Skip to content

💥 Attack Tracker

Newest first. Most entries are claims listed on actors' leak sites, not confirmed breaches — flagged 🟥 unverified until corroborated. Verify before acting; see Methodology. Colour bands mark each month; each actor links to its battle card.

September 2026

Sep 11 Agencia Estatal de Meteorología (AEMET) Panzer Ransomware · government · Spain Panzer, a newly observed RaaS operation running since Aug 5 2026 with 16-21 claimed victims across 11 countries in its first month, lists Spain's national meteorological agency, claiming roughly 5GB exfiltrated with a 20-21 day publication deadline. No agency confirmation yet; verify before treating as a breach. · Sources: EscudoDigital · Ransomware.live
Sep 10 i2k2 Networks Vexy Ransomware · IT services / cloud hosting · IN New Delhi-based Indian cloud computing, web hosting, managed IT and disaster-recovery provider listed on Vexy's leak site Sep 10; over 100GB claimed exfiltrated, scope reported as employee and user records. Vexy is a newly observed group with only a handful of named victims to date; no vendor statement. 🟥 unverified DLS claim. · Sources: Ransomware.live
Sep 10 General Santos Doctors Hospital Rhysida Ransomware · healthcare · Philippines Rhysida lists a 280-bed Level 3 tertiary hospital in South Cotabato, claiming roughly 3.5M files (2.44TB) exfiltrated including name-tagged diagnostic scans, cancer-center records with PhilHealth IDs, lab quotations with birth dates, and a staff register with PRC license numbers. No hospital confirmation yet; verify before treating as a breach. · Sources: Ransomware.live
Sep 08 Mathspace Unknown Ransomware · Education · Australia Unauthorized access to internal Metabase reporting system (SQLi in unpatched Metabase instance) exposed names, emails, usernames and account metadata for 1,079,819 students, parents and staff across Australia and New Zealand; no passwords, academic records or API credentials taken. Fourth confirmed victim of the same unpatched-Metabase pattern after Framework, Tally and Kilo Code in August. · Sources: https://www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/ · https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
Sep 08 Florida DAVID (Highway Safety and Motor Vehicles) ShinyHunters Extortion · Government · USA ShinyHunters claims access to Florida's DAVID driver/vehicle lookup database via a password-reset flaw compromising DMV-employee and FBI-agent accounts; ~200,000 driver records allegedly pulled by iterating IDs starting around Sep 3. Proof includes a screenshot of Jeffrey Epstein's DMV record. Verify before treating as a confirmed breach — FLHSMV has not confirmed the claim; leak-site deadline set for Sep 11. · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
Sep 08 Veradigm The Gentlemen Ransomware · healthcare technology · US Chicago-based EHR/e-prescribing/practice-management vendor confirms an attacker used compromised third-party vendor credentials to access a specific Veradigm API and download patient data, including Social Security numbers for a subset of customers; no clinical/medical data, network or server compromise. The Gentlemen posted Veradigm to its leak site Sep 5, asserting 3.5M patient records (names, addresses, SSNs, emails, phones) were taken, and set a Sep 11 publication deadline absent ransom negotiation. The access itself is company-confirmed; the 3.5M-record scope is the attacker's own figure. · Sources: BleepingComputer · The Record
Sep 08 GT Distributors Play Ransomware · law enforcement equipment · US Austin, Texas-based national distributor of tactical gear, firearms accessories and uniforms for law enforcement, military and public-safety agencies; listed on Play's leak site Sep 8 claiming internal data theft. Play uses double extortion (no upfront ransom demand in the leak note); data scope and impact unconfirmed. · Sources: RedPacketSecurity
Sep 07 ST Engineering Metaencryptor Ransomware · aerospace & defense · Singapore Singapore-based multinational technology, defence and engineering group (aerospace, smart city, defence and public security segments); Metaencryptor DLS claim Sep 7, 2026; data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.ransomware.live/id/U1QgRW5naW5lZXJpbmdAbWV0YWVuY3J5cHRvcg==
Sep 07 Lightcast Direwolf Ransomware · hr software · US US-based provider of human resources / labor-market analytics software; Direwolf DLS claim Sep 7, 2026; data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/direwolf-ransomware-victim-lightcast/
Sep 07 United Group Vexy Ransomware · conglomerate · India Indian diversified business group (food ingredients, nutraceuticals, industrial machinery, infrastructure, fashion, digital branding, packaging, automotive accessories); Vexy DLS claim Sep 7, 2026; Vexy is a newly emerged group (first seen Sep 2026); data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/vexy-ransomware-ransomware-victim-united-group/
Sep 07 Master Manufacturing Co., Inc. Dark Project Ransomware · manufacturing · US Southern Indiana custom metal stamping, laser cutting, and wire bending manufacturer (founded 1970, IATF 16949 certified); Dark Project claims 36GB exfiltrated, including SQL databases with personal data and technical schematics; data-exfiltration claim, no encryption reported. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/dark-project-ransomware-victim-master-manufacturing-co-inc/
Sep 07 Conde Nast Unknown Ransomware · publishing services · US A dataset of 32,815,767 user records (names, emails, postal addresses, gender, DOB, phone numbers -- no passwords or payment data) listed for sale for $15,000 on a Russian-language cybercrime forum Sep 7, pitched as the full set behind the Dec 2025 WIRED subscriber leak (which itself totaled a fraction of this volume). Ransomnews sampled 5,000 records and found them consistent with genuine Conde Nast account data collected Sep-Oct 2025. Conde Nast has not confirmed the breach or the new sale listing. · Sources: SecurityAffairs · Cybernews
Sep 04 Manchester Airports Group FulcrumSec Ransomware · transportation/airports · UK 8.8M traveller records (email, phone, vehicle reg, postcodes) published Sep 4 after MAG refused ransom; FulcrumSec extracted 86GB compressed / 550GB uncompressed from MAG's Iterable marketing platform using API credentials embedded in publicly visible website JavaScript — no network intrusion required; covers Manchester, London Stansted, and East Midlands airports; parking, lounge, Fast Track, Wi-Fi data; payment-card data not accessed; MAG disclosed Aug 27, FulcrumSec claimed Sep 1, data published Sep 4; UK ICO notified · Sources: https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/ · https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
Sep 04 EDIF S.p.A. Aurora Ransomware · wholesale/electrical equipment · Italy Italian wholesale distributor of electrical equipment, plumbing, and lighting systems; Aurora DLS claim Sep 4, attack estimated Aug 27; exposed data includes system passwords, certified email credentials, customer invoices, tax numbers, shipping records, CCTV configurations, financial databases, and a detailed 2024 financial report; 🟥 DLS claim only; verify before treating as a breach · Sources: https://www.dexpose.io/aurora-targets-italian-wholesale-distributor-edif-s-p-a/ · https://www.redpacketsecurity.com/aurora-ransomware-victim-edif-s-p-a/
Sep 04 Blanco & Etcheverry Gunra Ransomware · law/professional services · Uruguay Uruguayan law firm (~$5M revenue); Gunra DLS claim Sep 4; no data scope or operational impact disclosed; 🟥 DLS claim only; verify before treating as a breach · Sources: https://ransomware.live/id/QmxhbmNvICYgRXRjaGV2ZXJyeUBndW5yYQ== · https://www.redpacketsecurity.com/gunra-ransomware-victim-blanco-etcheverry/
Sep 04 Occidental Gunra Ransomware · insurance · Venezuela Venezuelan insurance company (~$157M revenue); Gunra DLS claim Sep 4; no data scope or operational impact disclosed; 🟥 DLS claim only; verify before treating as a breach · Sources: https://ransomware.live/id/T2NjaWRlbnRhbEBndW5yYQ== · https://www.redpacketsecurity.com/gunra-ransomware-victim-occidental/
Sep 04 Berlin Senate (urban development, transport, environment departments) Rhysida Ransomware · government · DE 5.79 TB / 1.44M files published to dark web after Berlin refused 30 BTC ransom. Data includes critical infrastructure blueprints for Berlin water/power grids, police/LKA files, Bundeswehr documents, federal defense communication plans, CBRN threat assessments, 12,000+ personnel records. Exfiltration Aug 7-12; detection Aug 14; auction countdown ended Sep 4; data dumped Sep 4-5. 13 days before Sep 20 state election. · Sources: https://cybernews.com/news/stolen-berlin-government-files-dumped-on-dark-web-rhysida/ https://www.bankinfosecurity.com/berlin-rejects-rhysida-ransomware-blackmail-a-32731
Sep 03 DiaSorin S.p.A. Settra Ransomware · Healthcare / Diagnostics · Italy Settra DLS claim Sep 3 2026; Italian in vitro diagnostics multinational (EURONEXT Milan: DIA); data scope and volume not disclosed. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/settra-ransomware-attack-on-diasorin-s-p-a/
Sep 03 MedEvolve Settra Ransomware · Healthcare · USA Settra DLS claim Sep 3 2026; US medical billing and practice management software provider; ~820GB exfiltrated; estimated attack date Aug 11 2026. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/settra-ransomware-attack-on-medevolve/
Sep 03 Complete Packaging Solutions Qilin Ransomware · Professional Services · UK Qilin DLS claim Sep 3 2026; UK business services and packaging solutions provider. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/qilin-ransomware-targets-complete-packaging-solutions/
Sep 03 Katten Muchin Rosenman SilentRansomGroup Ransomware · law firm · US Am Law firm claimed by SilentRansomGroup; DLS Sep 3; full-service US law firm; data scope and authenticity unverified. · Sources: https://www.redpacketsecurity.com/silentransomgroup-ransomware-victim-katten-muchin-rosenman/
Sep 03 IDScan.net Unknown Ransomware · technology · US 153M+ US and Canadian driver's license scans (front/back, IR, UV images) offered on dark web via Nexus marketplace. FBI New Orleans field office opened investigation. Krebs traced data to IDScan.net (New Orleans, Louisiana). Nexus site went dark after Krebs reporting. Breach ongoing for over a year per seller claim. Clients include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment. · Sources: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ https://www.securityweek.com/153-million-driver-license-images-offered-on-dark-web/
Sep 02 Greenberg Traurig SilentRansomGroup Ransomware · law firm · US Am Law firm claimed by SilentRansomGroup; DLS Sep 2; data scope and authenticity unverified; threat to publish if no contact made. · Sources: https://www.dexpose.io/silentransomgroup-compromises-greenberg-traurig/
Sep 01 Holland & Knight SilentRansomGroup Ransomware · law firm · US Am Law firm claimed by SilentRansomGroup; DLS Sep 1; data scope and authenticity unverified; threat to publish if no contact. · Sources: https://www.hookphish.com/blog/ransomware-group-silentransomgroup-hits-holland-and-knight/

August 2026

Aug 30 AFSARD Qilin Ransomware · Government · GBR Qilin ransomware DLS claim posted August 30 2026. Organization based in Milton Keynes UK. Attack date not confirmed. · Sources: https://www.hookphish.com/blog/ransomware-group-qilin-hits-afsard/
Aug 29 Bandit Industries Qilin Ransomware · Manufacturing · USA Qilin DLS claim Aug 29, 2026; US industrial equipment manufacturer; scope and data volume unconfirmed · Sources: https://www.ransomware.live/summary/
Aug 29 LAPoco Architects Qilin Ransomware · Professional Services · USA Qilin DLS claim Aug 29, 2026; architecture firm; scope and data volume unconfirmed · Sources: https://www.ransomware.live/summary/
Aug 28 Berlin State Government (Senate Department for Mobility and Environment) Rhysida Ransomware · Government · DEU Rhysida DLS claim Aug 28, 2026: 5.79TB exfiltrated Aug 7-12 from Berlin's Senate Department for Mobility, Transport, Climate Protection and Environment; 80K administrative offence proceedings and 46.5K contracts claimed; 30 BTC ransom demand (approx EUR 2M); Berlin refuses to pay; auction countdown started Aug 28; September 20 Abgeordnetenhaus election context; Interior Senator says election data not affected · Sources: https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
Aug 27 Manchester Airports Group Unknown Ransomware · Transportation / Aviation · UK Cyberattack disclosed Aug 27 on Manchester, Stansted, and East Midlands airports; 8.7M customer records exposed including WiFi registrations, email addresses, phone numbers, vehicle registrations, parking/lounge bookings; payment data and passwords not stored on affected system; ransom demanded but not paid; actor unattributed · Sources: https://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943 · https://cybernews.com/security/manchester-airport-cyber-attack-9-million-wifi-data-breach/
Aug 27 Providence Investments Qilin Ransomware · Financial Services · USA DLS posting Aug 27; no data volume or proof of exfiltration provided; 🟥 unverified claim · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-providence-investments/ · https://ransomware.live/group/qilin
Aug 27 Displaydata Qilin Ransomware · Technology · UK DLS posting Aug 27; UK-based tech company specialising in electronic shelf labels; no data volume or proof of exfiltration provided; 🟥 unverified claim · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-displaydata/ · https://ransomware.live/id/RGlzcGxheWRhdGFAcWlsaW4=
Aug 26 Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) Qilin Ransomware · Government & Defense · USA Qilin posted ATF (atf.gov) to DLS Aug 26. ATF confirmed 'major cybersecurity incident' on a standalone system isolated from enterprise network. DOJ designated it a major incident under federal guidelines. No data samples published by Qilin. Standalone system; eForms and enterprise network unaffected. · Sources: https://cybernews.com/news/qilin-ransomware-bureau-alcohol-tobacco-firearms-atf-cyberattack/
Aug 26 Air International Thermal Systems Qilin Ransomware · Manufacturing · USA Qilin DLS posting Aug 26. Air International Thermal Systems is a US provider of thermal management and HVAC solutions for industrial and defense applications. Unverified DLS claim; no data samples published. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-air-international-thermal-systems/
Aug 26 Metal Conversions Qilin Ransomware · Manufacturing · USA Qilin DLS posting Aug 26. Metal Conversions is a US metals manufacturing company. Unverified DLS claim; no data samples published. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-metal-conversions/
Aug 25 National Kidney Registry Direwolf Ransomware · Healthcare · US Organ donor-recipient matching nonprofit; DLS claim Aug 25. Five healthcare victims for Direwolf in 16 days. 🟥 Unverified DLS claim. · Sources: https://www.ransomware.live/group/direwolf
Aug 25 Johnson City Honda Global Secret Group Ransomware · Automotive · US Car dealership, Tennessee. DLS claim Aug 25. 🟥 Unverified DLS claim. · Sources: https://ransomware.live/
Aug 25 PCA Group Sdn. Bhd. Majinahanashi Ransomware · Unknown · Malaysia Malaysian company. DLS claim Aug 25 by Majinahanashi group. 🟥 Unverified DLS claim. · Sources: https://ransomware.live/
Aug 25 McKesson Corporation ShinyHunters Extortion · Healthcare · USA ShinyHunters claimed theft of 284M patient data records via third-party application compromise; McKesson confirmed the incident in an SEC 8-K and launched investigation; data allegedly includes names, SSNs, DOBs, patient IDs, Medicaid numbers, medical records, medications — 284M is raw record count, unique individual count TBD; claim unverified · Sources: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
Aug 25 Boston Scientific Unknown Ransomware · Healthcare · USA Cyberattack caused global IT disruption; systems supporting order processing and shipment affected; Cork Ireland manufacturing facility workers sent home; investigation by third-party incident response firm ongoing; actor unattributed; timeline for restoration unknown · Sources: https://techcrunch.com/2026/08/26/medical-device-maker-boston-scientific-says-a-cyberattack-is-causing-a-global-disruption-to-its-operations/
Aug 24 Espac The Gentlemen Ransomware · Construction · Chile Chilean construction company; The Gentlemen DLS claim Aug 24 threatening sensitive data exposure · Sources: https://www.dexpose.io/thegentlemen-ransomware-attack-on-espac/
Aug 23 Clear Align Qilin Ransomware · Technology · USA Optical engineering company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-ransomware-attack-on-clear-align/
Aug 23 Difor Qilin Ransomware · Distribution · Chile Chilean distribution/retail company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-ransomware-group-strikes-chilean-company-difor/
Aug 23 Aurore Development S.p.A. Qilin Ransomware · Professional Services · Italy Italian business services company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-targets-aurore-development-s-p-a-in-ransomware-attack/
Aug 22 PenLink Qilin Ransomware · Technology / Surveillance · USA Qilin ransomware DLS claim August 2026; PenLink is a US surveillance technology company providing investigative tools to law enforcement; data scope unconfirmed · Sources: https://www.galaxywarden.com/blog/breach/penlink-qilin-2026-08
Aug 22 Agunsa Qilin Ransomware · Logistics / Port Services · Chile Qilin ransomware DLS claim August 2026; Agunsa is a major Chilean port and logistics services company; data scope unconfirmed · Sources: https://www.galaxywarden.com/blog/breach/agunsa-qilin-2026-08
Aug 22 Thialf The Gentlemen Ransomware · Sports / Entertainment · Netherlands TheGentlemen ransomware DLS claim August 22 2026; Thialf is an international speed skating venue in Heerenveen, Netherlands; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 22 Promatrix The Gentlemen Ransomware · Technology / IT Services · USA TheGentlemen ransomware DLS claim August 22 2026; Promatrix is a US IT services firm; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 22 BOK Financial ShinyHunters Extortion · Financial Services · USA ShinyHunters DLS claim Aug 22 2026; BOK Financial is a major US financial holding company (NASDAQ: BOKF, ~$50B assets, Tulsa OK); ransom deadline August 24; data scope not disclosed; 🟥 unverified DLS claim · Sources: DEXpose · RansomLook
