFjdGluZ0BxaWxpbg== · Sources: [RedPacket Security] · [ransomware.live]
Jun 19
ALS Global Limited
Aur0ra
ASX-listed global testing, inspection, and certification firm (est. 1863; ~70 countries; mining, environmental, food safety, life sciences, materials testing); attack May 2026 (disclosed June 11 via ASX filing); Aur0ra DLS claim June 19, 2026; data published dark web June 22; 500+ employees' home directories including cached credentials; hundreds of plaintext password files; passport scans; bank account details; payroll data; workplace injury records; client laboratory results and analytical data; ALS confirmed breach, engaged cybersecurity specialists, and notified ACSC and relevant regulators · https://www.cyberdaily.au/security/13794-exclusi · https://www.dexpose.io/aurora-ransomware-strikes-als-global/ · https://www.breachsense.com/breaches/als-global-data-breach/ · Sources: [Cyber Daily] · [DeXpose] · [Breachsense]
Jun 19
Aflac
Scattered Spider
June 2025 social-engineering intrusion; 22.6M people notified (≥13.9M with PHI) · Sources: The Record / HIPAA Journal
Jun 18
Inter-Con Security Systems
ShinyHunters
provider of armed/unarmed security officers, risk management, executive protection, and facility security for government, corporate, and critical infrastructure; 2.7M records claimed; ShinyHunters DLS June 18, 2026; no victim statement · https://www.dexpose.io/shinyhunters-compromise-ic-security-in-major-ransomware-attack/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-icsecurity-com/ · https://www.breachsense.com/breaches/inter-con-security-systems-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
Jun 18
Horizon Family Medical Group
INC Ransom
7TB of sensitive data claimed exfiltrated; includes patient medical records (diagnoses, prescriptions, treatments, lab results), SQL databases, and QuickBooks financial data; victim management notified but did not respond per INC Ransom; 🟥 unconfirmed — no Horizon public statement · https://www.dexpose.io/incransom-compromises-horizon-family-medical-group/ · https://www.ransomware.live/group/incransom · https://malware.news/t/incransom-compromises-horizon-family-medical-group/108055 · Sources: [DeXpose] · [ransomware.live] · [Malware News]
Jun 18
"FortiBleed" mass credential exposure
Unattributed
logged as an enabling-access event feeding downstream intrusions; seen 2026-06-18 — BleepingComputer / Help Net Security (no CVE, no single attributed actor)
Jun 17
Novo Nordisk
FulcrumSec
🟥 unverified group claim; confirm before treating as a breach · Sources: ransomware.live DLS
Jun 17
iRhythm Technologies
Unattributed
proprietary data + patient PHI allegedly exfiltrated from third-party-hosted apps, ransom demanded · actor not yet attributed · Sources: Dark Reading / DataBreachToday
Jun 16
Moody Bible Institute
ShinyHunters
1,300+ files claimed; group alleged "tens of millions of records" related to enrollment, donor relations, payroll, and communications; Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim June 16, 2026; scope unverified; law firm class action investigation underway — 🟥 unverified · https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit · https://www.classaction.org/data-breach-lawsuits/moody-bible-institute-june-2026 · Sources: [Google Cloud Blog] · [classaction.org]
Jun 16
Kedah State Government
Nova
official state government portal providing public services for Kedah, Malaysia; Nova DLS claim June 16, 2026; estimated attack date June 16; data scope and impact unconfirmed · https://www.dexpose.io/nova-ransomware-group-targets-kedah-state-government/ · https://www.ransomware.live/id/S2VkYWhAbm92YQ== · Sources: [DeXpose] · [ransomware.live]
Jun 16
River Bank & Trust
Unattributed
ransomware attack June 16, 2026; SEC 8-K filed June 25, 2026; PII of customers and employees potentially exposed; investigation ongoing; operational impact not disclosed; actor unattributed · https://www.sec.gov/Archives/edgar/data/1641601/000119312526282946/ck0001641601-20260619.htm · https://1819news.com/news/item/river-bank-trust-hit-by-ransomware-attack-from-unauthorized-threat-actor · Sources: [SEC 8-K] · [1819 News]
Jun 15
Grupo Indi
Qilin
prominent Mexican civil engineering and construction company; Qilin DLS claim June 15, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-targets-mexican-construction-leader-grupo-indi/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jun 15
Kawai Musical Instruments Mfg. Co., Ltd.
SafePay
renowned Japanese manufacturer of pianos, digital keyboards, and band/orchestral instruments; SafePay DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/safepay-ransomware-attack-on-kawai-musical-instruments/ · https://www.ransomware.live/id/a2F3YWl1cy5jb21Ac2FmZXBheQ== · https://www.hendryadrian.com/ransom-kawaius-com-jun-2026/ · Sources: [DeXpose] · [ransomware.live] · [hendryadrian.com]
Jun 15
Hugh Stirling Ltd
SafePay
established UK construction company; SafePay DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/safepay-ransomware-attack-on-hugh-stirling-ltd/ · https://www.ransomware.live/group/safepay · Sources: [DeXpose] · [ransomware.live]
Jun 15
Kodak
ShinyHunters
2.2M records (customer PII and internal corporate data); ShinyHunters listed June 15 with a June 18 ransom deadline; Kodak confirmed "unauthorized third party illegally gained temporary access to a limited amount of company data" June 17 and engaged cybersecurity experts and law enforcement; no proof sample published; no data dump confirmed; claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://cybernews.com/security/shinyhunters-claims-kodak-hack-2-million-records/ · https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/ · https://www.techtimes.com/articles/318565/20260617/kodak-confirms-data-breach-shinyhunters-threatens-leak-22m-records.htm · Sources: [Cybernews] · [BleepingComputer] · [TechTimes]
Jun 15
Sysco
ShinyHunters
61M Salesforce records claimed; ShinyHunters listed June 15, weeks after Sysco was separately targeted by Qilin ransomware (two distinct threat actors targeting the same org); Sysco has not publicly confirmed this incident; 🟥 unverified — treat as claimed only · https://cybernews.com/news/sysco-shinyhunters-61-million-salesforce-records/ · Sources: [Cybernews]
Jun 15
Glendale Community College
ShinyHunters
62GB exfiltrated (304,000+ files); Oracle PeopleSoft Campus Solutions compromised via CVE-2026-35273; 150,000+ student records including names, DOBs, student emails, enrollment, financial aid, and transcript data (Sept 2020–June 2026); DLS claim June 15–16, 2026; final ransom warning before June 18 deadline · https://www.ransomware.live/id/Z2xlbmRhbGUuZWR1QHNoaW55aHVudGVycw · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-glendale-edu/ · https://cybernews.com/security/google-shinyhunters-oracle-peoplesoft-zero-day-extortion/ · Sources: [ransomware.live] · [RedPacket Security] · [Cybernews]
Jun 15
Illinois Central College
ShinyHunters
28GB data claimed; Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim June 15, 2026; final ransom warning issued · https://www.dexpose.io/shinyhunters-breach-illinois-central-college/ · https://www.breachsense.com/breaches/illinois-central-college-data-breach/ · Sources: [DeXpose] · [Breachsense]
Jun 15
Deep Well Services
ShinyHunters
provider of downhole tools and services to the oil and gas industry; 7,000+ customer PII and internal corporate data records claimed; ShinyHunters DLS June 15, 2026; ransom deadline June 18 passed without data publication at time of initial report; no victim statement · https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-deep-well-services/ · https://www.ransomware.live/id/RGVlcCBXZWxsIFNlcnZpY2VzQHNoaW55aHVudGVycw · https://breachnews.com/breaches/kodak-and-deep-well-services-added-to-shinyhunters-leak-site/ · Sources: [HookPhish] · [ransomware.live] · [BreachNews]
Jun 15
Mahajak Development Co., Ltd.
The Gentlemen
leading IT and technology distributor in Thailand; The Gentlemen DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/the-gentlemen-ransomware-targets-mahajak-development/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 14
INK
DragonForce
UK-based production studio; 102.85 GB exfiltrated; DLS claim June 14, 2026; 7–8 day data-publication ultimatum issued after ransom deadline · https://www.dexpose.io/dragonforce-ransomware-attack-on-ink/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-ink/ · Sources: [DeXpose] · [RedPacket Security]
Jun 14
Council of Europe
ShinyHunters
297 GB published June 16, 2026, after ransom deadline not met; content: 409,000+ payslips (2011–2026), 3,700+ personnel files, 14,000+ CVs, and employee personal/financial records (names, DOB, home addresses, phone, salaries, bank account details, SSN/tax information, medical records) for 10,000+ staff; claimed access vector: Oracle PeopleSoft CVE-2026-35273; Council of Europe states investigation is ongoing; data authenticity not yet independently verified by forensics · https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/ · https://www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/ · https://cybernews.com/security/council-of-europe-data-breach-claim/ · Sources: [SecurityWeek] · [BleepingComputer] · [Cybernews]
Jun 14
Winona County
NightSpire
second ransomware attack on county in 2026; attack detected April 7; county network partially taken offline; MN National Guard assisted; NightSpire leaked data June 14 2026; county confirmed data leak same day; personal info affected pending review; 🟨 county-confirmed · https://www.govtech.com/security/cyber-criminals-leak-data-from-minnesota-ransomware-incident · https://www.dexpose.io/nightspire-ransomware-attack-on-k-county/ · Sources: [GovTech] · [DeXpose]
Jun 13
One Medical
ShinyHunters
legacy One Medical Seniors patient file storage compromised (demographic + clinical records, 9 US cities: Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, Seattle); 8.8TB claimed; breach June 8-11, detected June 13; ShinyHunters deadline June 22; company confirmed unauthorized access; core EHR and non-Seniors systems unaffected; vector unconfirmed (not PeopleSoft CVE-2026-35273) · https://www.hipaajournal.com/one-medical-data-breach/ · https://cybernews.com/security/amazon-one-medical-data-breach/ · https://www.bankinfosecurity.com/shinyhunters-threatens-to-leak-amazon-one-medical-records-a-32027 · Sources: [HIPAA Journal] · [Cybernews] · [BankInfoSecurity]
Jun 12
Al Shafar GRC
DragonForce
UAE construction and governance, risk, and compliance services company; DragonForce DLS claim June 12, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jun 12
Al Ishrak Contracting
DragonForce
Dubai-based contracting company; DragonForce DLS claim June 12, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jun 12
JCPenney / Catalyst Brands / Authentic Brands Group
ShinyHunters
hundreds of thousands of records claimed (SSNs, DOBs, W-2 tax forms, payroll records, driver's licenses, government-issued IDs); ShinyHunters claimed June 12; threatened to publish by June 15; no JCPenney/Catalyst/Authentic public statement; class action investigation launched (Edelson Lechtzin LLP, June 18); no data samples published; 🟥 unverified — treat as claimed only · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-jcpenney-several-other-subsdiaries-under-catalyst-brands-authentic-brands-group/ · https://cybernews.com/security/shinyhunters-jcpenney-retail-data-leak-claim/ · https://www.dexpose.io/shinyhunters-breaches-jcpenney-and-catalyst-brands/ · Sources: [RedPacket Security] · [Cybernews] · [DeXpose]
Jun 12
American Tower Corporation
ShinyHunters
5.2M records claimed including customer and landowner PII, records linking T-Mobile/Verizon/US DHS as clients, tower asset GPS coordinates, and plaintext physical access/gate codes for cell tower compounds across the US; claimed June 12, ransom deadline June 15 (passed with no confirmed data dump); company has not issued a public statement; 🟥 unverified — treat as claimed only · https://www.dexpose.io/shinyhunters-breach-american-tower-corporation/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-american-tower-corporation/ · https://www.breachsense.com/breaches/american-tower-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
Jun 12
Zayo Group + Allstream
ShinyHunters
ShinyHunters claimed June 12, 2026 with a June 16 payment-or-leak deadline; data scope unconfirmed; no victim statement · https://www.dexpose.io/shinyhunters-target-zayo-group-and-allstream-in-ransomware-attack/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-zayo-com-allstream-com/ · https://www.ransomware.live/id/WmF5by5jb20gJiBBbGxzdHJlYW0uY29tQHNoaW55aHVudGVycw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 12
BeyondTrust
Icarus
Salesforce CRM business contact and general sales-related customer information accessed via Klue OAuth integration; notified June 12, publicly disclosed June 24 via BeyondTrust Trust Center; 13th confirmed Klue supply-chain victim · https://www.beyondtrust.com/trust-center/security-advisories/klue-security-incident · https://www.securityweek.com/beyondtrust-lastpass-impacted-by-klue-salesforce-incident/ · Sources: [BeyondTrust] · [SecurityWeek]
Jun 12
8×8
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 24; 14th confirmed Klue supply-chain victim · https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ · Sources: [SecurityWeek]
Jun 12
Pendo
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 24; 15th confirmed Klue supply-chain victim · https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ · Sources: [SecurityWeek]
Jun 12
AlertMedia
Icarus
Salesforce CRM business contact and sales data accessed via Klue OAuth integration; disclosed June 30, 2026; 17th confirmed Klue supply-chain victim · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12
Blackbaud
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026; 🟨 scope unverified · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12
Camunda
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12
Cresta
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12
Deel
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12
Lucanet