Aug 22 NovoCure ShinyHunters Extortion · Healthcare / Medical Devices · USA ShinyHunters DLS claim Aug 22 2026; NovoCure (NYSE: NVCR) makes Tumor Treating Fields cancer-treatment devices; data scope and deadline not publicly confirmed; 🟥 unverified DLS claim · Sources: RansomLook
Aug 22 Integrated Health Systems CoinbaseCartel Ransomware · Healthcare · USA CoinbaseCartel DLS claim Aug 22 2026; Integrated Health Systems (ihs911.com) is a US healthcare provider; data-theft extortion with 48h contact window, 10-day payment deadline; data scope unconfirmed; 🟥 unverified DLS claim · Sources: DEXpose
Aug 22 RXPE Group CoinbaseCartel Ransomware · Energy · China CoinbaseCartel DLS claim Aug 22 2026; RXPE Group (rxpe.com) is a Chinese energy company; data-theft extortion with 48h contact window, 10-day payment deadline; data scope unconfirmed; 🟥 unverified DLS claim · Sources: DEXpose
Aug 22 Vietnam Electricity (EVNHANOI) Emperador Ransomware · Energy / Utilities · Vietnam Emperador ransomware DLS claim Aug 22 2026; EVNHANOI is Vietnam's Hanoi Electricity Corporation, a state-owned critical infrastructure entity; Emperador is a lower-profile group with limited prior reporting; data scope unconfirmed; 🟥 unverified DLS claim · Sources: RansomLook
Aug 21 NTE Italia Panzer Ransomware · Engineering / Telecommunications · Italy Panzer ransomware DLS claim August 21 2026; NTE Italia is an engineering and telecommunications service provider based in Catanzaro, Italy; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 21 JC Sales Akira Ransomware · Wholesale Distribution · USA Akira ransomware DLS claim August 21 2026; JC Sales is a full-service wholesaler based in Los Angeles; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 21 Apollo Global Management Falcon/Helix/Pink/Redact Ransomware · Financial Services · USA Social engineering attack July 6-10 2026; SSNs, names, DOBs, home addresses compromised from cloud systems; part of wider wave targeting major financial firms including Blackstone, Bridgewater, Bain Capital; disclosed Aug 21 / notified California AG Aug 20 · Sources: https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/
Aug 20 Kingston Technology Everest Ransomware · Technology / Data Storage · USA Everest ransomware DLS claim August 20 2026; 9,438 files / 138.49 GB claimed exfiltrated; data described as APAC-focused (Taiwan, Japan, Korea, Thailand, Vietnam, India, Australia, NZ, Malaysia, Singapore); Kingston said operations unaffected; Kingston manufactures DRAM and flash storage · Sources: https://www.cyberdaily.au/security/14078-exclusive-ram-maker-kingston-technology-investigating-ransomware-claims
Aug 20 Capgemini Engineering Everest Ransomware · Technology / Professional Services · France Everest ransomware DLS listing August 20 2026 against Capgemini Engineering (formerly Altran, global engineering and technology services firm); data scope and impact unconfirmed · Sources: https://cypro.co.uk/insights/cyber-bulletins/everest-ransomware-claims-capgemini-engineering-listing/
Aug 20 Hospital for Sick Children (SickKids) Unknown Ransomware · Healthcare · Canada Employee and job-applicant personal data exposed via vulnerability in unnamed third-party careers website software; clinical systems and patient data not affected; SickKids, Boomerang Health, SickKids Foundation employees and applicants impacted; vendor unnamed suggesting wider supply-chain exposure · Sources: CP24 · BleepingComputer · The Record
Aug 19 Senvest Capital The Gentlemen Ransomware · Financial Services · USA TheGentlemen ransomware group DLS claim Aug 19 2026 against international hedge fund and investment firm; data theft threatened; Senvest manages billions in public equities, private markets, and real estate; no public confirmation from Senvest · Sources: https://www.dexpose.io/thegentlemen-ransomware-targets-senvest-capital/
Aug 19 Babcock Africa The Gentlemen Ransomware · Engineering / Asset Management · South Africa TheGentlemen ransomware DLS claim August 19 2026; Babcock Africa is a major engineering and asset management company serving critical infrastructure and heavy equipment across Africa; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://ransomware.live/id/QmFiY29ja0B0aGVnZW50bGVtZW4=
Aug 18 Zebra Technologies Clop Extortion · Technology / RFID and Barcode Solutions · USA Clop listed Zebra Technologies (ZEBRA.COM; global provider of RFID, barcode, and enterprise mobile computing solutions; ~.6B annual revenue) on its DLS around August 18, 2026, claiming exfiltration of 8TB of sensitive data including critical databases and CAD files, consistent with the PTC Windchill/FlexPLM campaign (CVE-2026-12569). 8TB would be the largest single-organization claim in this campaign. DLS claim — extent of access and veracity unverified. · Sources: https://www.dexpose.io/clop-ransomware-targets-zebra-com-in-major-data-breach/
Aug 18 Logitech ShinyHunters Extortion · Technology / Consumer Electronics · USA ShinyHunters DLS claim August 18 2026 against Logitech and its Streamlabs streaming platform; payment deadline set for August 21; data scope and scale unconfirmed; no public statement from Logitech as of August 21 · Sources: https://www.cyberdaily.au/security/14076-pay-or-leak-shinyhunters-delivers-ultimatum-to-logitech
Aug 18 R&D Machine and Engineering DragonForce Ransomware · Aerospace & Defense · USA DragonForce ransomware group posted R&D Machine and Engineering (rdmachine.com) on its DLS Aug 18; US aerospace and defense manufacturer; sensitive engineering data threatened for release. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/dragonforce-strikes-r-d-machine-and-engineering/
Aug 14 Direction Generale des Finances Publiques (DGFiP) ZeroBytes (individual threat actor) Ransomware · Government / Tax Administration · FRA Hacker using alias ZeroBytes gained access via stolen internal VPN credentials in late June 2026; exfiltrated records of 678,000 individuals and businesses (names, reference income data, tax rates) in first breach (June); second theft (July) took 200,000 land-registry account details. DGFiP confirmed breach Aug 12 after ZeroBytes posted claim publicly. Data exposure creates targeted physical-robbery risk for high-income crypto holders in France given 30 violent wrench attacks in H1 2026. · Sources: https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
Aug 14 Baxter International ShinyHunters Extortion · Healthcare / Medical Technology · USA ShinyHunters DLS claim August 14 2026 against Baxter International; 7.1 million Salesforce records with PII claimed; extortion deadline was August 17; as of August 22 no data has been published · Sources: https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-baxter-international-inc/
Aug 13 D&J Beverage Service Qilin Ransomware · Beverages · US Qilin DLS claim August 13, 2026; scope unconfirmed. · Sources: https://www.ransomware.live/group/qilin
Aug 13 SIA Medical Centre Rhysida Ransomware · Healthcare · AU Rhysida DLS claim August 13, 2026; SIA Medical Centre Melbourne; scope unconfirmed. · Sources: https://www.ransomware.live/group/rhysida
Aug 13 CF Supply Akira Ransomware · Distribution · US Akira DLS claim August 13, 2026; industrial supply distributor; scope unconfirmed. · Sources: https://www.ransomware.live/group/akira
Aug 13 GB Group S.A. DragonForce Ransomware · Unknown · Unknown DragonForce DLS claim August 13, 2026; scope and country unconfirmed. · Sources: https://www.ransomware.live/group/dragonforce
Aug 13 Shell Clop Extortion · Energy · NLD Clop listed Shell on DLS as part of mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed 89GB of engineering drawings, facility scans, test reports and project plans. Shell confirmed it is investigating a potential incident. DLS claim — breach not confirmed. · Sources: https://www.technadu.com/shell-and-philips-confirm-investigation-following-cl0p-data-theft-claims-targeting-nearly-50-companies-including-fiserv-and-ge/633182/
Aug 13 Philips Clop Extortion · Healthcare Technology · NLD Clop listed Philips on DLS in mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed 13.5GB of PDF drawings, diagrams and blueprints. Philips confirmed an investigation is underway. DLS claim — breach not confirmed. · Sources: https://www.technadu.com/shell-and-philips-confirm-investigation-following-cl0p-data-theft-claims-targeting-nearly-50-companies-including-fiserv-and-ge/633182/
Aug 13 General Electric Clop Extortion · Industrial / Aerospace · USA Clop listed GE on DLS as part of mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed engineering data. GE has made no public statement. DLS claim — breach not confirmed. · Sources: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
Aug 12 B Wright Drywall Qilin Ransomware · Construction · CAN DLS claim by Qilin (Aug 11-13 posting); Canadian construction firm; scope and data volume unverified · Sources: https://www.ransomware.live/group/qilin
Aug 12 Fiserv Clop Extortion · Financial Technology · US Clop DLS claim August 12, 2026 against Fiserv (global fintech/payments processor); scope unconfirmed; first appeared in tracker August 14. · Sources: https://www.bleepingcomputer.com/news/security/
Aug 11 Pennsylvania Attorney General's Office Unknown Ransomware · Government · US Ransomware attack struck communications systems; 1,200 staff affected; courts granted case extensions; recovery ongoing August 11 · Sources: https://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery
Aug 11 Stade Français Paris Qilin Ransomware · Sports · FR Qilin DLS August 11, 2026; Aug 15 deadline; player passport/ID data published as proof-of-breach; club filed complaint with French authorities; no payment confirmed. · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-stade-francais/
Aug 11 Otter Tail County INC Ransom Ransomware · Government · USA INC Ransom DLS claim posted August 17, 2026; attack estimated August 11. County government (population ~60,000, west-central Minnesota). Scope unconfirmed. · Sources: https://www.ransomware.live/id/T3R0ZXIgVGFpbCBDb3VudHksIE1pbm5lc290YUBpbmNyYW5zb20=
Aug 10 ATMS & Co. LLP INC Ransom Ransomware · Professional Services · IN Chartered accountant firm; INC_RANSOM DLS posting August 10, 2026; part of INC's SonicWall SMA 1000 exploitation campaign (CVE-2026-15409/CVE-2026-15410 CVSS 10.0); data scope unconfirmed · Sources: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Aug 10 Astro Electroplating Qilin Ransomware · Manufacturing · US Qilin DLS posting August 10, 2026; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10 Chung Tai Shin Chemical Industry Co. Qilin Ransomware · Chemicals · TW Qilin DLS posting August 10, 2026; chemicals and manufacturing sector; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10 AIMS Group The Gentlemen Ransomware · Conglomerate · AE TheGentlemen DLS posting August 10, 2026; UAE-based conglomerate; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10 Canopy Support Services The Gentlemen Ransomware · Nonprofit · CA TheGentlemen DLS posting August 10, 2026; Canadian nonprofit; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10 Actini Group KRYBIT Ransomware · Industrial Machinery · FR KRYBIT ransomware DLS posting August 10, 2026; French industrial machinery manufacturer; data scope unconfirmed · Sources: https://www.redpacketsecurity.com/krybit-ransomware-victim-www-actini-com/
Aug 10 Unlimited Technology Systems Unknown Ransomware · Healthcare Technology · US Ohio-based healthcare revenue cycle management firm; breach Oct 5-10 2025; detected Oct 19 2025; HHS OCR notification filed late July 2026 confirming 3,803,750 individuals affected; SSNs DOBs medical/insurance data stolen; largest healthcare breach of 2026 YTD by victim count · Sources: https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/
Aug 10 Quironsalud Direwolf Ransomware · Healthcare · Spain Spain's largest private hospital group (50+ hospitals, ~13,000 beds). Attack discovered Aug 10; DLS claim Aug 10-11. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/direwolf-ransomware-attack-on-quironsalud-spains-health-giant/
Aug 09 Studio Associato Tibaldi Unknown Ransomware · Professional Services · ITA DLS claim posted August 9 on ransomware.live; Italian professional firm based in Rome; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 09 Siam Oil Product Co. Ltd. Unknown Ransomware · Energy / Petroleum · THA DLS claim posted August 9 on ransomware.live; Thai petroleum and industrial distributor; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 08 Filtronic plc Qilin Ransomware · Manufacturing / Defence Electronics · UK Qilin DLS claim August 8 2026; UK-listed manufacturer of RF/microwave components for defence and telecoms infrastructure; no statement from Filtronic; data scope and impact unconfirmed · Sources: https://www.hendryadrian.com/ransom-filtronic-aug-2026/
Aug 08 Clausing Industrial Qilin Ransomware · Manufacturing / Machine Tools · US Qilin DLS claim August 8 2026; Michigan-based metalworking machinery manufacturer; no statement from Clausing; data scope and impact unconfirmed · Sources: https://www.ransomware.live/group/qilin
Aug 08 CLLS Co Ltd Qilin Ransomware · Unknown · Unknown Qilin DLS claim August 8 2026; sector and country of origin unconfirmed; no victim statement · Sources: https://www.ransomware.live/group/qilin
Aug 08 Louisville Bar Association INC Ransom Ransomware · Legal / Professional Association · US INC Ransom DLS claim August 8 2026; Kentucky-based legal professional association; consistent with INC Ransom sustained 2026 legal-sector campaign; no victim statement; data scope unconfirmed · Sources: https://www.ransomware.live/group/incransom
Aug 08 Daily Trust Unknown Ransomware · Media · NGA DLS claim posted August 8 on ransomware.live; Nigerian national newspaper/news organization; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 07 Levi Strauss Unknown Ransomware · Retail/Apparel · US Social engineering of employee computers; attacker accessed corporate files; consumer data not affected; breach contained · Sources: https://therecord.media/levis-data-breach-social-engineering
Aug 07 IEH Corporation Unknown Ransomware · Defense Manufacturing · US SEC cybersecurity disclosure; producer of components for military satellites, missiles, fighter jets; cyberattack discovered early August, containment actions taken · Sources: https://therecord.media/military-device-manufacturer-discloses-cyber-incident
Aug 07 Stade Français Unknown Ransomware · Sports/Entertainment · France Paris-based Top 14 rugby club; systems restored after cyberattack; data leak under investigation · Sources: https://therecord.media
Aug 07 Morguard Corporation Helix Ransomware · Real Estate · CA Helix ransomware group (emerged July 2026; Microsoft OAuth/SharePoint data exfiltration, no custom malware) posted DLS claim Aug 7; 160GB claimed exfiltrated; negotiations broke down. Helix uses voice phishing and OAuth abuse targeting SharePoint. · Sources: https://ransomware.live/id/TW9yZ3VhcmRASGVsaXg=
Aug 06 Signature Services Play Ransomware · Business Services · US Play ransomware DLS listing, Aug 6 2026; files encrypted, data exfiltrated · Sources: https://ransomware.live/id/U2lnbmF0dXJlIFNlcnZpY2VzQHBsYXk=
Aug 06 TechVentures Bank S.A. RansomHouse Ransomware · Financial Services · Unknown RansomHouse DLS listing Aug 6 2026; double extortion · Sources: https://www.ransomware.live/group/ransomhouse
Aug 05 Allied Telesis Everest Ransomware · Networking / Technology · JPN Everest posted Allied Telesis (global networking solutions provider, Tokyo) on its DLS on August 5 2026; estimated attack date July 17 2026. Group threatened data leak unless demands met. DLS claim — scope unverified. · Sources: https://www.dexpose.io/everest-ransomware-group-targets-allied-telesis/
Aug 05 FIS Global Clop Extortion · Financial Technology / Payment Infrastructure · USA Clop listed FIS Global (one of the world's largest financial technology providers, serving thousands of financial institutions) on its DLS on Aug 5, claiming 874GB of exfiltrated data including project files, CAD files, and Windchill-related engineering data — consistent with the PTC Windchill/FlexPLM campaign (CVE-2026-12569) that also hit Shell, GE, Philips, and Fiserv. FIS has not confirmed breach. DLS claim only — unverified. · Sources: https://malware.news/t/clop-ransomware-targets-fis-global/124620
Aug 04 Trulite Glass and Aluminum Solutions INC Ransomware Ransomware · Manufacturing / Glass and Aluminium · US INC Ransomware DLS claim August 4 2026; US glass and aluminium manufacturer; attack via SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410 CVSS 10.0); no statement from Trulite; data scope unconfirmed · Sources: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Aug 04 BLACKBURN's Physicians Pharmacy Anubis Ransomware · Healthcare / Pharmacy · US Anubis ransomware DLS claim approximately August 3-4 2026; US healthcare pharmacy; no statement from BLACKBURN's; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 04 RUPP Spritzguss Qilin Ransomware · Manufacturing / Plastics · Germany Qilin DLS claim approximately August 4 2026; German plastics injection-moulding manufacturer; no statement from RUPP; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 04 North Carolina Ports (Wilmington, Morehead City, Charlotte Inland Port) Unknown Ransomware · Transportation / Critical Infrastructure · US Cyberattack detected Aug 4; ports operating manually with IT systems partially offline; NC DOIT, USCG, and external forensics engaged; no exfiltration confirmed · Sources: https://therecord.media/cyberattack-north-carolina-ports
Aug 03 Amgen Unknown Ransomware · Pharmaceutical / Biotech · US Unauthorized access to third-party cloud systems detected July 2026; PHI and proprietary company data exfiltrated; Amgen disclosed via SEC 8-K filing approximately August 3; forensic investigation ongoing; no patient count disclosed; no operational disruption reported; no threat actor claimed credit · Sources: https://therecord.media/amgen-hackers-cyberattack-sec https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