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12
Link11
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12
Tines
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12
Nintendo of America
ShadowByt3$
ShadowByt3$ claimed June 12, 2026 via compromise of TinyPulse (HR and employee-engagement SaaS platform used by Nintendo); group demanded $2M ransom with 48-hour deadline; Nintendo declined; ShadowByt3$ shifted demand to TinyPulse directly on June 14 with June 16 secondary deadline; data leaked June 16 after deadline passed; Nintendo confirmed breach "limited to internal survey content comprising a small subset of our employees" — Nintendo's own network was not compromised; attack was against TinyPulse's cloud environment; ShadowByt3$ claims 859MB including full employee names, email addresses, bank statements, W-9 tax forms, employee IDs, HR progress plans, analytics, and survey data spanning 2016–2026; 🟨 breach confirmed by Nintendo (survey content); broader scope claims unverified · https://hackread.com/nintendo-america-employee-data-shadowbyt3-tinypulse/ · https://www.nintendolife.com/news/2026/06/hacker-group-claims-to-have-stolen-nintendo-data-posts-usd2-million-ransom · https://www.technadu.com/nintendo-confirms-tinypulse-data-stolen-in-shadowbyt3-extortion-attack/629628/ · https://www.dexpose.io/shadowbyt3-targets-nintendo-via-tinypulse/ · Sources: [HackRead] · [Nintendo Life] · [TechNadu] · [DeXpose]
Jun 11
Areco
DragonForce
leading Swedish construction materials sector company; DLS claim June 11, 2026; data scope and impact unconfirmed · https://www.dexpose.io/dragonforce-ransomware-attack-on-areco/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-areco/ · Sources: [DeXpose] · [RedPacket Security]
Jun 11
National Association of Insurance Commissioners
ShinyHunters
3.1TB and 105,000+ files claimed; investigation confirmed (July 1): only publicly available statutory financial reports, outdated logs, and config files accessed; key systems SERFF/OPTins/UCAA/EDP/RDC confirmed intact; no consumer PII or payment data; breach via PeopleSoft CVE-2026-35273, access June 11; data published online by June 25; 🟩 breach confirmed, impact minimal (public regulatory data only) · https://www.insurancejournal.com/news/national/2026/06/24/875119.htm · https://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/ · https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack · Sources: [Insurance Journal] · [BleepingComputer] · [TechRadar]
Jun 11
Baylor Genetics
Unknown
Unauthorized access to Baylor Genetics systems June 11-17 2026; 305,066 individuals notified (248,430 Texas, 56,636 Massachusetts); exposed: genetic test results, SSNs, dates of birth, health insurance info, employee financial account numbers; breach detected ~June 15; data review concluded ~July 30; notifications dispatched August 20 2026 · Sources: https://www.bankinfosecurity.com/genomics-testing-lab-notifies-nearly-310000-hack-a-32618
Jun 10
Sayre Associates
DragonForce
civil engineering and land surveying firm (est. 1969; land development, parks and recreation design, drainage/erosion control, construction administration); sensitive client data, project files, emails, and financial documents claimed; DLS claim June 10, 2026 · https://www.dexpose.io/dragonforce-strikes-sayre-associates-in-ransomware-attack/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-sayre-associates/ · Sources: [DeXpose] · [RedPacket Security]
Jun 10
Tata Electronics
WorldLeaks
200,000+ files (630+ GB) exfiltrated: Apple iPhone manufacturing records, technical drawings, component specifications, Tesla engineering documents, employee passport scans; attack date est. early June 2026; Tata confirmed breach June 23; operations reported unaffected; Apple investigating; ransom demand confirmed but payment status unknown · https://cybernews.com/security/tata-electronics-breach-apple-tesla-secret-files/ · https://www.cnbc.com/amp/2026/06/23/indias-tata-electronics-hit-by-cyber-breach-claiming-to-expose-apple-tesla-trade-secrets.html · Sources: [Cybernews] · [CNBC]
Jun 10
Mackay Sugar
The Gentlemen
mills shut, harvest disrupted; ransomware confirmed (The Gentlemen attribution) · Sources: SecurityWeek / The Record
Jun 09
University of Nottingham
ShinyHunters
454,600+ student and alumni records including names, addresses, phone numbers, passport numbers, ethnicity and disability data, and academic records; Oracle PeopleSoft CVE-2026-35273 confirmed access vector (attack window May 27–June 9); university confirmed incident June 11, 2026 · https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/ · https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-raids-nottingham-uni-for-student-alumni-data/5253961 · https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/ · Sources: [BleepingComputer] · [The Register] · [Help Net Security]
Jun 09
Houston City College
ShinyHunters
Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim first posted June 9 onwards; named victim confirmed in Google Cloud/Mandiant ShinyHunters education sector campaign report (June 2026) · https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit · https://www.highereddive.com/news/colleges-hit-in-cyberattack-by-group-behind-canvas-breach-google-says/822831/ · Sources: [Google Cloud Blog] · [Higher Ed Dive]
Jun 09
Spratley's of Mortimer
PrinzEugen
posted twice on DLS; de-duped · Sources: ransomware.live DLS
Jun 09
Philadelphia Insurance Companies
Ethics
DLS claim by new group Ethics (debuted Aug 12, 2026); one of 3 simultaneous inaugural postings; estimated attack date Jun 2026; scope unverified · Sources: https://www.dexpose.io/ethics-ransomware-group-targets-philadelphia-insurance-companies/
Jun 08
Covenant Health
Qilin
Qilin attack May 2025; ~850GB leaked, 478,188 individuals affected (notifications confirmed) · Sources: The Record / SecurityWeek
Jun 05
REHA-ACTIV
DragonForce
medical rehabilitation equipment, mobility aids, orthotics, prosthetics, home care products; 48.55 GB exfiltrated; DLS claim June 5, 2026 · https://www.dexpose.io/dragonforce-targets-german-medical-supplier-reha-activ/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-reha-activ/ · Sources: [DeXpose] · [RedPacket Security]
Jun 05
Madison Square Garden Sports Corp.
ShinyHunters
45 GB published June 16 (26M customer and corporate records); content includes facial recognition surveillance records, internal threat assessments, and personal customer data; breach June 5, ransom deadline June 15, deadline missed, data published June 16; MSG's second major breach within 6 months (prior: Cl0p/Oracle eBusiness Suite February 2026, 131,070 employees/contractors); claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://thenextweb.com/news/shinyhunters-madison-square-garden-45gb-data-leak-facial-recognition · https://www.dexpose.io/shinyhunters-breach-madison-square-garden-sports-corp/ · Sources: [The Next Web] · [DeXpose]
Jun 04
National Industries
The Gentlemen
Indian precision-engineered automotive components manufacturer under the Metalman Group; supplies major two-wheeler OEMs; The Gentlemen DLS claim June 4, 2026; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.dexpose.io/thegentlemen-ransomware-attack-on-national-industries/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 03
Copamex
DragonForce
Monterrey-based paper products manufacturer (est. 1928); DLS claim June 3, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-copamex/ · Sources: [RedPacket Security]
Jun 03
SETS Solutions
DragonForce
technology solutions provider (est. 1990; HR management system People365, data centre, cloud, end-user computing); DLS claim June 3, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-sets-solutions/ · Sources: [RedPacket Security]
Jun 02
Cropwise
ShadowByt3$
Syngenta's digital farming platform offering GIS mapping, field crop scouting, and agronomic advisory tools deployed across 100+ countries; ShadowByt3$ DLS claim June 2, 2026; 10.4 MB of data exfiltrated including agricultural GIS data, crop field data, and user credentials; no Syngenta or Cropwise public statement · https://hackread.com/ · Sources: [HackRead]
Jun 01
Synex International Pvt Ltd
DragonForce
integrated mechanical, electrical, and plumbing (MEP), extra-low voltage (ELV), and solar energy solutions provider; DragonForce DLS claim June 1, 2026; 13.63 GB claimed; estimated attack date May 30, 2026 · https://www.dexpose.io/dragonforce-strikes-synex-international-pvt-ltd-in-sophisticated-ransomware-attack/ · https://www.hookphish.com/blog/ransomware-group-dragonforce-hits-synex-international-pvt-ltd/ · https://www.ransomware.live/id/U3luZXggSW50ZXJuYXRpb25hbCBQdnQgTHRkQGRyYWdvbmZvcmNl · Sources: [DeXpose] · [HookPhish] · [ransomware.live]
Jun 01
The Adviser
Brain Cipher
350GB claimed; ransom deadline 2026-06-02 · Sources: Brain Cipher DLS
Jun 01
School Facility Consultants
Abyss
California-based firm advising school districts on facility planning, project management, and construction; Abyss DLS claim June 1, 2026; sensitive information threatened for release; scope unconfirmed · https://www.dexpose.io/abyss-ransomware-targets-school-facility-consultants/ · https://www.hookphish.com/blog/ransomware-group-abyss-hits-school-facility-consultants/ · Sources: [DeXpose] · [HookPhish]
Jun 01
Expert MRI
Unattributed
PEAR DLS claim seen 2026-06, attack est. Aug 2025 — ransomware.live DLS — 🟥 attack predates PEAR posting; 617GB alleged, 209,560 individuals' PHI (names, addresses, DOB, diagnosis/treatment, SSNs); verify PEAR attribution independently
Jun 01
RRCA Accounts Management
Unattributed
115,837 individuals affected
Jun 01
Dairy Farmers of America
Unattributed
employee + member data leaked · actor not yet attributed · Sources: The Record
Jun 01
Dresden State Art Collections
Unattributed
digital systems disrupted · actor not yet attributed · Sources: The Record
Jun 01
DHS Homeland Security Information Network
Unattributed
HSIN servers and an associated SharePoint collaboration system compromised; used by state/local law enforcement fusion centers and federal agencies to share threat intelligence; attack estimated late May–early June 2026; disclosed July 1, 2026; DHS confirmed attack and isolated affected systems; forensic investigation underway; no classified networks affected; sensitive law enforcement operational data (open investigations, facility-threat mappings, inter-agency partner identities) potentially exposed; actor unattributed · https://www.bleepingcomputer.com/ · https://www.nextgov.com/ · Sources: [BleepingComputer] · [Nextgov/FCW]
Jun 01
Department of Homeland Security (HSIN)
Unknown
DHS confirmed intrusion into Homeland Security Information Network (HSIN), the SBU inter-agency intelligence-sharing platform; attackers stole credential files, ran malicious code, and deleted logs; initial alerts were dismissed as false positives giving extended dwell time (late May - early June 2026); classified systems not affected; House Homeland Security Committee requested formal briefing; 🟩 confirmed by DHS · Sources: https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/ · https://www.nextgov.com/cybersecurity/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414724/
May 2026
May 28
VVO Finance
Everest
Everest DLS May 28, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-vvo-finance/ · https://www.redpacketsecurity.com/everest-ransomware-victim-vvo-finance/ · Sources: [HookPhish] · [RedPacket Security]
May 27
QLS Group
DragonForce
large Australian domestic appliances retailer and logistics group; DragonForce DLS claim May 27, 2026; threat to release data; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/dragonforce-targets-qls-group-in-ransomware-attack/ · https://www.ransomware.live/group/dragonforce · Sources: [DeXpose] · [ransomware.live]
May 27
Carnival Corporation
ShinyHunters