Aug 03 Winn-Dixie Anubis Ransomware · Retail / Grocery · US Anubis ransomware DLS claim August 3 2026; major US Southeast grocery chain; no statement from Winn-Dixie; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 03 Cameron Regional Medical Center Anubis Ransomware · Healthcare · US Anubis ransomware DLS claim August 3 2026; regional US medical centre; no statement from Cameron Regional; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 03 Service Electric Qilin Ransomware · Telecommunications · US Qilin DLS claim approximately August 3 2026; US regional telecom; no statement from Service Electric; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 02 Encore Enterprises CRPxO Ransomware · Real Estate · US CRPxO DLS claim August 2 2026; US commercial real estate firm; attacker claims 700 GB exfiltrated. No victim statement; data not yet published. · Sources: https://www.ransomware.live/id/RW5jb3JlIEVudGVycHJpc2VzLCBJbmMuQENSUHhP
Aug 02 ProHealth Medical Group Krybit Ransomware · Healthcare · Singapore Krybit DLS claim August 2: 114 GB of data claimed exfiltrated from Singapore healthcare provider ProHealth Medical Group Pte Ltd (prohealth.sg). Patient and operational data scope unconfirmed; no victim statement. 🟥 DLS claim only. · Sources: https://www.dexpose.io/krybit-ransomware-targets-singapores-prohealth-medical-group/ · https://www.redpacketsecurity.com/krybit-ransomware-victim-www-prohealth-sg/
Aug 02 ProHealth Medical Group Pte Ltd Krybit Ransomware · Healthcare · SGP Krybit ransomware posted DLS claim Aug 2; 114GB data claimed from Singapore primary healthcare provider (11 clinics). Krybit also targeted Actini Group (France) Aug 10. · Sources: https://www.dexpose.io/krybit-ransomware-targets-singapores-prohealth-medical-group/
Aug 01 Philippine Savings Bank The Gentlemen Ransomware · Finance · PH TheGentlemen claim on DLS August 1 2026; separate from January 2026 Qilin listing (different group, independent claim). No statement from PSBank; no data published. · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-philippine-savings-bank/
Aug 01 Sigma Plastics Group Play Ransomware · Manufacturing · US Play DLS claim August 1 2026; major US plastics manufacturer. No victim statement; no data published. · Sources: https://www.redpacketsecurity.com/play-ransomware-victim-sigma-plastics-group/
Aug 01 The Butcher Brothers Play Ransomware · Food Processing · US Play DLS claim August 1 2026; US food processing/distribution. No victim statement; no data published; no data volume disclosed. · Sources: https://www.ransomware.live/id/VGhlIEJ1dGNoZXIgQnJvdGhlcnNAcGxheQ==
Aug 01 Questel SAS ShinyHunters Extortion · Intellectual Property Management · France ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 21M+ Salesforce records plus 147 GB internal corporate data; Questel is a major IP and patent management firm serving global enterprise clients; no statement from Questel; data not yet published · Sources: https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/ https://www.dexpose.io/shinyhunters-breach-questel-sas-french-ip-giant-under-siege/
Aug 01 Alcon Inc. ShinyHunters Extortion · Medical Devices / Ophthalmology · Switzerland ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 25M+ Salesforce records with PII; Alcon is a global ophthalmology medical device and pharmaceutical company; no statement from Alcon; data not yet published · Sources: https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-alcon-inc/ https://www.dexpose.io/shinyhunters-breach-alcon-inc/
Aug 01 Lumenis Ltd. ShinyHunters Extortion · Medical Devices / Laser Systems · Israel ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 1.1M+ customer and employee records plus 176 GB internal corporate data; Lumenis manufactures surgical and aesthetic laser systems; no statement from Lumenis; data not yet published · Sources: https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-lumenis-ltd/ https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/

July 2026

Jul 31 Brinks Home ShinyHunters Extortion · Security Services · US ShinyHunters claims breach via Microsoft Entra vishing attack July 13; detected by Brinks July 20; claimed: 4.9M+ Salesforce records including 1.1M customer contacts, 3.8M customer support chat logs (Cresta), 4000+ employee PII rows; CEO confirmed breach, alarm monitoring unaffected · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/ https://www.theregister.com/security/2026/07/31/the-most-famous-brand-in-physical-security-got-pwned-by-shinyhunters/5281924
Jul 31 Kuveyt Turk / Finansbank / Anadolubank / Turkish Airlines (THY) CRPxO Ransomware · Finance / Aviation · Turkey CRPxO ransomware posted wave of Turkish targets July 31: Kuveyt Turk (0.8 GB), Finansbank (2.3 GB), Anadolubank (0.4 GB), Turkish Airlines/THY (4.2 GB); also claimed Johnson & Johnson, Dogan Holding, Anadolu Sigorta, Hyundai · Sources: https://www.ransomware.live/
Jul 31 Hawaii Family Dental Qilin Ransomware · Healthcare · US Qilin posted Hawaii Family Dental on DLS July 31; dental healthcare provider; Qilin exploiting CVE-2026-0257 (PAN-OS GlobalProtect) as primary initial access; 1358+ cumulative Qilin victims · Sources: https://www.ransomware.live/ https://cybersecuritynews.com/qilin-ransomware-claims-1358-victims/
Jul 31 Hyundai Motor Türkiye CRPxO Ransomware · Automotive / HR Data · Turkey CRPxO DLS claim July 31: 1.5 GB of recruitment and personnel data including interview answers, evaluation scores, and tracking logs. Part of the broader July 31 CRPxO Turkish wave. 🟥 DLS claim only; no victim statement. · Sources: https://gbhackers.com/crpx0-ransomware-claims-hyundai-turkey-breach/amp/ · https://cyberpress.org/crpx0-ransomware-claims-hyundai-turkey-breach/
Jul 31 Southeastern Oklahoma State University Interlock Ransomware · Education · USA Interlock ransomware attack on public university in Durant OK; confidential financial records including unaudited earnings reports and tax files stolen; campus closed 3 days; 42,000 students locked out; DLS claim posted Aug 19 2026 · Sources: https://www.kxii.com/video/2026/08/03/southeastern-oklahoma-state-university-reopen-tuesday-after-cybersecurity-incident/
Jul 30 Indus Protech Solutions The Gentlemen Ransomware · industrial supply chain / MRO · India TheGentlemen DLS claim July 30, 2026; Chennai-based bulk MRO and supply chain services provider for global trade; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-indus-protech-solutions/ · https://www.ransomware.live/
Jul 30 Malaysian Nuclear Agency The Gentlemen Ransomware · government / nuclear research · Malaysia TheGentlemen DLS claim July 30, 2026; Malaysian government nuclear research and technology organisation; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 30 MicroPhase Corporation The Gentlemen Ransomware · defense electronics / IT · US TheGentlemen DLS claim July 30, 2026; US defense electronics and IT company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 30 Kontact Consortium India INC Ransom Ransomware · engineering and manufacturing · India INC_RANSOM DLS claim July 30, 2026; Indian engineering and manufacturing company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 29 StellarRAD Systems Space Bears Ransomware · Technology · US Posted to Space Bears DLS July 29; sector and data scope unconfirmed · Sources: https://www.ransomware.live/
Jul 29 Bretford Manufacturing Aurora Ransomware · Manufacturing · US Posted to Aurora ransomware DLS July 29; data scope unconfirmed · Sources: https://www.ransomware.live/
Jul 29 Administratia Nationala a Penitenciarelor (ANP) Unknown Ransomware · Government · RO Romanian National Prison Administration posted to DLS July 29; group unconfirmed; data scope unknown · Sources: https://www.ransomware.live/
Jul 29 Analog Devices ExfilSquad Ransomware · Technology (Semiconductors) · US Analog Devices filed SEC 8-K disclosing breach detected June 23 2026; ExfilSquad claimed 570,000+ records stolen; ADI says operations unaffected and no evidence data leaked or misused; investigation ongoing · Sources: https://www.securityweek.com/semiconductor-firm-analog-devices-discloses-data-breach/ https://www.bloomberg.com/news/articles/2026-07-29/analog-devices-discloses-data-breach-after-unauthorized-access
Jul 29 Accenture 888 Ransomware · Professional Services / Consulting · US Threat actor 888 (PwnForums) claimed theft of 35 GB including Azure DevOps source code, Azure access keys, tokens, RSA/SSH keys, and config files; Accenture confirmed incident was contained with no operational impact; disclosed approximately July 29 2026 · Sources: https://www.securityweek.com/accenture-confirms-data-breach-after-hacker-claims-source-code-theft/ https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
Jul 29 CEVA Logistics Unknown Ransomware · Logistics/Transportation · NLD Cyberattack on 8 European warehouses (Jul 29 attack, Aug 1 notification); customer data (names, addresses, phones, emails, order data) exposed for clients including Valve/Steam, Ajax, banks, and retailers; Dutch DPA investigating; no ransomware deployed · Sources: https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
Jul 28 Affinia Healthcare Termite Ransomware · Healthcare · US St. Louis multidisciplinary medical system; Termite ransomware DLS posting July 28 2026; class action investigation opened; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://www.redpacketsecurity.com/termite-ransomware-victim-affinia-healthcare/
Jul 28 Swiss Federal IT Office (FOITT/BIT) Unknown Ransomware · Government · CHE SharePoint exploitation chain (CVE-2026-55040 JWT bypass + CVE-2026-56164 EoP); ~200 user and technical accounts compromised; attack detected July 28, external access blocked, passwords reset, servers being rebuilt; no confirmed data exfiltration beyond compromised credentials; attackers described as previously unknown · Sources: https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
Jul 27 MCBS (Medical Computer Business Services) PEAR Ransomware · Healthcare · US Healthcare revenue cycle management firm; 1,261,464 patients exposed across 7 healthcare providers; 3TB data allegedly exfiltrated; 5-day compromise Sep 22-26 2025; not detected until May 28 2026; PEAR operates without encryption (pure extortion) · Sources: https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/
Jul 27 Ernst and Young ShinyHunters Extortion · Professional Services · US Supply-chain compromise of third-party IT service management platform Mar 28-Apr 12 2026; yielded credentials to EY Jira, GitHub, Azure; client tax documents with SSNs and financial data; July 31 2026 deadline issued · Sources: https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
Jul 26 Multiple Minnesota Water and Wastewater Utilities (30+) CyberAv3ngers Ransomware · Critical Infrastructure · US Coordinated OT attack on 30+ community water and wastewater systems including Plymouth, South St. Paul, Braham, and Maple Plain; automated control functions disrupted, some systems switched to manual; no water quality impact reported; MNIT activated statewide incident response; FBI investigating; pattern matches CyberAv3ngers/Iranian ICS tradecraft · Sources: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/ · https://www.securityweek.com/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks/
Jul 26 UK Police National Legal Database (PNLD) ExfilSquad Ransomware · Law Enforcement / Government · UK Attack detected July 26 2026; PNLD confirmed breach; ExfilSquad claims 135,000 contact records of UK police officers, criminal justice staff, and government partners (names, organisations, email addresses); 14 total ExfilSquad victims across 5 countries in this wave; exposure of officers in sensitive investigations is primary concern · Sources: https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/amp/ https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
Jul 26 Wesco International ExfilSquad Ransomware · Technology/Distribution · USA Data extortion group ExfilSquad claims to have exfiltrated 2.6M records from Wesco cloud CRM environment (Jul 26 attack); leaked via torrents Aug 7; customer lists, shipment details, project pricing exposed; Wesco confirmed incident Aug 11; no ransomware encryption · Sources: https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
Jul 25 Traffic Control and Road Safety Services Qilin Ransomware · Government/Transportation · Unknown DLS posting July 25 2026 by Qilin. Sector and country unconfirmed from snippets. · Sources: https://www.ransomware.live/
Jul 25 Guntert & Zimmerman Qilin Ransomware · Manufacturing · DE DLS posting July 25 2026 by Qilin. Guntert & Zimmerman manufactures heavy concrete paving equipment. Country inferred from name. · Sources: https://www.ransomware.live/
Jul 25 Plitvicka Jezera Nacionalni Park Qilin Ransomware · Tourism/Government · HR Plitvice Lakes National Park (Croatia), UNESCO World Heritage Site. DLS posting July 25 2026 by Qilin. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25 Principle Diagnostics Laboratory Qilin Ransomware · Healthcare · Unknown DLS posting July 25 2026 by Qilin. Diagnostic laboratory; sector confirmed, country unconfirmed. · Sources: https://www.ransomware.live/
Jul 25 GURR Abdichtungstechnik GmbH Qilin Ransomware · Construction · DE German waterproofing/sealing technology firm. DLS posting July 25 2026 by Qilin. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25 Yourway Transportation Moneymessage Ransomware · Logistics/Transportation · US DLS posting July 25 2026 by Moneymessage. US transportation company. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25 SistNet Nova Ransomware · IT Services · Unknown DLS posting July 25 2026 by Nova group. IT services firm. Country and data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25 Jubilee Jobs Qilin Ransomware · Business Services/Staffing · Unknown DLS posting July 25 2026 by Qilin. Employment/staffing services firm. Country and data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25 The Myers Y Cooper Qilin Ransomware · Professional Services · Unknown DLS posting July 25 2026 by Qilin. Professional services firm; sector and country unconfirmed from snippets. · Sources: https://www.ransomware.live/
Jul 25 Health Law Advocates INC Ransom Ransomware · legal-nonprofit · US Boston non-profit legal organization; INC Ransom DLS posting July 26 2026, estimated attack date July 25; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://www.ransomware.live/
Jul 25 AnMed Health System Unknown Ransomware · Healthcare · US 79 of 106 facilities closed including oncology, radiation, infusion, and imaging services; 72-hour ransom demand issued; FBI and SLED investigating; class action investigations underway · Sources: https://www.hipaajournal.com/anmed-closes-almost-80-facilities-while-it-grapples-with-cyberattack/ · https://www.healthcareitnews.com/news/anmed-given-72-hours-respond-demands-ransomware-incident
Jul 24 Bank of Baroda Triple X Ransomware · banking · India Triple X DLS claim July 24; ~1 TB data alleged exfiltrated; estimated attack date May 12, 2026; government-owned second-largest public-sector bank in India. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 23 Origin Energy Unattributed Breach · Energy / Utilities · Australia 4.8 million customer records breached; names, addresses, DOBs, phone numbers, partial payment card/bank account details. Company engaged ACSC and Australian Federal Police. · Sources: https://therecord.media/australia-origin-energy-data-breach
Jul 23 Czech Philharmonic The Gentlemen Ransomware · arts/culture · Czech Republic TheGentlemen DLS claim July 23; data volume not yet disclosed; cultural heritage institution based in Prague. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 23 LAXAI Life Sciences Krybit Ransomware · pharmaceutical / CDMO · India Krybit DLS claim July 23, 2026; LAXAI Life Sciences Pvt. Ltd. is a Contract Research, Development, and Manufacturing Organization (CRDMO) based in India; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.dexpose.io/krybit-ransomware-targets-laxai-life-sciences-in-india/ · https://www.cyfirma.com/news/weekly-intelligence-report-31-jul-2026/
Jul 22 Nidec Corporation Blackfield Ransomware · manufacturing · JP Blackfield ransomware group claimed Nidec Corporation (major Japanese manufacturer of electronic components for automotive and computing sectors) on DLS July 22, 2026; M ransom demand; full encryption plus exfiltration model; 🟥 unverified DLS claim only · Sources: https://www.bleepingcomputer.com/
Jul 22 South Korean National Diplomatic Academy Unattributed (suspected DPRK) Ransomware · government · KR South Korean Ministry of Foreign Affairs diplomatic training academy compromised; ~10,000 current and former diplomat records exfiltrated (names, IDs, email, encrypted passwords, job titles, affiliations); dwell time ~9-10 months (Apr/May 2025 – Feb 2026); zero-day + misconfigured security settings; South Korean officials describe exfiltration scope as 'unprecedented'; North Korean link under investigation; 🟨 attribution unverified · Sources: https://therecord.media/south-korea-cyberattack-foreign-ministry
Jul 22 Estee Lauder Clop Extortion · consumer/cosmetics · US Clop exploited Oracle E-Business Suite zero-day CVE-2025-61882 to access EL HR systems (attack Aug 9 2025, discovered Jun 19 2026, disclosed via CA AG filing Jul 22 2026); exposed SSNs, passport numbers, bank account details, health info, payroll and performance data for employees; 24 months Kroll identity monitoring offered · Sources: https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
Jul 22 Recsa Qilin Ransomware · Business Services / Security · South Africa Qilin DLS claim posted Jul 22-23; data leak threatened if no negotiations. Unverified — verify before treating as confirmed breach. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-recsa-in-south-africa/
Jul 22 Ingersoll Rand Everest Ransomware · Industrial Manufacturing / HVAC · US Everest ransomware DLS claim posted August 8 2026, estimated attack date July 22 2026; attribution disputed — separate DeXpose report attributes incident to '0apt ransomware'; Ingersoll Rand has not issued a statement; this is at least their second ransomware-related incident of 2026 (ALP-001 March 2026) · Sources: https://x.com/FalconFeedsio/status/2079991407490851128 · https://www.dexpose.io/0apt-ransomware-attack-targets-ingersoll-rand/