5,995,277 individuals affected; names, dates of birth, addresses, email, phone, passport and driver's license numbers; social-engineering attack on Carnival employee led to account compromise April 14, 2026; data exfiltrated before access blocked; breach notification letters dated May 27, 2026 · https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/ · https://www.theregister.com/cyber-crime/2026/05/28/carnival-shinyhunters-cruised-off-with-6m-customer-records/5247808 · https://www.malwarebytes.com/blog/data-breaches/2026/05/carnival-confirms-data-breach-impacting-nearly-6-million · Sources: [BleepingComputer] · [The Register] · [Malwarebytes]
May 23
DentaQuest
ShinyHunters
2.6M members' PII and PHI exposed (names, DOBs, email, phone, home addresses, gender, government-issued IDs, health insurance info, Medicaid IDs); 234GB exfiltrated; ShinyHunters posted May 23, data published after ransom negotiation failure; DentaQuest confirmed breach June 2, 2026; 2,553,599 unique emails confirmed via HIBP June 3; attack vector unconfirmed · https://securityaffairs.com/193274/data-breach/dentaquest-breach-shinyhunters-publish-data-impacting-2-6m-people.html · https://www.bankinfosecurity.com/shinyhunters-leaks-234gb-dentaquest-data-trove-a-31883 · https://www.rescana.com/post/dentaquest-data-breach-analysis-shinyhunters-leak-exposes-pii-and-phi-of-2-6-million-members-in-2026 · https://www.hipaajournal.com/dentaquest-data-breach/ · Sources: [SecurityAffairs] · [BankInfoSecurity] · [Rescana] · [HIPAA Journal]
May 22
TVN Media
APT73
leading multimedia company and broadcaster based in Panama; APT73/Bashe DLS claim May 22, 2026; data scope and impact unconfirmed; APT73 noted for fabricating some high-profile claims — 🟥 unverified pending independent confirmation · https://www.dexpose.io/apt73-bashe-strikes-panamas-tvn-media/ · https://www.ransomware.live/group/apt73 · Sources: [DeXpose] · [ransomware.live]
May 20
GitHub Internal
Lapsus$
~3,800–4,000 internal source code repositories exfiltrated; attack May 20, 2026 via poisoned "Nx Console" VS Code extension (nrwl.angular-console v18.95.0, published May 18 by threat actor); primary actor: TeamPCP (UNC6780); Lapsus$ listed as extortion partner (operational collaboration confirmed since March 2026 per Resecurity); joint dark-web listing: $50K (TeamPCP standalone) / $95K (TeamPCP x Lapsus$); exfiltrated content includes GitHub Actions, Copilot internal tooling, CodeQL, security tools, Codespaces, and Dependabot source; GitHub confirmed unauthorized access to internal repositories; GitHub stated customer repositories, enterprise accounts, and user data NOT affected; Lapsus$ DLS claim June 13, 2026 · https://therecord.media/github-confirms-teampcp-hack-customers-unaffected · https://www.infosecurity-magazine.com/news/github-confirms-breach-vs-code/ · https://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html · https://www.bleepingcomputer.com/news/security/github-investigates-internal-repositories-breach-claimed-by-teampcp/ · Sources: [The Record] · [Infosecurity Magazine] · [The Hacker News] · [BleepingComputer]
May 15
Krum Public Library
NightSpire
50 GB claimed exfiltrated: financial docs, HR data, supervisor info; attack May 14 2026; city of Krum confirmed ransomware in June 3 public notice; no SSNs/financial account info compromised; backups prevented permanent data loss; 🟨 city-confirmed · https://dysruptionhub.com/krum-library-ransomware-wifi/ · https://www.ransomware.live/id/S3J1bSBQdWJsaWMgTGlicmFyeUBuaWdodHNwaXJl · Sources: [Dysruption Hub] · [ransomware.live]
May 06
Keretapi Tanah Melayu Berhad
The Gentlemen
Malaysia's national railway company; The Gentlemen DLS claim May 6, 2026; 3,858 employees and 8,428 users exposed; 21 third-party employee credentials and 143 external attack surface vulnerabilities identified; estimated attack date May 3, 2026; rail operations unaffected · https://www.dexpose.io/the-gentlemen-ransomware-group-targets-keretapi-tanah-melayu-berhad/ · https://www.ransomware.live/id/S2VyZXRhcGkgVGFuYWhAdGhlZ2VudGxlbWVu · Sources: [DeXpose] · [ransomware.live]
May 04
Hokuyo 2006 Co., Ltd.
SafePay
SafePay DLS claim; data exfiltration from multiple directories claimed incl. employee records and business documents; no victim statement · https://www.redpacketsecurity.com/safepay-ransomware-victim-hokuyo2006-co-jp/ · https://www.ransomware.live/id/aG9rdXlvMjAwNi5jby5qcEBzYWZlcGF5 · Sources: [RedPacket Security] · [ransomware.live]
May 03
Fiserv Inc.
Everest
powers core banking systems, digital platforms, merchant acquiring, and Clover POS for thousands of financial institutions worldwide; Everest DLS May 3, 2026; no ransom demand stated; Fiserv has not confirmed; 🟥 unverified · https://www.dexpose.io/everest-ransomware-attack-targets-financial-tech-leader-fiserv/ · https://www.redpacketsecurity.com/everest-ransomware-victim-fiserv/ · https://www.breachsense.com/breaches/fiserv-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
May 02
Epiq Global
Everest
global eDiscovery, class action administration, bankruptcy case management provider; Everest DLS May 2, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-epiq-global/ · https://www.redpacketsecurity.com/everest-ransomware-victim-epiq-global/ · Sources: [HookPhish] · [RedPacket Security]
May 02
TSYS
Everest
Global Payments' core payment-processing and card-issuer subsidiary; Everest DLS May 2, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-tsys/ · https://www.redpacketsecurity.com/everest-ransomware-victim-tsys/ · Sources: [HookPhish] · [RedPacket Security]
May 02
Symcor Inc.
Everest
Canada's primary bank-statement and tax-document processor for the Big Five Canadian banks; Everest DLS May 2, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-symcor/ · https://www.dexpose.io/everest-ransomware-group-strikes-canadian-firm-symcor/ · Sources: [HookPhish] · [DeXpose]
May 01
BCD Travel
ShinyHunters
396,313 customer email addresses and 700,000+ Salesforce records (30 GB+ compressed) published after June 1 ransom deadline; data includes names, physical addresses, phone numbers, job titles, and support tickets; access via direct Salesforce/SharePoint compromise (not Oracle PeopleSoft CVE-2026-35273) · https://cybernews.com/security/shinyhunters-400k-bcd-travel-customers-data-online/ · https://www.dutchnews.nl/2026/06/dutch-travel-firm-bcd-hacked-700000-customers-reportedly-hit/ · Sources: [Cybernews] · [DutchNews.nl]
May 01
Cushman & Wakefield
ShinyHunters
500,000+ Salesforce records (310,400 accounts confirmed via HIBP May 12); names, job titles, company addresses, phone numbers, email addresses; vishing attack May 1 2026; 50GB data published May 7 after ransom talks failed (May 6 deadline); Qilin also listed Cushman & Wakefield on DLS May 4 — relationship unconfirmed, may reflect separate opportunistic access; access via Salesforce (not PeopleSoft CVE-2026-35273) · https://cybernews.com/security/shinyhunters-cushman-wakefield-salesforce-dataset-leak/ · https://www.theregister.com/security/2026/05/05/cushman-wakefield-confirms-vishing-cyberattack/5228718/ · https://socradar.io/blog/charter-data-breach-shinyhunters-42m-records/ · Sources: [Cybernews] · [The Register] · [SOCRadar]
April 2026
Apr 30
Liberty Mutual Insurance
Everest
108 GB (52,429 files) dumped May 4 after ransom deadline; policyholder names, addresses, policy numbers, financial details; Liberty Mutual confirmed "third-party vendor" investigation and denied direct system compromise; 🟨 vendor breach confirmed · https://www.bankinfosecurity.com/everest-group-begins-leaking-alleged-liberty-mutual-data-a-31589 · https://cybernews.com/security/liberty-mutual-ransomware-attack-policyholder-data/ · Sources: [BankInfoSecurity] · [Cybernews]
Apr 28
Mediaworks Kft
WorldLeaks
Hungary's largest pro-government media company (Orbán-aligned conglomerate operating national TV, radio, and print outlets); WorldLeaks DLS claim April 28-29, 2026; 15 million files (~8.5 TB) published including payroll records, contracts, financial statements, and internal communications; Hungary's National Authority for Data Protection and Freedom of Information (NAIH) confirmed unlawful exfiltration and scale; Mediaworks confirmed breach and warned journalists against circulating leaked material; 🟨 confirmed breach, scope verified by Hungarian data authority · https://therecord.media/ransomware-group-claims-breach-of-pro-orban-media-firm · https://www.redpacketsecurity.com/worldleaks-ransomware-victim-mediaworks-kft/ · https://www.dexpose.io/worldleaks-targets-hungarian-mediaworks-kft/ · Sources: [The Record] · [RedPacket Security] · [DeXpose]
Apr 25
Instructure/Canvas
ShinyHunters
275 million users across 8,809 universities, educational ministries, and institutions worldwide; attack April 25, 2026; Instructure detected intrusion April 29 and revoked access; disclosed May 1; data includes student names, email addresses, student ID numbers, and user messages; described as the largest educational data breach on record; Instructure paid ransom, "shred logs" provided May 11; FBI warned students and staff of ongoing phishing risk post-ransom · https://www.malwarebytes.com/blog/news/2026/05/millions-of-students-personal-data-stolen-in-major-education-cyberattack · https://www.bitdefender.com/en-us/blog/hotforsecurity/canvas-data-breach-2026 · Sources: [Malwarebytes] · [Bitdefender]
Apr 24
Udemy
ShinyHunters
1.4 million records claimed; listed DLS April 24, data published April 27 after ransom deadline; no Udemy public confirmation — 🟥 unverified · https://cybernews.com/security/shinyhunters-claim-udemy-data-theft/ · https://www.scworld.com/brief/udemy-allegedly-breached-by-shinyhunters-data-leak-warned · Sources: [Cybernews] · [SC Media]
Apr 21
Zara
ShinyHunters
197,400 customer emails, product order data (order IDs, SKUs, market of purchase); Anodot/BigQuery SaaS supply chain (not PeopleSoft CVE-2026-35273); ransom deadline April 21, data published April 22 after deadline; Inditex confirmed "unauthorized access to BigQuery data via a retired third-party analytics provider" early May 2026; HIBP added May 8; no passwords or payment data affected · https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/ · https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html · https://www.infosecurity-magazine.com/news/zara-data-breach-impacts-200000/ · Sources: [BleepingComputer] · [SecurityAffairs] · [Infosecurity Magazine]
Apr 21
7-Eleven
ShinyHunters
600,000+ Salesforce CRM records; listed DLS April 21-27, 2026; data published after ransom deadline; Salesforce environment vector (not PeopleSoft CVE-2026-35273); no 7-Eleven public confirmation — 🟥 unverified · https://cybernews.com/news/shinyhunters-myteresa-zara-carnival-7eleven-data-leak/ · https://www.techradar.com/pro/security/shinyhunters-exposes-data-on-mytheresa-zara-carnival-7-eleven-over-40-organizations-tied-up-in-new-data-trove-which-will-stay-up-indefinitely · Sources: [Cybernews] · [TechRadar]
Apr 20
ADT
ShinyHunters
5.5M individuals affected (names, phone numbers, physical addresses; partial SSNs and DOBs for subset); vishing attack on ADT employee Okta SSO credentials → attacker pivoted to Salesforce CRM; breach detected April 20, access confirmed revoked April 24; ShinyHunters claimed 10M records; ADT confirmed 5.5M via HIBP notification; ADT filed breach notification and notified law enforcement; Salesforce vector (not Oracle PeopleSoft CVE-2026-35273) · https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/ · https://www.bankinfosecurity.com/home-security-firm-adt-breach-55m-customers-data-exposed-a-31511 · https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack · Sources: [BleepingComputer] · [BankInfoSecurity] · [Rescana]
Apr 20
Citizens Financial Group
Everest
shared statement-printing vendor compromised; 3.4M records (names, home addresses, account numbers, internal document flags; no SSNs confirmed); Everest DLS April 20, 2026; Citizens confirmed third-party vendor breach; class action filed US District Court Providence April 24; 🟨 vendor breach confirmed · https://www.scworld.com/brief/extensive-citizens-financial-group-frost-bank-breaches-claimed-by-everest-ransomware · https://www.americanbanker.com/news/citizens-frost-blame-vendor-after-data-breach-claim · Sources: [SC Media] · [American Banker]
Apr 20
Frost Bank
Everest