Jul 21 Fairlife (Coca-Cola subsidiary) Anubis Ransomware · food and beverage · US Anubis RaaS (emerged Dec 2024) claimed the July 16 Fairlife ransomware attack on its DLS July 21, 2026; claims ~1TB exfiltrated corporate data with ransom deadline end of week; Coca-Cola confirmed attack via SEC filing (third-party access to Fairlife IT environment); US dairy production suspended; Canadian operations unaffected; 🟥 data scope and exfiltration volume unverified · Sources: BleepingComputer · Cybernews · Coca-Cola SEC filing
Jul 21 Stadler Rail Everest Ransomware · manufacturing · Switzerland Everest data-theft gang breached supplier-shared data-exchange platform; CHF 10M (~2.3M) ransom demand rejected; criminal complaint filed; technical/manufacturing data targeted, no personal data claimed. Stadler refused to pay and terminated the compromised platform July 21-23, 2026. · Sources: https://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/
Jul 20 Advantage Home Health Care The Gentlemen Ransomware · healthcare · US US home healthcare company claimed by The Gentlemen extortion group July 20; no confirmation from organization · Sources: https://www.ransomware.live/
Jul 20 Adventus LockBit Ransomware · IT services · SG Singapore-based IT company claimed on LockBit DLS July 20; no confirmation from organization · Sources: https://www.ransomware.live/ · https://www.breachsense.com/breaches/
Jul 20 Alzone Software Everest Ransomware · software/IT · IN India-based IT and software company claimed on Everest ransomware DLS July 20; no confirmation from organization · Sources: https://www.ransomware.live/ · https://www.breachsense.com/breaches/
Jul 20 Caterpillar Inc. CoinbaseCartel Ransomware · manufacturing · US CoinbaseCartel (pure data-theft/extortion, no encryption; 160+ victims since Sept 2025) claimed Caterpillar Inc. July 20, 2026; initial access via credential reuse from infostealer logs; data scope unconfirmed; 🟥 unverified · Sources: DeXpose · HookPhish
Jul 20 Stroebel Gruppe SafePay Ransomware · manufacturing · Germany SafePay DLS claim July 20, 2026; part of coordinated 7-victim Germany spree on same date; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 20 TimeTEX GmbH SafePay Ransomware · education · Germany German educational supplies company; SafePay DLS claim July 20, 2026; part of coordinated 7-victim Germany spree on same date; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 20 L&A Transport Akira Ransomware · transportation · US US trucking company; Akira DLS claim July 20, 2026; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 20 Brinks Home Unknown Ransomware · Security Services · US Dallas-based alarm and home security firm; unauthorized access detected July 20 2026; company disclosed July 28; outside cybersecurity experts engaged; blackmail threat reported; incident does not involve alarm products or monitoring services; customer data scope not yet disclosed; 🟨 confirmed by company · Sources: https://hoodline.com/2026/07/dallas-alarm-giant-brinks-home-shaken-by-cyber-heist-and-blackmail-threat-6930961/
Jul 19 Eana Qilin Ransomware · telecommunications (satellite/connectivity) · Argentina Qilin DLS posting July 19; data claimed exfiltrated; unverified — no public statement from Eana · Sources: https://www.ransomware.live
Jul 19 Synergy Products Qilin Ransomware · manufacturing (industrial products) · United States Qilin DLS posting July 19; data claimed exfiltrated; unverified — no public statement from Synergy Products · Sources: https://www.ransomware.live
Jul 19 MER-AL Nova Ransomware · manufacturing (automotive components) · Turkey Nova DLS posting July 19; data claimed exfiltrated; unverified — no public statement from MER-AL · Sources: https://www.ransomware.live
Jul 19 Dephub Nova Ransomware · government (transportation/ports authority) · Indonesia Nova DLS posting July 19; Indonesian government transportation and ports authority entity; data claimed exfiltrated; unverified — no public statement from Dephub · Sources: https://www.ransomware.live
Jul 18 Droguería Martorani Qilin Ransomware · healthcare (pharmaceutical distribution) · Argentina Argentine medical and hospital products importer/distributor, Buenos Aires; Qilin DLS claim Jul 18, 2026; founded 1970 by Luis Alberto Martorani; distributes medical equipment nationally; 🟥 unverified · Sources: https://ransomware.live/id/RHJvZ3VlcsOtYSBNYXJ0b3JhbmlAcWlsaW4=
Jul 18 Abbott Laboratories (Exact Sciences) ShinyHunters Extortion · healthcare (medical devices / cancer diagnostics) · US Abbott confirmed Jul 18, 2026 unauthorized access to limited systems in Cancer Diagnostics (Exact Sciences) business; ShinyHunters DLS claim alleges exfil of Microsoft Entra/ServiceNow/SharePoint/Databricks/Coupa data; claims: 30M+ rows customer PII, 1M+ SSNs, 22M+ medical order records, doctor-patient notes, NDAs; DLS deadline extended to Jul 21; ShadowByt3$ claims separate LabCentral portal breach under parallel investigation; Abbott has not confirmed data theft scope; 🟥 unverified · Sources: https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/ · https://cybernews.com/news/abbott-laboratories-breach-shinyhunters/ · https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business
Jul 18 Salina Supply Qilin Ransomware · retail (home improvement/building supplies) · United States Qilin DLS posting July 18; data claimed exfiltrated; unverified — no public statement from Salina Supply · Sources: https://www.ransomware.live
Jul 18 Reatile Group INC Ransom Ransomware · energy (industrial/energy distribution) · South Africa INC Ransom DLS posting July 18; data claimed exfiltrated; unverified — no public statement from Reatile Group · Sources: https://www.ransomware.live
Jul 18 D.MAG New Material Technology INC Ransom Ransomware · manufacturing (advanced materials) · China INC Ransom DLS posting July 18; data claimed exfiltrated; unverified — no public statement from D.MAG · Sources: https://www.ransomware.live
Jul 18 NewNet S.A. DragonForce Ransomware · IT services · CO Colombian IT/business-services company claimed on DragonForce DLS July 18; no confirmation from organization · Sources: https://www.ransomware.live/group/dragonforce
Jul 18 PCL Holding Public Co. Ltd RansomHouse Ransomware · Holding / Diversified · Thailand RansomHouse DLS claim; Thai holding company; estimated attack date July 18 2026; no statement from PCL; data scope unconfirmed · Sources: https://www.ransomlook.io/recent
Jul 17 Acosol Qilin Ransomware · utilities (water) · Spain Spanish public water utility; Qilin DLS claim Jul 17, 2026; company confirmed cyberattack, activated security protocols, warned subscribers personal data including national ID numbers, contract info, and payment methods may be compromised; NIS2-classified critical infrastructure · Sources: https://www.ransomware.live/id/QWNvc29sQHFpbGlu · https://www.hendryadrian.com/acosol-suffers-cyberattack-urges-customers-to-stay-alert/
Jul 17 Cafar Qilin Ransomware · unknown · Argentina Argentine organisation; Qilin DLS claim Jul 17, 2026; cafar.org.ar; sector unconfirmed; 🟥 unverified · Sources: https://ransomware.live/id/Q2FmYXJAcWlsaW4=
Jul 17 Ecopetrol Unattributed Breach · energy (oil and gas) · Colombia Colombia's national oil company; unauthorized access to cloud-based file storage environments of approximately 15 subsidiaries; data from ~3,300 user accounts exfiltrated including financial records, customer data, and internal files; ransomware encryption attempt blocked by existing controls; external actor communicated extortion demands; no data published on leak sites as of July 20; criminal complaint filed with Colombian Attorney General; investigation ongoing with insurers and outside experts · Sources: https://www.prnewswire.com/news-releases/ecopetrol-reports-cybersecurity-incident-302828952.html https://colombiaone.com/2026/07/18/colombia-cyberattack-company-ecopetrol/
Jul 17 Danone Qilin Ransomware · food/beverage manufacturing · FR Qilin DLS claim July 17: 221 GB claimed (91,558 files) including year-end financial summaries, customer account database, NDAs, and quarterly sales reports 2023-2025. Danone has not confirmed; treat as claim only. · Sources: https://cybernews.com/news/danone-evian-silk-international-delight-qilin-ransomware-attack/ · https://www.ransomware.live/group/qilin
Jul 16 Fairlife LLC (Coca-Cola subsidiary) Unattributed Breach · Food & Beverage / Dairy Manufacturing · US Coca-Cola subsidiary Fairlife detected unauthorised third-party access to production-related systems on July 16 2026; ransomware event halted all US dairy production including Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan; Canada operations unaffected; no actor claimed responsibility; no data theft confirmed; investigation ongoing with outside advisors; law enforcement notified · Sources: https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/ · https://www.theregister.com/cyber-crime/2026/07/17/ransomware-curdles-production-at-coca-colas-fairlife-dairy-biz/5274157 · https://www.helpnetsecurity.com/2026/07/17/coca-cola-fairlife-ransomware-attack/
Jul 16 Converting Equipment International Interlock Ransomware · Manufacturing · GB UK-based manufacturing company (converting equipment). Attack date July 16 2026; DLS posting July 2026. Data leaked to Interlock's Worldwide Secrets Blog. · Sources: https://socradar.io/free-tools/ransomware-intelligence/victims/converting-equipment-international-interlock-bc57bbfc
Jul 15 Nihon Kotsu Co., Ltd. AiLock Ransomware · Transportation/Logistics · Japan Malware attack July 11 disrupted taxi dispatch, hire-car reservation, and internal IT systems for Japan's largest taxi and limousine operator; no confirmed data exfiltration as of Jul 15 but investigation ongoing. Claimed on AiLock DLS July 15. · Sources: https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/
Jul 15 Ferrovial AiLock Ransomware · Infrastructure/Construction · Spain Global infrastructure and mobility operator claimed on AiLock DLS July 15; 147 compromised employees and 16 users listed, 106 third-party credentials. No public statement from Ferrovial. · Sources: https://ransomware.live/id/RmVycm92aWFsQEFpTG9jaw==
Jul 15 BRAC The Gentlemen Ransomware · Humanitarian/NGO · Bangladesh World's largest NGO listed on The Gentlemen DLS July 15; no public statement from BRAC. Unverified claim. · Sources: https://www.ransomware.live/group/the-gentlemen
Jul 15 ATCOM Technology DragonForce Ransomware · Telecommunications/Manufacturing · Unknown Telecommunications manufacturer claimed on DragonForce DLS July 15. Country unconfirmed. No public statement. · Sources: https://www.ransomware.live/group/dragonforce
Jul 15 Panasonic Avionics Corporation Coinbasecartel Ransomware · technology (aviation / in-flight entertainment) · US US-based Panasonic subsidiary supplying in-flight entertainment and connectivity systems to commercial airlines; Coinbasecartel DLS claim Jul 15, 2026; claimed data includes employee records, user accounts, third-party credentials, external attack surface; no encryption confirmed — data-theft-first extortion model; 🟥 unverified · Sources: https://ransomware.live/id/UGFuYXNvbmljQWVyb0Bjb2luYmFzZWNhcnRlbA== · https://www.breachsense.com/breaches/panasonic-avionics-data-breach/
Jul 15 Fidelity Services Group Ransomhouse Ransomware · security services · South Africa Southern Africa's largest integrated security solutions provider (guarding, cash management, fire protection, 60+ years); Ransomhouse DLS claim Jul 15, 2026; estimated attack date Jul 12; 🟥 unverified · Sources: https://ransomware.live/id/RmlkZWxpdHkgU2VydmljZXMgR3JvdXBAcmFuc29taG91c2U=
Jul 15 Ernst & Young (EY) Unattributed Breach · professional services (accounting/consulting) · United Kingdom EY disclosed on July 15 that client data was accessed via a compromised third-party IT support platform used for UK client engagements; breach window estimated March-April 2026; exposed data includes client tax records, investment data, and Social Security Numbers for affected individuals; EY notified affected clients directly; investigation ongoing with external forensics; no ransomware group has claimed the breach; attack vector believed to be credential theft at the third-party vendor · Sources: https://www.bleepingcomputer.com/news/security/ey-discloses-data-breach-exposing-client-tax-and-financial-records/
Jul 14 Asimar (Asian Marine Service PCL) DragonForce Ransomware · maritime · Thailand Thailand's leading shipyard claimed on DragonForce DLS July 14; data type and volume unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 14 Momenta DragonForce Ransomware · technology · CN Chinese AI and autonomous-driving company claimed on DragonForce DLS July 14; group claims access to source code, financial documents, and configuration files; unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 14 Sedemi Qilin Ransomware · unknown · Unknown Claimed on Qilin DLS July 14; sector and country unconfirmed · Sources: https://www.ransomware.live/group/qilin
Jul 14 Cedar Crest College NightSpire Ransomware · Education · USA Liberal arts college in Allentown PA listed on NightSpire DLS July 14. Estimated attack date July 13. No public statement from Cedar Crest College. · Sources: https://ransomware.live/group/nightspire
Jul 14 Edison Global Networks Limited DragonForce Ransomware · Technology/MSP · Hong Kong Hong Kong-based IT systems integrator and MSP claimed on DragonForce DLS July 14; internal files alleged exfiltrated. No public statement. · Sources: https://www.hookphish.com/blog/ransomware-group-dragonforce-hits-edison-global-networks-limited/
Jul 13 Allied Plumbing Heating & Cooling Qilin Ransomware · services · US HVAC/plumbing services company claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 13 Access Group International DragonForce Ransomware · business services · US Business services company claimed on DragonForce DLS July 13; data type and volume unconfirmed · Sources: ransomware.live · purpleops.io
Jul 13 Nichirei Corporation RansomHouse Ransomware · Food & Logistics · Japan Ransomware attack disrupted 140 cold-chain distribution centers; impact on KFC Japan (1,300+ restaurants), Aeon, Kura Sushi supply chains. DLS claim posted Jul 22-23; data theft scope unverified. · Sources: https://www.japantimes.co.jp/business/2026/07/22/companies/nichirei-cyberattack-ransomhouse/
Jul 12 Retelit SpA Qilin Ransomware · technology · Italy Italian IT services and telecommunications infrastructure provider claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · undercodenews.com
Jul 12 Carolina Agri-Power Qilin Ransomware · agriculture · US Agricultural equipment dealer claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 12 Century Equities Qilin Ransomware · real estate · US Real estate company claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 11 Alan F. Burke CPA Qilin Ransomware · accounting · US Qilin DLS claim July 11, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 11 Bronken's Distributing Qilin Ransomware · distribution · wholesale/US Qilin DLS claim July 11, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 11 Carita The Gentlemen Ransomware · retail · France French luxury skincare and cosmetics brand claimed on The Gentlemen data leak site July 11; data type and volume unconfirmed; company has not issued a public statement · Sources: ransomware.live · breachsense.com
Jul 11 Nihon Kotsu Unattributed Breach · transportation · JP Japan's largest taxi and chauffeur operator; malware infection via unauthorised external access detected July 11; taxi dispatch, hire car web order/reservation management, and internal IT systems shut down for containment; no data exfiltration confirmed as of July 14; no group has claimed responsibility · Sources: https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/ https://www.scworld.com/brief/japans-largest-taxi-operator-suffers-cyberattack-disrupts-services
Jul 10 The Schuett Companies Qilin Ransomware · real estate · construction/US Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10 Eurodefi Qilin Ransomware · financial services · EU Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10 Sintax Qilin Ransomware · legal services · Belgium Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10 Commune de Castries Payload Ransomware · municipal government · France French municipality (Castries, Hérault); Payload DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/payload · Sources: [ransomware.live]
Jul 10 Robroy Industries Brain Cipher Ransomware · manufacturing · US US manufacturing company; Brain Cipher DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jul 10 Finance Yorkshire CMD Ransomware · financial services · UK UK regional finance provider supporting business growth across Yorkshire and the Humber; CMD DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/cmdorganization · Sources: [ransomware.live]
Jul 10 Envision Unlimited MoneyMessage Ransomware · nonprofit · human services/US Chicago-based nonprofit providing residential, day, and community-based services for adults with intellectual and developmental disabilities; MoneyMessage DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/moneymessage · Sources: [ransomware.live]
Jul 10 Lidl Unattributed Breach · retail · Germany Third-party IT service provider breach; customer data from Lidl online shops in Germany, Belgium, and Netherlands exfiltrated; names, phone numbers, email addresses, dates of birth, customer numbers, and salutations exposed; passwords, billing/delivery addresses, bank details, and payment information potentially compromised; Lidl notified affected customers July 10; Dutch and Belgian data protection authorities notified; forensic investigation ongoing · Sources: BleepingComputer · Help Net Security · SC Media
Jul 09 Inter Power Engineering Qilin Ransomware · electronics manufacturing · Singapore Qilin DLS claim July 9, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 09 IAC International Brain Cipher Ransomware · industrial services · US US industrial services company; Brain Cipher DLS claim July 9, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jul 09 Greene County Government (GA) Incrandom Ransomware · Government · US Greene County Georgia government; county servers taken offline after incident detected July 9 2026; Incrandom DLS posting July 28 2026; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://hoodline.com/2026/07/cyber-scare-knocks-greene-county-computers-offline/