same shared vendor as Citizens Financial Group; 250K records incl. SSNs, tax IDs, mortgage rates, income data, home addresses; Everest DLS April 20, 2026; Frost confirmed third-party vendor breach; full data dumped after 6-day deadline; 🟨 vendor breach confirmed · https://www.scworld.com/brief/extensive-citizens-financial-group-frost-bank-breaches-claimed-by-everest-ransomware · https://cybernews.com/security/everest-ransomware-frost-citizens-bank-breach/ · Sources: [SC Media] · [Cybernews]
Apr 19
Cherry Health
Unattributed
Michigan's largest independent federally qualified health center; ransomware attack detected April 19, 2026 causing days-long network outage; preliminary breach notice published June 18, 2026; unauthorized actor accessed and copied patient and staff data; compromised data varies by individual: names, addresses, phone numbers, dates of birth, health insurance ID numbers, patient ID numbers, provider names, service dates, and Social Security numbers; total affected count not yet disclosed (prior incident 2023 affected 184,000); actor unattributed; breach is distinct from the 2023 incident · https://databreaches.net/2026/06/22/cherry-health-provides-preliminary-notice-of-recent-data-breach/ · https://www.hipaajournal.com/ · https://therecord.media/cherry-health-ransomware-michigan · Sources: [DataBreaches.net] · [HIPAA Journal] · [The Record]
Apr 18
Polmed
ShinyHunters
Police Medical Benefits Scheme serving South African Police Service (SAPS) members and their families; 214 GB claimed; 1.7M member records exposed including 68,000 active SAPS employee numbers, home addresses, bank account details, mental health diagnostic codes, and undercover officer designations (creating national security exposure); initial access via password-spray on abandoned SAP consultant account last active 2019 but retaining domain-admin rights; ShinyHunters $1M ransom demand; Polmed board approved R67M emergency response budget (Mandiant IR retainer + credit-protection cover for all members + remediation costs); undercover officer identifiers in the dataset represent the highest-sensitivity element of this breach · https://capetown.today/news/massive-police-data-breach-raises-national-security-alarm-in-south-africa · https://www.itweb.co.za/article/saps-medical-aid-scheme-probes-potential-data-breach/P3gQ2MGA5VNvnRD1 · https://www.malwarebytes.com/blog/news/2026/05/biometrics-diagnoses-and-bank-details-exposed-in-major-healthcare-breach · Sources: [Cape Town Today] · [ITWeb] · [Malwarebytes]
Apr 16
Empower Group
DragonForce
UAE financial services firm; DragonForce DLS claim April 16, 2026; 316.38 GB exfiltrated claimed; data scope unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Apr 16
Standard Bank Group
PrinzEugen
1.2 TB exfiltrated; 1 BTC ransom demanded and refused; Group is South Africa's largest bank by assets; DLS claim April 16; first widely documented Prinz Eugen victim (new Go-based strain analyzed June 20 by ThreatDown) · https://www.bleepingcomputer.com/news/security/new-prinz-eugen-ransomware-prioritizes-recent-files-for-encryption/ · https://www.threatdown.com/blog/prinz-eugen-ransomware-a-deep-dive-into-a-new-go-based-encryptor/ · Sources: [BleepingComputer] · [ThreatDown]
Apr 13
Medtronic
ShinyHunters
global medical device manufacturer; breach April 13–19, 2026 via third-party vendor credential compromise; 3.8M individuals affected (names, contact information, product/service history; scope confirmed per Medtronic's HIPAA breach notification to HHS/OCR); customer notification letters sent July 2, 2026; class action investigation opened; medical devices and patient safety systems confirmed unaffected; 🟨 breach confirmed by Medtronic, group attribution based on ShinyHunters DLS · https://www.securityweek.com/medtronic-discloses-data-breach-impacting-3-8-million-people/ · https://www.hipaajournal.com/medtronic-data-breach-3-8-million/ · https://www.bleepingcomputer.com/news/security/medtronic-discloses-data-breach-impacting-38-million-customers/ · https://therecord.media/medtronic-data-breach-3-million · Sources: [SecurityWeek] · [HIPAA Journal] · [BleepingComputer] · [The Record]
Apr 12
Mytheresa
ShinyHunters
data published post-deadline; Anodot/BigQuery SaaS supply chain vector (same vector as Rockstar Games; not PeopleSoft CVE-2026-35273); no Mytheresa public confirmation — 🟥 unverified · https://cybernews.com/news/shinyhunters-myteresa-zara-carnival-7eleven-data-leak/ · https://www.techradar.com/pro/security/shinyhunters-exposes-data-on-mytheresa-zara-carnival-7-eleven-over-40-organizations-tied-up-in-new-data-trove-which-will-stay-up-indefinitely · Sources: [Cybernews] · [TechRadar]
Apr 12
Marcus & Millichap
ShinyHunters
30M Salesforce records claimed including employee/client PII and internal corporate data; ShinyHunters claimed April 12, 2026; HIBP confirmed; no Marcus & Millichap public statement · https://www.dexpose.io/shinyhunters-target-marcus-millichap-in-major-ransomware-attack/ · https://haveibeenpwned.com/Breach/MarcusMillichap · https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-marcus-and-millichap-inc/ · https://www.breachsense.com/breaches/marcus-and-millichap-data-breach/ · Sources: [DeXpose] · [HIBP] · [HookPhish] · [Breachsense]
Apr 11
Rockstar Games
ShinyHunters
78.6M records claimed (GTA Online/Red Dead Online analytics, internal business metrics); breach April 11 via Anodot (third-party SaaS analytics) → Snowflake; ransom deadline April 14 missed, partial data published; Rockstar confirmed "limited, non-material" information; Snowflake confirmed breach was Anodot credential compromise, not Snowflake infrastructure; SaaS supply chain vector (not PeopleSoft CVE-2026-35273) · https://www.benzinga.com/markets/tech/26/04/51795873/rockstar-games-data-breach-80-million-records-anodot-snowflake · https://www.bitdefender.com/en-us/blog/hotforsecurity/rockstar-games-data-breach · https://www.deepwatch.com/labs/ca-a-26-006-shinyhunters-breaches-rockstar-games-via-third-party-cloud-integration/ · Sources: [Benzinga] · [Bitdefender] · [DeepWatch]
Apr 09
Pitney Bowes
ShinyHunters
8,243,989 unique customer email addresses + names, phone numbers, physical addresses (business customer Salesforce contacts); phishing attack April 8 harvested employee credentials; attacker used credentials to access Salesforce CRM and exfiltrate records; Pitney Bowes confirmed breach, secured environment, notified law enforcement; HIBP confirmed 8.2M records April 27; no SSNs or payment data accessed · https://www.theregister.com/2026/04/28/pitney_bowes_is_the_latest/ · https://www.dexpose.io/shinyhunters-breach-pitney-bowes-inc/ · https://www.teiss.co.uk/news/pitney-bowes-confirms-cyber-intrusion-as-shinyhunters-claims-breach-of-millions-of-records-17436 · Sources: [The Register] · [DeXpose] · [teiss]
Apr 01
Charter Communications
ShinyHunters
40-42M records claimed (13M+ individually confirmed); names, email/physical addresses, phone numbers, subscription plan details, support tickets, CPNI; vishing attack April 1 2026 targeting Microsoft Entra credentials; attacker pivoted to Salesforce CRM; Charter disclosed publicly May 26 one day before ShinyHunters' May 27 ransom deadline; 50GB data published after ransom refusal; Charter disputes CPNI exfiltration, ShinyHunters disputes claim with screenshots; access via Salesforce/Entra (not PeopleSoft CVE-2026-35273); among the largest US telecom breaches on record · https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/ · https://www.techradar.com/pro/security/charter-communications-confirms-data-breach-shinyhunters-blamed-after-threat-to-leak-user-info-online/ · https://www.scworld.com/brief/shinyhunters-extorts-charter-communications-after-data-breach · Sources: [BleepingComputer] · [TechRadar] · [SC Media]
March 2026
Mar 18
Infinite Campus
ShinyHunters
student information system serving 3,200+ school districts and 11M students across 46 US states; Salesforce account vishing attack March 18, 2026; 137,123 unique school staff accounts' data exfiltrated: names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets; Infinite Campus confirmed breach (staff data only; no evidence student databases compromised); HIBP notification June 15, 2026; Salesforce vector (not PeopleSoft CVE-2026-35273) · https://www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/ · https://cybernews.com/cybercrime/shinyhunters-data-infinite-campus-137k-students-exposed/ · https://www.techradar.com/pro/security/11-million-students-possibly-at-risk-after-classroom-software-used-by-millions-hacked · Sources: [BleepingComputer] · [Cybernews] · [TechRadar]
Mar 17
AssuranceAmerica
Unattributed
14-state auto insurer headquartered in Atlanta, GA; employee credential compromise allowed unauthorized access March 17 – June 15, 2026; 6,990,000+ individuals' driver's licence numbers exfiltrated across 14 states; notification letters began July 10, 2026; actor unattributed · https://www.bleepingcomputer.com/ · https://securityaffairs.com/ · https://www.technadu.com/ · Sources: [BleepingComputer] · [SecurityAffairs] · [TechNadu]
Mar 16
Kubota North America Corporation
Unattributed
unauthorized access to HR system files March 16 – April 20, 2026; attackers exfiltrated files containing employee and dependent personal data: names, Social Security numbers, Social Insurance numbers, dates of birth, and taxpayer IDs; attack identified April 30, 2026; breach scope confirmed June 16, 2026; employee notification emails sent June 30, 2026; at minimum 2,237 Texas residents confirmed affected; no operational disruption reported; no ransomware group has claimed responsibility; actor unattributed · https://www.bleepingcomputer.com/news/security/kubota-says-hackers-had-month-long-access-to-network-systems/ · https://www.claimdepot.com/investigations/kubota-data-breach-2026 · Sources: [BleepingComputer] · [ClaimDepot]
Mar 10
CareCloud
Unknown
Unauthorized access to CareCloud AWS environment March 10-16 2026; 3.7 million patients affected (names SSNs DOBs health insurance and medical records); 8-hour network disruption; notified HHS; confirmed 5th-largest healthcare data theft of 2026 · Sources: https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/
Mar 01
Kennedy McLaughlin & Associates
Qilin
Qilin ransomware attack; company confirmed "cyber incident" publicly; data published approximately May 28, 2026; reported to ACSC and OAIC; 🟨 company-confirmed breach · https://www.cyberdaily.au/security/13668-exclusive-accounting-firm-kennedy-mclaughlin-confirms-cyber-incident-following-qilin-ransomware-attack · https://ransomware.live/id/S2VubmVkeSwgTWNMYXVnaGxpbiAmIEFzc29jaWF0ZXNAcWlsaW4= · Sources: [Cyber Daily] · [ransomware.live]
February 2026
Feb 24
Wynn Resorts
ShinyHunters
21,000 employees affected; 800,000+ records claimed including full names, SSNs, dates of birth, email addresses, and phone numbers; unauthorized access identified September 2025; Wynn confirmed breach February 24, 2026; ShinyHunters removed Wynn from DLS after ransom reportedly paid (~22 BTC / ~$1.5M); SEC 8-K filed · https://www.securityweek.com/wynn-resorts-says-21000-employees-affected-by-shinyhunters-hack/ · https://www.bleepingcomputer.com/news/security/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/ · Sources: [SecurityWeek] · [BleepingComputer]
Feb 24
LexisNexis Legal & Professional
FulcrumSec
400,000 cloud user profiles (names, emails, phone numbers, job functions) + 2GB structured data exfiltrated from AWS environment; access via React2Shell vulnerability in unpatched React frontend app; initial access February 24, 2026; 118 .gov users exposed (federal judges, law clerks, DOJ attorneys, SEC staff); disclosed March 2026; LexisNexis characterised the accessed data as "old, non-critical" but acknowledged the intrusion; law enforcement notified · https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/ · https://therecord.media/lexisnexis-says-hackers-accessed-legacy-data · https://www.theregister.com/security/2026/03/04/lexisnexis-legal-professional-confirms-data-breach/4305422 · Sources: [BleepingComputer] · [The Record] · [The Register]
Feb 24
Strategic Education
Unattributed
incident 23–25 Feb 2026
January 2026
Jan 13
Tepco-Group
DireWolf
Egypt-based electronics manufacturing company; DireWolf DLS claim January 13, 2026; ~300 GB exfiltrated claimed; full data publication threatened after ransom deadline; 🟥 unverified · https://www.dexpose.io/direwolf-ransomware-attack-on-tepco-group/ · https://www.redpacketsecurity.com/direwolf-ransomware-victim-tepco-group/ · https://www.hookphish.com/blog/ransomware-group-direwolf-hits-tepco-group/ · Sources: [DeXpose] · [RedPacket Security] · [HookPhish]
September 2025
Sep 11
BerlinerLuft Technology GmbH
Ethics
DLS claim by new group Ethics (debuted Aug 12, 2026); German industrial ventilation and air conditioning systems manufacturer; estimated attack date Sep 2025 · Sources: https://www.ransomlook.io/group/ethics
Sep 11
Holstrom, Block & Parke
Ethics
DLS claim by new group Ethics (debuted Aug 12, 2026); California family law and estate planning firm; one of 3 inaugural victims; estimated attack date Sep 2025 · Sources: https://www.ransomlook.io/group/ethics
May 2025
May 01
Harrods
DragonForce
third UK retailer hit; attack confirmed 1 May 2025, access restricted to contain it · https://www.acronis.com/en/blog/posts/the-harrods-cyberattacks-a-legendary-retailer-becomes-a-target/ · https://www.picussecurity.com/resource/blog/dragonforce-ransomware-attacks-retail-giants · Sources: [Acronis] · [Picus]
April 2025
Apr 30
Co-op
DragonForce
back-office & call-centre disruption; 10,000+ members' personal data exposed · https://www.infosecurity-magazine.com/news/dragonforce-goup-ms-coop-harrods/ · Sources: [Infosecurity]
Apr 22
Marks & Spencer
DragonForce
~£300M profit hit; online orders & payments disrupted for weeks; customer + employee data threatened (Scattered Spider service-desk initial access) · https://www.blackfog.com/marks-and-spencer-ransomware-attack/ · https://www.infosecurity-magazine.com/news/dragonforce-goup-ms-coop-harrods/ · Sources: [BlackFog] · [Infosecurity]