Jul 09 Canadian Armed Forces (forces.gc.ca) Bavaqai Ransomware · Government / Defense · CAN Bavaqai (MedusaLocker/BAVACAI variant) listed the Canadian Armed Forces domain forces.gc.ca on its 'File Manager' DLS on approximately July 9 2026. Some tracker feeds index this under the medusalocker group slug. DLS claim — scope and exfiltrated data not confirmed. · Sources: https://socradar.io/data-breach/forces-medusalocker-ransomware-2026/
Jul 08 Accelirate Inc. Qilin Ransomware · IT services · intelligent automation/US Qilin DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/qilin · Sources: [SharkStriker] · [ransomware.live]
Jul 08 S.J. Louis Construction Qilin Ransomware · construction · US Qilin DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/qilin · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Ample Surveyor Services DragonForce Ransomware · land surveying · professional services/unknown region DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08 HIVE360 DragonForce Ransomware · HR · payroll services/UK DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Dignity Health St. Mary's Medical Center Akira Ransomware · healthcare · hospital/US acute-care hospital (232 beds); Akira DLS claim April 2026; 41 GB claimed including employee passports, SSNs, government IDs, contracts, NDAs; victim notification letters sent July 2026; attack date estimated April 2026; 🟥 unverified — hospital has not issued public statement confirming breach · Sources: [ClassAction.org] · [BleepingComputer]
Jul 08 Wade's Dairy Akira Ransomware · food · dairy manufacturing/US Akira DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/akira · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Aesthetic Surgical Images INC Ransom Ransomware · healthcare · plastic surgery/US INC Ransom DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/incransom · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Printronix Brain Cipher Ransomware · technology · printer-hardware manufacturing/US industrial printer manufacturer; Brain Cipher DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jul 08 PCCC Realty LLC NightSpire Ransomware · real estate · US NightSpire DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/nightspire · Sources: [ransomware.live]
Jul 08 Shanghai Xuerong Biotechnology Co., Ltd. KRYBIT Ransomware · biotechnology · China KRYBIT DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/krybit · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Shelby Manufacturing de México KRYBIT Ransomware · manufacturing · Mexico KRYBIT DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/krybit · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Conway Data Everest Ransomware · IT services · US Everest DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/everest · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Greenbotz Everest Ransomware · services · unknown region Everest DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/everest · Sources: [SharkStriker] · [ransomware.live]
Jul 07 Next Clinics Qilin Ransomware · healthcare · US Qilin DLS claim July 7, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 07 Excalibur Rentals Akira Ransomware · equipment rental · US Akira DLS claim July 7, 2026; 45 GB claimed including employee PII (SSNs, passports), contracts, and customer data; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/akira-ransomware-strikes-excalibur-rentals/ · https://www.ransomware.live/group/akira · Sources: [DeXpose] · [ransomware.live]
Jul 07 RISE Architecture Akira Ransomware · architecture · US Akira DLS claim July 7, 2026; 57 GB claimed including employee PII, client files, financial records, and project documents; data scope unconfirmed; 🟥 unverified · https://www.galaxywarden.com/blog/breach/rise-architecture-akira-2026-07 · https://www.ransomware.live/group/akira · Sources: [GalaxyWarden] · [ransomware.live]
Jul 07 Chisholm, Persson & Ball, PC Akira Ransomware · legal · law firm/US Akira DLS claim July 7, 2026; 45 GB claimed including client passports, visas, SSNs, court files, and police reports; data scope unconfirmed; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-akira-hits-chisholm-persson-and-ball/ · https://www.ransomware.live/group/akira · Sources: [HookPhish] · [ransomware.live]
Jul 07 Mercado Libre The Gentlemen Ransomware · e-commerce · technology/Argentina Latin America's largest e-commerce and fintech platform; The Gentlemen DLS claim July 7, 2026; approximately 118,244 users reportedly affected; company has not issued a public statement; data scope and impact unconfirmed; 🟥 unverified — verify before treating as breach · https://www.escudodigital.com/en/cybersecurity/mercado-libre-hit-by-ransomware-attack.html · https://blog.rankiteo.com/mer1783492030-mercado-libre-ransomware-july-2026/ · https://www.ransomware.live/id/TWVyY2FkbyBMaWJyZUB0aGVnZW50bGVtZW4= · Sources: [EscudoDigital] · [Rankiteo] · [ransomware.live]
Jul 07 YMCA of Western North Carolina Interlock Ransomware · non-profit · community services/US Interlock DLS claim July 7, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · Sources: [ransomware.live]
Jul 06 Precision Steel Services Qilin Ransomware · manufacturing · steel service center/US Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-attack-on-precision-steel-services/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06 Wood Ellis & Wood CPA Qilin Ransomware · professional services · accounting/US Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-attack-on-wood-ellis-wood-cpa/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06 Max Fordham Qilin Ransomware · professional services · building engineering/UK independent building engineering consultancy (MEP/sustainability; clients include museums, schools, housing); Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-targets-max-fordham-in-uk-cyberattack/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06 Grupo Inteca Qilin Ransomware · construction · Mexico Qilin DLS claim July 6, 2026; internal files claimed exfiltrated; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 06 CSEC RATP The Gentlemen Ransomware · services · France The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 06 Arabia Falcon Insurance Company The Gentlemen Ransomware · insurance · Oman The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 06 Ahmet Aydeniz Group APT73 Ransomware · conglomerate · Turkey APT73/Bashe DLS claim July 6, 2026; data scope and impact unconfirmed; APT73 noted for fabricating some high-profile claims — 🟥 unverified pending independent confirmation · https://www.ransomware.live/group/apt73 · Sources: [ransomware.live]
Jul 06 CNW Electronics Pte Ltd Unattributed Breach · manufacturing · electronics/Singapore PEAR DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/pear · Sources: [ransomware.live]
Jul 06 AC Beverage Unattributed Breach · beverage · US PEAR DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/pear · Sources: [ransomware.live]
Jul 06 Apex Agro LLC Genesis Ransomware · agri-chemicals · US Genesis DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/genesis · Sources: [ransomware.live]
Jul 06 Asisken Wallstreet Ransomware · medical assistance · unknown Wallstreet DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/wallstreet · Sources: [ransomware.live]
Jul 04 Sisint Qilin Ransomware · technology · Portugal Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 Sitmatic GmbH Qilin Ransomware · IT services · Germany Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 TQ Financial Services Qilin Ransomware · financial services · unknown Qilin DLS claim July 3–4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 Md Lewis Qilin Ransomware · sector unknown · US Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 Goodwill Manasota Qilin Ransomware · nonprofit · thrift retail/US Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 Chemco Qilin Ransomware · manufacturing · Canada Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 Locati Architects Play Ransomware · architecture · construction/Australia Play DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/play · Sources: [ransomware.live]
Jul 04 Silvestri & Associates Insurance Play Ransomware · financial services · insurance/US Play DLS claim July 4, 2026; data leak threatened; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/play-ransomware-targets-silvestri-associates-insurance/ · Sources: [DeXpose]
Jul 04 US government entity Kairos Ransomware · government · US 2TB of sensitive records exfiltrated including SSNs, fingerprints, financial data, and passport scans; ~$1M (~9.44 BTC) ransom paid July 4, 2026 to prevent publication; victim identity not publicly disclosed; pure data-extortion model — no encryption, no operational disruption; 🟨 payment confirmed, victim identity unconfirmed · https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html · https://securityaffairs.com/194750/security/u-s-government-agency-paid-1m-to-data-extortion-group-kairos.html · Sources: [The Hacker News] · [Security Affairs]
Jul 04 Baraga County Memorial Hospital Wallstreet Ransomware · healthcare · US Baraga County Memorial Hospital in L'Anse, Michigan; Wallstreet DLS claim July 4, 2026; data scope and impact unconfirmed; attack in reduced-staffing US Independence Day holiday window; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04 Edgewood Police Department Wallstreet Ransomware · government · law enforcement/US Edgewood Police Department, Pierce County, Washington; Wallstreet DLS claim July 4, 2026; law enforcement targeting during holiday window; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04 Gold Standard Automotive Wallstreet Ransomware · automotive services · US Wallstreet DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04 Deutsche Bank UnSafe Ransomware · banking · financial services/Germany UnSafe DLS claim July 4–6, 2026; Deutsche Bank is Germany's largest bank by assets; UnSafe is a brand-new group with no established track record or prior leak history; data scope, attack vector, and impact entirely unconfirmed; 🟥 EXTREMELY LOW CONFIDENCE — verify through Deutsche Bank communications only before treating as breach · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 04 Abbott Laboratories (LabCentral) ShadowByt3dollar Ransomware · Healthcare / Medical Devices · USA API exfiltration of LabCentral customer portal from July 4; actor claims CE certificates, manufacturing specs, regulatory documents. Distinct from ShinyHunters Exact Sciences SSO incident (seq 478). Abbott investigating both simultaneously. · Sources: https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/
Jul 03 Prince George County RansomHouse Ransomware · government · US Virginia county systems encrypted June 10 2026; phone, internet, and online payment systems disrupted; 911 unaffected; PII possibly exposed (names, addresses, DOBs, driver's licence numbers, SSNs); credit monitoring offered; FBI Cyber Crimes Division and CISA notified; RansomHouse claims encryption and posted evidence pack; county has not officially confirmed ransomware attribution or data theft; 🟥 unverified · https://www.wric.com/news/local-news/prince-george/county-government-cybersecurity-incident/ · https://www.govtech.com/security/prince-george-county-va-discloses-recent-cyber-attack · https://ransomware.live/id/UHJpbmNlIEdlb3JnZSBDb3VudHlAcmFuc29taG91c2U= · https://www.redpacketsecurity.com/ransomhouse-ransomware-victim-prince-george-county/ · Sources: [WRIC ABC 8News] · [GovTech] · [ransomware.live] · [RedPacket Security]
Jul 03 Oak Park INC Ransom Ransomware · local government · city/US Metro Detroit suburb in Oakland County; INC Ransom DLS claim July 3, 2026; attack estimated July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 City of Acworth, Georgia INC Ransom Ransomware · local government · US suburban Atlanta city northwest of the city; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 Carvalima Transportes INC Ransom Ransomware · transportation-logistics · Portugal road transport and logistics company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 Estrutural Zortéa INC Ransom Ransomware · construction · Brazil Brazilian construction and infrastructure company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 CUI Agency The Gentlemen Ransomware · insurance · US US insurance agency based in Utah; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 03 MakoLab S.A. The Gentlemen Ransomware · IT consulting · Poland Polish IT and digital transformation consultancy providing software development, cloud, and data analytics services; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 03 Shamrock The Gentlemen Ransomware · sector unknown · US The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 03 Ferrum AG Anubis Ransomware · manufacturing · Switzerland one of the largest family-owned manufacturing companies in Switzerland; Anubis DLS claim July 3, 2026; Anubis now totals 91 claimed victims (11 in June alone); data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.ransomlook.io/group/anubis · Sources: [ransomware.live] · [RansomLook]
Jul 02 Dixie Beverage West Qilin Ransomware · beverage distribution · US Qilin DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 02 Pennant Hills Golf Club Qilin Ransomware · hospitality · Australia Qilin DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · https://www.hendryadrian.com/ransom-pennant-hills-golf-club-jul-2026/ · Sources: [ransomware.live] · [hendryadrian.com]
Jul 02 A. Bianchini Ingeniero S.A. LockBit Ransomware · industrial engineering · Spain Spanish industrial engineering company; LockBit DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/lockbit · Sources: [ransomware.live]
Jul 02 AWO Kreisverband Südost e.V. SafePay Ransomware · social welfare non-profit · Germany German social welfare organization; SafePay DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jul 02 DIA179 SafePay Ransomware · architecture · Germany German architecture firm; SafePay DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jul 02 COMHAR WorldLeaks Ransomware · health and human services non-profit · Ireland Irish non-profit providing community mental health, disability, and social services; WorldLeaks DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/worldleaks · Sources: [ransomware.live]
Jul 02 Treet Group of Companies WorldLeaks Ransomware · manufacturing · conglomerate/Pakistan Pakistani conglomerate spanning razor blades (Treet Razors), textiles (Treet Fabrics), and power generation (Liberty Power Tech); WorldLeaks DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ransom-treet-group-of-companies-jul-2026/ · https://www.ransomware.live/group/worldleaks · Sources: [hendryadrian.com] · [ransomware.live]
Jul 02 Service IT WorldLeaks Ransomware · IT services · Brazil Brazilian IT services company; WorldLeaks DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ransom-service-it-jul-2026/ · https://www.ransomware.live/group/worldleaks · Sources: [hendryadrian.com] · [ransomware.live]
Jul 02 Fluke Corporation ShinyHunters Extortion · electronics · test-and-measurement manufacturing/US global manufacturer of electronic test and measurement equipment (subsidiary of Fortive Corporation; >3,000 employees); ShinyHunters DLS claim July 2, 2026 — over 21 million Salesforce records claimed including employee/customer PII; group described failed negotiations with victim before publishing; data scope unconfirmed; no Fluke or Fortive public statement; 🟥 unverified · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-fluke-corporation/ · https://www.ransomware.live/group/shinyhunters · Sources: [RedPacket Security] · [ransomware.live]
Jul 02 Ingram Content Group ShinyHunters Extortion · publishing services · book distribution/US major US book distribution, print-on-demand, and publishing-services company serving thousands of publishers worldwide; ShinyHunters DLS claim July 2, 2026; group alleged failed negotiations with victim; Salesforce data exfiltration claimed; data scope unconfirmed; no public statement from Ingram; 🟥 unverified · https://breachnews.com/breaches/shinyhunters-adds-ingram-content-group-and-fluke-corporation-to-leak-site/ · https://www.hendryadrian.com/ransom-ingram-content-group-inc-jul-2026/ · Sources: [BreachNews] · [hendryadrian.com]
Jul 02 AAI Krybit Ransomware · electronics · manufacturing/Taiwan Krybit DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/krybit · Sources: [ransomware.live]
Jul 02 DISS Krybit Ransomware · medical technology · US Krybit DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/krybit · Sources: [ransomware.live]
Jul 02 Colorado Rehabilitation & Occupational Medicine INC Ransom Ransomware · healthcare · US Colorado-based rehabilitation and occupational medicine practice; INC Ransom DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 02 Tofutown Payload Ransomware · food manufacturing · organic plant-based foods/Germany traditional organic food manufacturer (est. 1981; vegan spreads, tofu, seitan products); Payload DLS claim July 2, 2026 (07:26 UTC); data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/payload · https://www.hendryadrian.com/ransom-tofutown-jul-2026/ · Sources: [ransomware.live] · [hendryadrian.com]
Jul 02 Quest Healthcare Solutions Anubis Ransomware · healthcare · US employee data and internal files claimed exfiltrated; Anubis DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ransom-quest-healthcare-solutions-jul-2026/ · https://www.ransomware.live/group/anubis · Sources: [hendryadrian.com] · [ransomware.live]
Jul 02 Amtivo SETTRA Ransomware · ISO certification · professional services/US ANAB-accredited ISO and management system certification body (formerly Orion, ASR, CMA, Audit3, QSR, ISA in North America); offers ISO 9001, 14001, 27001, 45001 certification and training; SETTRA DLS claim July 1–2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071991911431426416 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jul 02 X-Copper Professional Corporation MoneyMessage Ransomware · legal services · Canada Canadian law firm specialising in traffic ticket defence, minor criminal charges, and licence-related legal matters; MoneyMessage DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ · Sources: [hendryadrian.com]
Jul 02 A. Bianchini LockBit Ransomware · Manufacturing (galvanized steel wire) · Spain Spanish galvanized steel wire manufacturer (abianchini.es, founded 1908) listed on LockBit 5.0 DLS approximately July 2 2026. DLS claim unverified. · Sources: https://ransomware.live/id/YWJpYW5jaGluaS5lc0Bsb2NrYml0NQ==
Jul 02 JS Hotels LockBit Ransomware · Hospitality · Spain Spanish hospitality group (jshotels.com) operating 10 hotel properties in Majorca; listed on LockBit 5.0 DLS approximately July 2 2026. DLS claim unverified. · Sources: https://www.ransomware.live/id/anNob3RlbHMuY29tQGxvY2tiaXQ1
Jul 01 Dennis Waters Rental Properties Qilin Ransomware · real estate · US residential rental property company; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Dynamic Laser Solutions Ltd. Qilin Ransomware · industrial machinery · UK UK-based laser cutting and industrial machinery solutions company; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Laughlin Nunnally Hood & Crum Qilin Ransomware · legal services · US US law firm; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Gies Dienstleistungen LockBit Ransomware · facility management · Germany German facility management and building services company; LockBit 5.0 DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 Refinery Hotel Akira Ransomware · hospitality · hotel/US luxury boutique hotel near Bryant Park (197 rooms, Parker & Quinn restaurant, Refinery Rooftop bar); Akira DLS claim July 1, 2026; 15 GB claimed including employee PII (passports, driver's licenses, SSNs, W-9 forms), guest information, financials, contracts and agreements, and NDAs; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.redpacketsecurity.com/akira-ransomware-victim-refinery-hotel/ · https://www.hookphish.com/blog/ransomware-group-akira-hits-refinery-hotel/ · https://ransomware.live/id/UmVmaW5lcnkgSG90ZWxAYWtpcmE= · Sources: [RedPacket Security] · [HookPhish] · [ransomware.live]
Jul 01 Starpool WorldLeaks Ransomware · wellness · spas/Italy Italian designer and manufacturer of premium wellness cabins, saunas, steam rooms, and hydromassage systems; WorldLeaks DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/worldleaks · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jul 01 B'Laofood Joint Stock Company KRYBIT Ransomware · food manufacturing · Vietnam KRYBIT DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/krybit-ransomware-attack-on-blaofood-joint-stock-company/ · https://www.ransomware.live/id/Ymxhb2Zvb2QuY29tQGtyeWJpdA · Sources: [DeXpose] · [ransomware.live]
Jul 01 Azienda Ospedaliera Moscati Krybit Ransomware · healthcare · Italy Italian public hospital; Krybit DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/krybit · Sources: [ransomware.live]
Jul 01 Roundshield Partners LLP INC Ransom Ransomware · financial services · private equity/UK UK-based private equity firm focused on special situations and credit investments; INC Ransom DLS claim July 1, 2026; 400 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Boyne City The Gentlemen Ransomware · local government · US City of Boyne City, northern Michigan municipality; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 FAC Logistique The Gentlemen Ransomware · logistics · France French logistics company; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 Centre Ophtalmologique d'Ermont The Gentlemen Ransomware · healthcare · ophthalmology/France French ophthalmology centre; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 CTM India Limited motherson INDIA The Gentlemen Ransomware · metalworking · automotive manufacturing/India Motherson Group subsidiary; precision metalworking and automotive component manufacturer; The Gentlemen DLS claim July 1, 2026; estimated attack June 22, 2026; data scope unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-ctm-india-limited-motherson-india/ · https://ransomware.live/id/Q1RNIEluZGlhIExpbWl0ZWQgbW90aGVyc29uIElORElBQHRoZWdlbnRsZW1lbg== · Sources: [RedPacket Security] · [ransomware.live]
Jul 01 Golden State Orthopedic Brain Cipher Ransomware · healthcare · orthopedics/US orthopedic healthcare provider; Brain Cipher DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Digital Dynamics Inc. Brain Cipher Ransomware · technology · US US technology company; Brain Cipher DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 CQCRM Icarus Ransomware · technology · unknown Icarus DLS claim July 1, 2026; 🟥 unverified · https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data · Sources: [Dark Reading]
Jul 01 CBAssociates Icarus Ransomware · professional services · unknown Icarus DLS claim July 1, 2026; 🟥 unverified · https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data · Sources: [Dark Reading]
Jul 01 AeroVision Avionics, Inc. KRYBIT Ransomware · aerospace electronics manufacturing · Taiwan KRYBIT DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/krybit-ransomware-strikes-aerovision-avionics-inc/ · https://www.ransomware.live/group/krybit · Sources: [DeXpose] · [ransomware.live]
Jul 01 DISS Corporation / DISS Analytics KRYBIT Ransomware · analytics · digital solutions/US KRYBIT DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://socradar.io/free-tools/ransomware-intelligence/victims/diss-analytics · https://www.ransomware.live/group/krybit · Sources: [SOCRadar] · [ransomware.live]
Jul 01 City Lumber Company SETTRA Ransomware · building materials · US Tennessee building materials supplier based in Tennessee; SETTRA DLS claim June 30–July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-strikes-city-lumber-company/ · https://x.com/FalconFeedsio/status/2071991911431426416 · Sources: [DeXpose] · [FalconFeeds]
Jul 01 Orion Registrar Inc. SETTRA Ransomware · certification body · professional services/US US-based management system certification registrar; SETTRA DLS claim June 30–July 1, 2026; claimed exposure of sensitive financial documents; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-targets-orion-registrar-inc/ · Sources: [DeXpose]
Jul 01 Nidec Chaun Choung Technology Co., Ltd. Blackfield Ransomware · electronics manufacturing · Taiwan Taiwan-based subsidiary of Japan's Nidec Corporation (global precision motor and electronics manufacturer; Tokyo Stock Exchange Prime Market); Blackfield DLS claim confirmed July 1, 2026 (BleepingComputer); attack date June 22, 2026; $2M ransom demand; 2TB exfiltrated claimed; no Nidec public statement; 🟥 unverified · https://www.bleepingcomputer.com/news/security/blackfield-ransomware-targets-nidec-subsidiary-with-2m-ransom-demand/ · https://www.dexpose.io/ · Sources: [BleepingComputer] · [DeXpose]
Jul 01 Dolrad MedusaLocker Ransomware · services · UAE 69 emails claimed exfiltrated; MedusaLocker DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/medusalocker-ransomware-victim-dolrad/ · https://ransomware.live/id/RG9scmFkQG1lZHVzYWxvY2tlcg== · Sources: [RedPacket Security] · [ransomware.live]
Jul 01 Penticton and District Society for Community Living MedusaLocker Ransomware · nonprofit · disability services/Canada nonprofit organisation providing residential, employment, and social services for adults with developmental disabilities in the Penticton (BC) region; MedusaLocker DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/medusalocker-ransomware-victim-penticton-and-district-society-for-community-living/ · https://ransomware.live/id/UGVudGljdG9uIGFuZCBEaXN0cmljdCBTb2NpZXR5IGZvciBDb21tdW5pdHkgTGl2aW5nQG1lZHVzYWxvY2tlcg== · Sources: [RedPacket Security] · [ransomware.live]
Jul 01 ComTRI GmbH LockBit Ransomware · IT Services · Germany German IT services provider listed on LockBit 5.0 DLS approximately July 1 2026. DLS claim unverified by independent source. · Sources: https://www.ransomware.live/
Jul 01 Hotel de la Bourse LockBit Ransomware · Hospitality · France Hotel in Mulhouse, France (hotel-bourse.com) listed on LockBit 5.0 DLS approximately July 1 2026, discovered July 11 2026. DLS claim unverified. · Sources: https://ransomware.live/id/aG90ZWwtYm91cnNlLmNvbUBsb2NrYml0NQ==
Jul 01 Marquis Software Unknown Ransomware · Financial Services / Software · US Financial software company serving community banks; ransomware attack compromised data for 670,000+ individuals across dozens of bank customers including Artisans Bank and VeraBank; no ransomware group claimed credit publicly (suggesting possible payment); attack date not precisely specified · Sources: https://therecord.media/marquis-bank-vendor-data-breach

June 2026

Jun 30 KALIACT ANCHETA et Associés Qilin Ransomware · legal services · France French legal advisory firm; Qilin DLS June 30, 2026; data scope unconfirmed; 🟥 unverified · https://socradar.io/free-tools/ransomware-intelligence/victims/kaliact-ancheta-et-associs-67e467e9 · https://www.ransomware.live/id/S0FMSUFDVCBBTkNIRVRBIGV0IEFzc29jaXNAcWlsaW4 · Sources: [SOCRadar] · [ransomware.live]
Jun 30 KUNERT Fashion Qilin Ransomware · manufacturing · legwear/Germany German legwear and hosiery manufacturer; Qilin DLS June 30, 2026; data scope unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/qilin-ransomware-victim-kunert-fashion/ · https://www.ransomware.live/group/qilin · Sources: [RedPacket Security] · [ransomware.live]
Jun 30 Chamco Qilin Ransomware · manufacturing · Canada Canadian manufacturing company; Qilin DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jun 30 Western Construction Play Ransomware · construction · US Play DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/V2VzdGVybiBDb25zdHJ1Y3Rpb25AcGxheQ== · Sources: [ransomware.live]
Jun 30 Agroprime DragonForce Ransomware · agricultural technology SaaS · Brazil developer of specialised SaaS software for automating agribusiness management and monitoring field personnel across Brazil; DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/YWdyb3ByaW1lQGRyYWdvbmZvcmNl · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 Hwa Seng Water Resources Biotech Co., Ltd. DragonForce Ransomware · beverage manufacturing · Taiwan DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 Advanced Business Systems Akira Ransomware · office solutions · technology/US regional office technology solutions and managed services provider; Akira DLS claim June 30, 2026; 31 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jun 30 Primed Halberstadt Medizintechnik GmbH Aur0ra Ransomware · medical devices · Germany German manufacturer of medical devices (founded 1946; part of PE-backed PP Medtech group); Aur0ra DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/UHJpbWVkIEhhbGJlcnN0YWR0IE1lZGl6aW50ZWNobmlrQGF1cm9yYQ== · Sources: [ransomware.live]
Jun 30 On-us Gunra Ransomware · technology · US DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/gunra-strikes-on-us-in-new-ransomware-attack/ · Sources: [DeXpose]
Jun 30 Pou Sheng International Holdings The Gentlemen Ransomware · footwear retail · China+Hong Kong China-based athletic footwear retailer and Yue Yuen Group subsidiary; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jun 30 SDEZ The Gentlemen Ransomware · textile services · France historic French family-owned company (est. 1816) specialising in industrial rental and maintenance of professional linen, workwear, and hygiene equipment; national network of industrial laundries across France and Belgium; 700+ employees; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/U0RFWkB0aGVnZW50bGVtZW4= · Sources: [ransomware.live]
Jun 30 Mondottica The Gentlemen Ransomware · fashion · luxury eyewear/Italy global luxury eyewear company specialising in design, production, and worldwide distribution of premium sunglasses and optical frames under licensed brand names; international operations across Europe and APAC; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-mondottica/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30 Melcor Developments Ltd The Gentlemen Ransomware · real estate · construction/Canada diversified real estate developer and asset manager headquartered in Edmonton, Alberta; community development, commercial property, and residential construction across Western Canada; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-melcor-developments-ltd/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30 Indra Group The Gentlemen Ransomware · defense · aerospace/technology/Spain one of Europe's largest defense, aerospace, and technology companies; €5B annual revenue; 62,000 employees; operates in 140+ countries; first Spanish company to join NATO's cyberdefence coalition; provides critical defense systems, air traffic management, space infrastructure, and IT to governments, militaries, and CNI operators worldwide; The Gentlemen DLS claim June 30, 2026; Indra confirmed attack was limited to a non-critical subsidiary environment; CSIRT protocols activated; operations unaffected; data type and volume unknown; data publication deadline July 9, 2026; 🟥 unverified · https://cybernews.com/security/indra-group-ransomware-attack-data-leak/ · https://www.cybersecurity-insiders.com/the-gentleman-ransomware-targets-prominent-european-nato-contractor/ · https://socradar.io/free-tools/ransomware-intelligence/victims/indra-group-9773ee2c · Sources: [Cybernews] · [Cybersecurity Insiders] · [SOCRadar]
Jun 30 PAI Pharma Brain Cipher Ransomware · pharmaceuticals · US Brain Cipher DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jun 30 Boston Orthotics & Prosthetics Anubis Ransomware · healthcare · orthotics-prosthetics/US leading employee-owned orthotics and prosthetics provider with multiple clinic locations across the northeastern US; ANUBIS DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 ESMS Global Anubis Ransomware · healthcare services · UK specialised healthcare services company; ANUBIS DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 Port Angeles Composite LLC CMD Ransomware · aerospace · advanced manufacturing/US structural composite manufacturer headquartered in Port Angeles, WA; produces composite structures for Boeing, Bombardier, and Honda Aircraft Company; acquired by Honda Aircraft Company October 2025; CMD DLS claim June 30, 2026 (~09:52 UTC); data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/group/cmdorganization · Sources: [ransomware.live]
Jun 30 Medlink Georgia CMD Ransomware · healthcare · federally qualified health center/US federally qualified health center providing comprehensive care with sliding-fee scale for uninsured and underinsured patients; CMD DLS claim June 30, 2026; sensitive data threatened for release unless negotiations initiated; data scope and impact unconfirmed; 🟥 unverified — no Medlink Georgia public statement · https://www.dexpose.io/cmdorganization-strikes-medlink-georgia-in-latest-ransomware-attack/ · https://ransomware.live/id/TWVkbGluayBHZW9yZ2lhQGNtZG9yZ2FuaXphdGlvbg== · Sources: [DeXpose] · [ransomware.live]
Jun 30 Aflac Life Insurance Japan Ltd. Scattered Spider Extortion · insurance · Japan unauthorized access June 15–25, 2026; 4.38M customer records exposed (names, addresses, phone numbers; bank account details for ~230K); access vector undisclosed; actor officially unattributed but TTPs consistent with Scattered Spider per industry analysis; Aflac disclosed June 30, 2026; Japan FSA and police notified; no misuse confirmed at disclosure; 🟥 unverified attribution · https://www.securityweek.com/aflac-japan-data-breach-impacts-4-38-million/ · https://www.bleepingcomputer.com/news/security/insurance-giant-aflac-discloses-data-breach-after-subsidiary-hack/ · https://www.japantimes.co.jp/business/2026/06/30/aflac-hack-4-million/ · Sources: [SecurityWeek] · [BleepingComputer] · [Japan Times]
Jun 30 Abans Group BlackNevas Ransomware · financial services · multinational diversified global financial services conglomerate; BlackNevas DLS claim June 30, 2026; estimated attack date June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/QWJhbnMgR3JvdXBAYmxhY2tuZXZhcw== · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 Arkın Group BlackNevas Ransomware · hospitality · casino/Northern Cyprus diversified hospitality and gaming conglomerate in Northern Cyprus (casino resorts, hotels); BlackNevas DLS claim June 30, 2026; 1.4 TB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/blacknevas · https://www.redpacketsecurity.com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 30 Brooklyn Defender Services Genesis Ransomware · legal services · US New York City public defender organization providing legal representation to low-income individuals; Genesis DLS claim June 30, 2026; estimated attack date June 23, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · https://www.redpacketsecurity.com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 30 Owensboro Grain Company SETTRA Ransomware · agriculture · grain processing/US US agricultural business specialising in grain processing and commodity trading; SETTRA DLS claim June 30, 2026; estimated attack date June 19, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-strikes-owensboro-grain-company/ · https://www.redpacketsecurity.com/settra-ransomware-victim-owensborograin-com/ · https://ransomware.live/id/b3dlbnNib3JvZ3JhaW4uY29tQHNldHRyYQ== · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 30 Tour Edge SETTRA Ransomware · sporting goods · golf equipment manufacturing/US US-based golf equipment manufacturer producing irons, woods, hybrids, and wedges across multiple premium lines; SETTRA DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-targets-golf-manufacturer-tour-edge/ · https://www.ransomware.live/group/settra · Sources: [DeXpose] · [ransomware.live]
Jun 30 Ilex Paysages et Urbanisme SETTRA Ransomware · landscape architecture · urban planning/France distinguished French landscape architecture and urban planning firm; SETTRA DLS claim June 30, 2026; estimated attack date June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-attack-targets-ilex-paysages-et-urbanisme/ · https://www.redpacketsecurity.com/settra-ransomware-victim-ilex-paysages-com/ · https://www.ransomware.live/id/aWxleC1wYXlzYWdlcy5jb21Ac2V0dHJh · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 30 Wilfley SETTRA Ransomware · industrial pump manufacturing · US A.R. Wilfley & Sons, manufacturer of centrifugal slurry pumps for mining, chemical, and industrial applications; SETTRA DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/settra · Sources: [ransomware.live]
Jun 30 Petra Diamonds SETTRA Ransomware · diamond mining · UK London-listed diamond mining company operating mines in Tanzania (Williamson) and South Africa (Cullinan, Finsch, Koffiefontein); SETTRA DLS claim June 30, 2026; estimated attack June 24, 2026; claimed "THE DIAMOND ARCHIVE" incl. employee directory; data scope and impact unconfirmed; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-settra-hits-petradiamonds-com/ · https://www.redpacketsecurity.com/settra-ransomware-victim-petradiamonds-com/ · https://x.com/FalconFeedsio/status/2071991911431426416 · Sources: [HookPhish] · [RedPacket Security] · [FalconFeeds]
Jun 30 Joy Construction Corp SETTRA Ransomware · construction · real estate development/US US-based construction and affordable housing developer ($1.3B+ in affordable housing projects; projects in multiple US states); SETTRA DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 30 VCNY Home SETTRA Ransomware · home textiles · consumer goods/US US-based home textiles company (bedding, bath, and decorative products; distributed through major US retail chains); SETTRA DLS claim June 30, 2026; estimated attack date June 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/id/dmNueWhvbWUuY29tQHNldHRyYQ== · Sources: [FalconFeeds] · [ransomware.live]
Jun 30 Cedrick Frank Associates SETTRA Ransomware · professional services · US SETTRA DLS claim June 30, 2026; sector and data scope unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 30 May Trucking Company Embargo Ransomware · logistics · transportation/US family-owned interstate carrier founded 1945, headquartered in Brooks, Oregon; operates dry-van truckload, intermodal, and refrigerated freight services across the continental US; Embargo DLS claim June 30, 2026 (07:59 UTC); 1 TB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/id/d3d3Lm1heXRydWNraW5nLmNvbUBlbWJhcmdv · https://www.redpacketsecurity.com/embargo-ransomware-victim-www-maytrucking-com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 29 Axionlog Qilin Ransomware · logistics · supply chain/unknown region Qilin DLS claim June 29, 2026; sector and data scope unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 29 NASCO Qilin Ransomware · healthcare technology · US NASCO provides Blue Cross Blue Shield plan administrative data processing for multiple BCBS plans nationwide; Qilin DLS claim June 29, 2026; data scope unconfirmed; 🟥 unverified — verify before treating as a breach · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 29 Bristol Place Corporation Qilin Ransomware · healthcare services · US family-owned healthcare services organization; Qilin DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/QnJpc3RvbCBQbGFjZUBxaWxpbg== · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 29 Musashino University Qilin Ransomware · education · Japan Qilin DLS claim June 29, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.redpacketsecurity.com/qilin-ransomware-victim-musashino-university/ · Sources: [RedPacket Security]
Jun 29 STNI Co., Ltd. DragonForce Ransomware · virtual technology · South Korea DragonForce DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/dragonforce-strikes-south-korean-virtual-tech-innovator-stni-co-ltd/ · https://www.ransomware.live/group/dragonforce · Sources: [DeXpose] · [ransomware.live]
Jun 29 Bonacio Construction RansomHouse Ransomware · construction · real estate development/US full-service construction and real estate development company specialising in commercial and residential projects in upstate New York (Bonacio Steel fabrication division); RansomHouse DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/Qm9uYWNpb0ByYW5zb21ob3VzZQ== · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 29 Nissan North America ShinyHunters Extortion · automotive · US+Canada+Mexico+Brazil 53,000+ current and former employees across four countries; data includes SSNs (US), Social Insurance Numbers (Canada), payroll records, banking/direct-deposit details, W-2/tax data, and dependent/beneficiary info; Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) attack window May 27–June 9, 2026; Nissan activated IR and engaged external cybersecurity specialists; notified law enforcement; multi-country regulatory exposure under US state notification laws, Canada PIPEDA, Mexico LFPDPPP, and Brazil LGPD · https://www.theregister.com/security/2026/06/29/nissan-says-oracle-peoplesoft-break-in-may-have-spilled-payroll-records-ssns/5263534 · https://www.scworld.com/brief/nissan-confirms-employee-data-exposed-in-oracle-peoplesoft-cyberattack · https://www.infosecurity-magazine.com/news/employees-social-security-nissan/ · Sources: [The Register] · [SC Media] · [Infosecurity Magazine]
Jun 29 GDN AR INC Ransom Ransomware · grocery · food retail/Argentina Argentine grocery store operator headquartered in Ciudad Autónoma de Buenos Aires; INC Ransom DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/R0ROIEFSKERvcmlua2EpQGluY3JhbnNvbQ · Sources: [ransomware.live]
Jun 29 Clínica La Sabana Payload Ransomware · healthcare · clinic/Colombia Colombian medical clinic; Payload DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.breachsense.com/breaches/2026/june/ · https://www.ransomware.live/group/payload · Sources: [Breachsense] · [ransomware.live]
Jun 29 Canopy Brands SETTRA Ransomware · consumer goods · US SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/Y2Fub3B5YnJhbmRzLnVzQHNldHRyYQ== · https://x.com/FalconFeedsio/status/2070588706558550063 · Sources: [ransomware.live] · [FalconFeeds]
Jun 29 Total Monitoring Services Inc. SETTRA Ransomware · security monitoring services · Canada SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 29 Doosan SETTRA Ransomware · industrial conglomerate · South Korea Doosan Group (heavy industry, power, construction equipment, hydrogen); SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 29 HMC Farms SETTRA Ransomware · agriculture · Canada SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 29 DyStar Group SETTRA Ransomware · specialty chemicals · textile dyes/global leading global manufacturer of specialty chemicals, reactive dyes, and textile process chemicals serving the apparel, home textiles, and technical textiles industries; SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 29 Quality Dining Inc. SETTRA Ransomware · food services · restaurant operator/US one of the largest US Burger King and Chili's franchise operators (Indiana-based); SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/settra · Sources: [ransomware.live]
Jun 29 Virginia Glass Products SETTRA Ransomware · glass manufacturing · US SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/dmEtZ2xhc3MuY29tQHNldHRyYQ== · Sources: [ransomware.live]
Jun 28 1-800-Dentist Qilin Ransomware · consumer services · dental referral/US US national dental referral and appointment-scheduling service (connects patients with 25,000+ dentist offices nationwide); Qilin DLS claim June 28, 2026; estimated attack date June 28; data scope and impact unconfirmed; 🟥 unverified — verify before treating as a breach · https://www.redpacketsecurity.com/qilin-ransomware-victim-1-800-dentist/ · https://www.ransomware.live/id/MS04MDAtZGVudGlzdEBxaWxpbg== · Sources: [RedPacket Security] · [ransomware.live]
Jun 28 TransCore Qilin Ransomware · transportation technology · ITS/US nationwide electronic toll collection and intelligent transportation systems provider (~$420M revenue, 2,068 employees; ST Engineering subsidiary; serves 8 of 10 largest US tolling agencies and provides traffic management systems worldwide); Qilin DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 28 Higuchi Inc. Stormous Ransomware · manufacturing · Japan Japanese industrial manufacturer; full financial statements including balance sheets and asset records exfiltrated; Stormous DLS claim June 28, 2026; data scope confirmed via ransomware.live indexed entry · https://www.hookphish.com/blog/ransomware-group-stormous-hits-higuchi-inc-co-jp/ · https://socradar.io/free-tools/ransomware-intelligence/victims/higuchi-inc-co-jp-fb4252a8 · Sources: [HookPhish] · [SOCRadar]
Jun 28 HIGUCHI USA, INC. Stormous Ransomware · manufacturing · US US subsidiary of Higuchi Inc. with offices in Dallas, Hong Kong, and Los Angeles; corporate financial and operational data exfiltrated; Stormous DLS claim June 28, 2026; 🟥 unverified — no independent victim statement · https://ransomware.live/id/SElHVUNISSBVU0EsIElOQ0BzdG9ybW91cw== · Sources: [ransomware.live]
Jun 28 EOGB Energy Products Ltd Stormous Ransomware · industrial machinery · energy products/UK leading UK manufacturer and distributor of oil, gas, and dual-fuel burners (14kW to 45MW), based in St Neots, Cambridgeshire; attackers gained deep access to Microsoft Dynamics GP containing complete corporate accounting, invoices, vendor details, and internal legal and partnership documents; Stormous DLS claim June 28, 2026; 🟥 unverified — no EOGB statement · https://ransomware.live/id/ZW9nYi5jby51a0BzdG9ybW91cw== · Sources: [ransomware.live]
Jun 28 ESHA Research/ESHA Cloud Services Stormous Ransomware · food · nutrition software/US food and beverage nutrition database and regulatory compliance software company (Salem, Oregon); core product development databases allegedly accessed; Stormous DLS claim June 28, 2026; 🟥 unverified — no vendor statement · https://www.hookphish.com/blog/ransomware-group-stormous-hits-eshacloudqa-com/ · https://socradar.io/free-tools/ransomware-intelligence/victims/eshacloudqa-com-352c7808 · Sources: [HookPhish] · [SOCRadar]
Jun 28 Monoprix.tn Stormous Ransomware · retail · Tunisia Tunisian supermarket and retail chain (monoprix.tn); Stormous DLS claim June 28, 2026; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/id/bW9ub3ByaXgudG5Ac3Rvcm1vdXM · Sources: [ransomware.live]
Jun 28 Thyssenkrupp Marine Systems (TKMS) GmbH / Atlas Elektronik The Gentlemen Ransomware · defense electronics · Germany TKMS is Germany's principal naval shipbuilding group; Atlas Elektronik is its naval electronics subsidiary (HQ Bremen), specialising in submarine sonar systems, acoustic measurement, and heavyweight torpedo guidance for the German Navy and allied export customers; The Gentlemen DLS claim June 28, 2026; estimated attack date June 25, 2026; data scope unconfirmed; 🟥 unverified — no TKMS or Atlas Elektronik public statement · https://www.ransomware.live/id/VGh5c3NlbmtydXBwIE1hcmluZSBTeXN0ZW1zIChUS01TKSBHbWJIIC8gQXRsYXMgRWxla3Ryb25pa0B0aGVnZW50bGVtZW4= · https://www.ransomware.live/summary/ · Sources: [ransomware.live] · [ransomware.live summary]
Jun 28 Ford Motor Company Mexico KRYBIT Ransomware · automotive manufacturing · Mexico Mexican subsidiary of Ford Motor Company; KRYBIT DLS claim June 28, 2026; estimated attack June 28, 2026; data scope and impact unconfirmed; 🟥 unverified — no Ford Mexico public statement · https://www.ransomware.live/id/Zm9yZC5teEBrcnliaXQ · https://socradar.io/free-tools/ransomware-intelligence/victims/ford-mx-906485b3 · Sources: [ransomware.live] · [SOCRadar]
Jun 28 FCCI Insurance Group REDACT Ransomware · insurance · financial services/US specialty commercial insurance company; REDACT DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/redact · https://www.redpacketsecurity.com/redact-ransomware-victim-fcci-insurance-group/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 28 Hologic, Inc. REDACT Ransomware · medical devices · healthcare technology/US global medical technology company (~$4B revenue; breast health, diagnostics, GYN surgical products); REDACT DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/redact-ransomware-victim-hologic/ · Sources: [RedPacket Security]
Jun 28 Turbo Data Systems SETTRA Ransomware · technology · data broker/US data aggregation and consumer intelligence company; SETTRA DLS claim June 28, 2026; estimated attack June 17, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/settra · https://www.redpacketsecurity.com/settra-ransomware-victim-turbodata-com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 28 Conduril Engenharia S.A. SETTRA Ransomware · civil engineering · construction/Portugal major Portuguese civil infrastructure contractor; SETTRA DLS claim June 28, 2026; estimated attack June 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/Y29uZHVyaWwucHRAc2V0dHJh · https://socradar.io/free-tools/ransomware-intelligence/victims/conduril-pt-b8d0b1d8 · Sources: [ransomware.live] · [SOCRadar]
Jun 28 LifeVantage Corporation SETTRA Ransomware · health and wellness supplements · US publicly traded direct-sales nutritional supplement company (NASDAQ: LFVN); SETTRA DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-hits-lifevantage-corporation/ · https://ransomware.live/id/bGlmZXZhbnRhZ2UuY29tQHNldHRyYQ== · Sources: [DeXpose] · [ransomware.live]
Jun 28 PChome Online Inc. SETTRA Ransomware · e-commerce · Taiwan one of Taiwan's largest online retail and e-commerce platforms; breach estimated June 10, 2026 via infostealer malware compromising employee and customer accounts; 35,000+ users and employees' credentials and personal data exposed; SETTRA DLS claim June 28, 2026; 🟥 unverified — no PChome public statement · https://www.dexpose.io/settra-ransomware-attack-on-pchome-online-inc/ · https://www.galaxywarden.com/blog/breach/pchome-settra-ransomware-june-2026 · https://socradar.io/free-tools/ransomware-intelligence/victims/pchome-com-tw-bcdbab3d · Sources: [DeXpose] · [GalaxyWarden] · [SOCRadar]
Jun 28 KDDI Corporation Unattributed Breach · telecommunications · Japan Japan's second-largest mobile carrier; 14.22 million email subscriber accounts compromised across six ISPs managed by KDDI (Chuokai, Johoku Communications, KCN Kyoto, Okayama Information Highway, Sanin Godo Bank Net, Tokai Broadband); root cause: vulnerability in third-party email management software; email subscriber account records (addresses, associated metadata) affected; KDDI confirmed breach and began customer notifications June 24-28, 2026; actor unattributed · https://therecord.media/ · https://www.securityweek.com/ · Sources: [The Record] · [SecurityWeek]
Jun 27 Kuhnline Play Ransomware · construction · Germany Play DLS claim June 27, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/S3VobmxpbmVAcGxheQ== · https://www.facebook.com/CyberNewsLive/photos/play-claims-to-have-targeted-kuhnline-kuhnlinecom-a-construction-company-this-re/1349093380535328/ · Sources: [ransomware.live] · [Cyber News Live]
Jun 27 hellmold-plank.de SafePay Ransomware · manufacturing · Germany long-established German manufacturer (roots to 1904); SafePay DLS claim June 27, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jun 27 Aptora DragonForce Ransomware · software · SaaS/field service management/US field service management platform used by contractors and service businesses; DragonForce DLS claim June 27, 2026; attackers allege databases of 100+ Aptora client companies exfiltrated; data scope unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · Sources: [ransomware.live]
Jun 26 Tokyo Civil Co., Ltd. SafePay Ransomware · civil engineering · construction/Japan public infrastructure specialist (river works, bridges, foundation engineering, water supply systems, government-related construction; established 2020; Edogawa City, Tokyo); SafePay DLS claim June 26, 2026; internal org data, employee info, and operational files claimed; 🟥 unverified — no Tokyo Civil statement · https://www.cyfirma.com/news/weekly-intelligence-report-26-jun-2026/ · https://www.ransomware.live/group/safepay · Sources: [CYFIRMA] · [ransomware.live]
Jun 26 Precise Forms, Inc. Akira Ransomware · manufacturing · aluminum forms/US aluminum forming products manufacturer; Akira DLS claim June 26, 2026; ~10 GB claimed; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/akira-ransomware-strikes-precise-forms-inc/ · https://www.ransomware.live/group/akira · Sources: [DeXpose] · [ransomware.live]
Jun 26 NSW Rural Fire Service Nova Ransomware · government · emergency services/Australia New South Wales Rural Fire Service; Nova DLS claim June 26, 2026; 300 GB claimed; RFS confirmed the breach June 24 but stated emergency operations were unaffected; no evidence of operational impact · https://www.cyberdaily.au/security/13817-exclusive-nova-ransomware-group-takes-responsibility-for-nsw-rfs-hack · https://www.ransomware.live/group/nova · Sources: [Cyber Daily] · [ransomware.live]
Jun 26 VSL Marine Technology Pvt. Ltd. Nova Ransomware · marine engineering · 3D scanning/India marine technology and underwater survey services provider; Nova DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/nova-ransomware-attack-targets-vsl-marine-technology-pvt-ltd/ · https://www.ransomware.live/group/nova · Sources: [DeXpose] · [ransomware.live]
Jun 26 callhorton.com INC Ransom Ransomware · legal services · US personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26 johndufourlaw.com INC Ransom Ransomware · legal services · US personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26 Life Bridges INC Ransom Ransomware · non-profit · social services/US non-profit organisation supporting individuals with intellectual and developmental disabilities; INC Ransom DLS claim June 25-26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/incransom-targets-life-bridges-non-profit-in-ransomware-attack/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 26 Salters Propane SpaceBears Ransomware · energy · propane distribution/US propane fuel distributor; SpaceBears DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/ · https://www.hendryadrian.com/ · Sources: [RedPacket Security] · [hendryadrian.com]
Jun 26 Ingerman Chaos Ransomware · multifamily housing · real estate/US multifamily developer and property management company; Chaos DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/chaos-strikes-ingerman-in-ransomware-attack/ · https://www.redpacketsecurity.com/chaos-ransomware-victim-ingerman-com/ · Sources: [DeXpose] · [RedPacket Security]
Jun 26 911 Driving School PrinzEugen Ransomware · education · driving instruction/US national driving school chain; PrinzEugen DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 26 Mosaic Partners Payload Ransomware · IT services · Switzerland Swiss IT services provider specialising in software development, systems engineering, CRM, cloud computing, and process management solutions; Payload DLS claim June 26, 2026; sensitive data publication threatened unless negotiations begin; 🟥 unverified — no victim statement · https://www.dexpose.io/payload-ransomware-attack-on-mosaic-partners/ · https://www.redpacketsecurity.com/payload-ransomware-victim-mosaic-partners/ · https://www.ransomware.live/id/TW9zYWljIFBhcnRuZXJzQHBheWxvYWQ= · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 26 Software Arge Payload Ransomware · technology · data analytics/Turkey Turkish enterprise data analytics and cloud platform company (founded 2016; cloud analytics, data visualisation, integration and management solutions for enterprise clients); Payload DLS claim June 26, 2026; sensitive data publication threatened unless negotiations initiated; 🟥 unverified — no victim statement · https://www.dexpose.io/payload-ransomware-strikes-software-arge/ · https://www.redpacketsecurity.com/payload-ransomware-victim-software-arge/ · Sources: [DeXpose] · [RedPacket Security]
Jun 26 Payload Corporation Payload Ransomware · fintech · payments/US B2B automated payment processing platform serving real estate, legal, insurance, and SaaS sectors (founded 2019; co-founders Ian Halpern and Ryan Rybolt); Payload DLS claim June 26, 2026; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.dexpose.io/payload-ransomware-breach-at-payload-corporation/ · https://www.ransomware.live/group/payload · Sources: [DeXpose] · [ransomware.live]
Jun 26 Nachlass Nord Anubis Ransomware · sector unknown · Germany Anubis/Booba joint DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 26 Clearview Eye Centre Interlock Ransomware · healthcare · ophthalmology/Canada ophthalmic clinic and eye care centre; Interlock DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · https://www.dexpose.io/interlock-ransomware-attack-on-clearview-eye-centre/ · Sources: [ransomware.live] · [DeXpose]
Jun 26 MagMutual Insurance Company LeakNet Ransomware · insurance · US mutual insurance company focused on healthcare professionals; LeakNet DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 26 Policía de Turismo KRYBIT Ransomware · government · law enforcement/Dominican Republic Dominican Republic tourist police force; KRYBIT DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 26 Hokua Suites AiLock Ransomware · real estate · luxury residential condominium/US upscale resort-style ocean-view residential condominium on the Oahu coast; AiLock DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ailock-ransomware-group-attacks-hokua-luxury-condominiums/ · https://www.redpacketsecurity.com/ailock-ransomware-victim-hokua/ · https://www.ransomware.live/id/SG9rdWFAQWlMb2Nr · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 25 ISOPLUS Qilin Ransomware · pharmaceuticals · Greece Greek pharmaceutical company; Qilin DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.dexpose.io/qilin-ransomware-targets-greek-pharma-leader-isoplus/ · https://www.hendryadrian.com/ransom-isoplus-jun-2026/ · Sources: [DeXpose] · [hendryadrian.com]
Jun 25 JMS Southeast Akira Ransomware · business services · industrial distribution/US temperature measurement and control products distributor (thermocouples, RTDs, thermowells, transmitters); Akira DLS claim June 25, 2026; ~25 GB claimed including employee PII (names/addresses), payment data, NDAs, project contracts, agreements with government entities, and customer information · https://www.redpacketsecurity.com/akira-ransomware-victim-jms-southeast/ · https://malware.news/t/akira-ransomware-attack-targets-jms-southeast/108233 · Sources: [RedPacket Security] · [malware.news]
Jun 25 Padget Technologies Akira Ransomware · manufacturing · robotics-automation/US robotics and automation company specialising in engineered machinery, assembly solutions, and robotic palletizing cells; Akira DLS claim June 25, 2026; data upload pending, includes employee records (government IDs, tax forms), payment details, and NDAs · https://www.redpacketsecurity.com/akira-ransomware-victim-padget-technologies/ · https://malware.news/t/akira-ransomware-targets-padget-technologies/108234 · Sources: [RedPacket Security] · [malware.news]
Jun 25 San Silvestre School Krybit Ransomware · education · Peru 148.75 GB claimed; 🟥 unverified — possible re-listing of prior Qilin-targeted school; treat as claimed only pending victim statement · https://x.com/FalconFeedsio/status/2070123961552371874 · Sources: [FalconFeeds]
Jun 25 impulso-store.com Stormous Ransomware · e-commerce · Italy Italian online retail platform; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25 Au Vieux Campeur The Gentlemen Ransomware · outdoor equipment retail · France French outdoor gear chain (24 stores, 180,000+ members); company confirmed cyberattack June 2, 2026 and mobilised incident response; DLS claim appeared June 25 after 23-day negotiation window closed without ransom payment; data scope unconfirmed · https://frenchbreaches.com/alertes/au-vieux-campeur-mq5ponk61juevh4e5fj · https://www.cyberattaque.org/au-vieux-campeur-victime-dune-cyberattaque-une-enquete-est-en-cours/ · https://www.ransomware.live/ · Sources: [FrenchBreaches] · [Cyberattaque.org] · [ransomware.live]
Jun 25 Al-Dhow The Gentlemen Ransomware · diversified business group · Kuwait Kuwaiti multi-sector business conglomerate; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25 Gegenbauer Elektrotechnik & IT The Gentlemen Ransomware · electrical engineering · IT services/Austria Austrian electrical engineering and IT services company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25 BDS CZ The Gentlemen Ransomware · real estate · Czech Republic Czech real estate agency; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25 Bell Hardware The Gentlemen Ransomware · commercial hardware · US family-owned commercial hardware company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25 Beran Concrete, Inc. The Gentlemen Ransomware · construction · building materials/US concrete construction and materials company; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25 I-SYS AuditTeam Ransomware · IT services · Russia Russian IT and systems integration company; AuditTeam DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25 Delegal Poindexter & Underkofler, P.A. Morpheus Ransomware · legal · employment law/US employment law firm; Morpheus DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-morpheus-hits-delegal-poindexter-and-underkofler-p-a/ · https://www.dexpose.io/morpheus-ransomware-targets-delegal-poindexter-underkofler-p-a/ · Sources: [HookPhish] · [DeXpose]
Jun 25 Frosty Acres Brands Booba Ransomware · foodservice · food distribution cooperative/US US-based national foodservice cooperative and purchasing organisation (member-owned, c.5,000+ restaurants and foodservice operators); Booba DLS claim June 25, 2026; data scope unconfirmed; group warned full data leak unless negotiations initiated; no victim statement · https://www.dexpose.io/booba-ransomware-strikes-frosty-acres-brands/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 24 Cash Canada Qilin Ransomware · financial services · Canada DLS claim June 24, 2026; data scope and impact unconfirmed · https://www.redpacketsecurity.com/qilin-ransomware-victim-cash-canada/ · https://www.ransomware.live/group/qilin · Sources: [RedPacket Security] · [ransomware.live]
Jun 24 Miami Machine Inc. Akira Ransomware · manufacturing · US DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 24 JIT-EX LLC Akira Ransomware · transportation · trucking-logistics/US regional and local truckload carrier (dedicated fleets, crossdock, transloading, storage trailer services); ~40GB claimed; includes employee SSNs, W-9 forms, driver's license documents, passport copies, and credit card details · https://www.redpacketsecurity.com/akira-ransomware-victim-jit-ex/ · https://www.ransomware.live/group/akira · Sources: [RedPacket Security] · [ransomware.live]
Jun 24 Adapt ShinyHunters Extortion · sector unknown · US ShinyHunters DLS claim June 24, 2026; final warning issued with data-leak deadline June 25, 2026 midnight NY time; data volume and type unconfirmed; no victim statement; 🟥 unverified · https://www.dexpose.io/shinyhunters-launches-ransomware-attack-on-adapt/ · Sources: [DeXpose]
Jun 24 Alexandria Nova Ransomware · telecommunications · unknown region teleinfrastructure platform; DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/ · Sources: [ransomware.live]
Jun 24 LP Group Nova Ransomware · construction · real estate/unknown region completed ~1 million sq metres of projects; DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/ · Sources: [ransomware.live]
Jun 24 Transvill SRL Nova Ransomware · transportation-logistics · Peru national and international road transport and cargo logistics; DLS claim June 24, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.redpacketsecurity.com/nova-ransomware-victim-transvill-com-pe/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 24 montechiaro-store.com Stormous Ransomware · consumer services · e-commerce/unknown DLS claim June 24, 2026; "complete customer and buyer data" claimed; scope unconfirmed · https://www.redpacketsecurity.com/stormous-ransomware-victim-montechiaro-store-com/ · Sources: [RedPacket Security]
Jun 24 mlit.com.my Stormous Ransomware · government · public sector/Malaysia DLS claim June 24, 2026; full 10GB data dump claimed including "highly sensitive internal information and financial records"; scope unconfirmed · https://www.redpacketsecurity.com/stormous-ransomware-victim-mlit-com-my-update-full-data-dump-new-link-10gb/ · Sources: [RedPacket Security]
Jun 24 lorenzoni-store.com Stormous Ransomware · fashion · knitwear retail/Italy Lorenzoni brand of Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969; Italian family-run knitwear manufacturer with three brands: Lorenzoni, Montechiaro, Impulso); DLS claim June 24, 2026; "complete data" belonging to customers and buyers claimed; part of the same parent-company incident as montechiaro-store.com (June 24) and impulso-store.com (June 25) · https://www.redpacketsecurity.com/stormous-ransomware-victim-lorenzoni-store-com/ · https://x.com/FalconFeedsio/status/2069899152281207018 · Sources: [RedPacket Security] · [FalconFeeds]
Jun 24 maglificioliliana.com Stormous Ransomware · textile · knitwear manufacturing/Italy parent company Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969, Montichiari; specialises in high-quality knitwear, operates three brands: Lorenzoni, Montechiaro, Impulso); 400+ GB of sensitive data claimed exfiltrated, including product designs, orders, and customer and operational records; DLS claim June 24, 2026; scope of all four brand/domain listings suggests a full-group compromise · https://www.hookphish.com/blog/ransomware-group-stormous-hits-maglificioliliana-com/ · https://x.com/FalconFeedsio/status/2069899152281207018 · Sources: [HookPhish] · [FalconFeeds]
Jun 24 Stadttheater Giessen The Gentlemen Ransomware · arts · culture/Germany municipal theatre serving the city of Giessen in the Mittelhessen region; publicly funded civic cultural venue; The Gentlemen DLS claim June 24, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-stadttheater-giessen/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 24 Quest Health Solutions Anubis Ransomware · healthcare · US 239 GB of sensitive operational data claimed exfiltrated including employee data, internal files, and additional undisclosed materials; Anubis announced attack June 24, 2026, and threatened to publish data within 2-3 days; Go-based malware with dual-threat encryption and wipe model; Quest Health Solutions has not issued a public statement · https://www.dexpose.io/anubis-ransomware-group-targets-quest-health-solutions/ · https://www.hookphish.com/blog/ransomware-group-anubis-hits-quest-health-solutions/ · https://www.ransomware.live/id/UXVlc3QgSGVhbHRoIFNvbHV0aW9uc0BhbnViaXM · Sources: [DeXpose] · [HookPhish] · [ransomware.live]
Jun 24 Sapporo Holdings Unattributed Breach · food and beverage · Japan Sapporo Holdings Ltd. disclosed June 24, 2026 that two overseas subsidiaries sustained suspected unauthorized access: Pokka Corporation Singapore (regional food and beverage company) and Sleeman Breweries (Canadian craft brewer); suspicious network activity detected, affected systems shut down pending investigation; no confirmed data exfiltration as of initial disclosure; no confirmed domestic (Japan) impact; actor unattributed; part of broader wave of cyberattacks against Japanese multinationals in June 2026 (alongside Aflac Japan, KDDI, Nidec) · https://therecord.media/japan-cyber-breaches-aflac-sapporo-nidec-kddi · https://www.ppln.co/en/post/japan-cyber-incidents-june-2026-eng · Sources: [The Record] · [Pipeline.co]
Jun 23 Lee International Qilin Ransomware · sector · US DLS claim June 23, 2026; data scope and impact unconfirmed; no Qilin proof sample or ransom demand publicly published · https://www.redpacketsecurity.com/qilin-ransomware-victim-lee-international/ · https://www.ransomware.live/group/qilin · Sources: [RedPacket Security] · [ransomware.live]
Jun 23 Leo International Akira Ransomware · supply chain · PVF/HVAC/plumbing products/US https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 23 IH Engineers, P.C. Akira Ransomware · engineering consulting · US https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 23 Nike, Inc. WorldLeaks Ransomware · consumer goods · US 1.4TB claimed; 188,347 files alleged to include R&D technical packs, bill-of-materials (BoMs), product prototypes, manufacturing schematics, and internal documents; WorldLeaks DLS claim June 23, 2026; full data dump published live; Nike confirmed it is investigating the incident and has engaged external cybersecurity experts; scope and authenticity not independently verified; 🟨 breach under investigation · https://www.infosecurity-magazine.com/news/worldleaks-ransomware-14tb-nike/ · https://www.darkreading.com/cyberattacks-data-breaches/worldeaks-extortion-group-stole-1-4tb-nike-data · https://www.computing.co.uk/news/2026/security/nike-confirms-investigation-of-1-4tb-nike-data · Sources: [Infosecurity Magazine] · [Dark Reading] · [Computing]
Jun 23 FTL-Fast Transit Line Nova Ransomware · transportation-logistics · Belgium Belgian logistics company; DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.dexpose.io/nova-ransomware-targets-ftl-fast-transit-line/ · https://www.ransomware.live/group/nova · Sources: [DeXpose] · [ransomware.live]
Jun 23 Aerospace & Advanced Composites GmbH Aur0ra Ransomware · aerospace manufacturing · Austria https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23 Belpointe Asset Management INC Ransom Ransomware · financial advisory · investment/US https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23 Horizon Eye Care INC Ransom Ransomware · healthcare · ophthalmology/US comprehensive eye exam and corrective-vision services provider (LASIK, cataract, contact lens, designer eyewear); DLS claim June 23; data scope and impact unconfirmed; no Horizon Eye Care statement · https://www.redpacketsecurity.com/incransom-ransomware-victim-horizoneye-com/ · https://www.ransomware.live/group/incransom · Sources: [RedPacket Security] · [ransomware.live]
Jun 23 Randa Apparel & Accessories Chaos Ransomware · apparel · fashion/US global apparel and accessories manufacturer (Dockers, Tommy Hilfiger, PGA TOUR licensed brands); DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.dexpose.io/chaos-ransomware-strikes-randa-apparel-accessories/ · https://www.ransomware.live/group/chaos · Sources: [DeXpose] · [ransomware.live]
Jun 23 (Jun 22-23 DLS batch: 15 new victims claimed past 24h incl. healthcare×3, hospitality, manufacturing, transportation The Gentlemen Ransomware · individual org names not yet enumerated in public feeds; to be split as sources firm up) · — https://purple-ops.io/blog/gentlemen-ransomware-victims · Sources: [PurpleOps]
Jun 23 Canada Wide Media The Gentlemen Ransomware · media · Canada https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23 GIA Partners LLC The Gentlemen Ransomware · financial services · US https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23 OneTrust Icarus Ransomware · governance risk and compliance software · US Salesforce CRM data · https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ · Sources: [SecurityWeek]
Jun 23 Global Message Services Icarus Ransomware · communications technology · Switzerland Salesforce-related data exfiltrated and compressed; new Icarus DLS posting June 23 (distinct from Klue supply-chain victims) · https://www.redpacketsecurity.com/icarus-ransomware-victim-gms-net/ · https://www.ransomware.live/group/Icarus · Sources: [RedPacket Security] · [ransomware.live]
Jun 23 LastPass Icarus Ransomware · password management · cybersecurity/US customer names, phone numbers, email addresses, physical addresses, and Salesforce support-case data accessed via Klue OAuth integration; vaults and core product infrastructure unaffected; LastPass disabled Klue access, rotated OAuth tokens, notified law enforcement; 12th confirmed downstream Klue supply-chain victim · https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/ · https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/ · https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response · Sources: [BleepingComputer] · [TechCrunch] · [LastPass Blog]
Jun 23 Reynella East College Interlock Ransomware · education · Australia all IT systems offline; 1,900+ students and staff at risk; school disclosed breach June 9 in letter to parents; Interlock DLS claim posted June 23; investigation ongoing, data exposure unconfirmed · https://www.cyberdaily.au/security/13731-parents-warned-after-cyber-security-breach-at-south-australia-s-reynella-east-college · https://www.ransomware.live/ · Sources: [Cyber Daily] · [ransomware.live]
Jun 23 Gov.br APT73 Ransomware · government · digital infrastructure/Brazil official state digital platform and domain zone of the Brazilian Federal Government claimed on DLS; impact scope unconfirmed; APT73 previously targeted siapenet.gov.br (April 2026) · https://www.blackfog.com/cybersecurity-101/apt73-ransomware-group/ · https://www.ransomware.live/group/apt73 · https://www.redpacketsecurity.com/apt73-ransomware-victim-www-siapenet-gov-br/ · Sources: [BlackFog] · [ransomware.live] · [RedPacket Security]
Jun 23 KliknKlik.com APT73 Ransomware · retail · computer equipment/Indonesia online retailer and distributor of computer hardware; APT73 DLS claim June 23; data exposure scope unconfirmed; APT73 (aka Bashe) noted for fabricating some high-profile claims — treat as 🟥 unverified pending confirmation · https://www.ransomware.live/group/apt73 · https://www.dexpose.io/apt73-bashe-ransomware-attack-on-medika-plaza/ · https://www.cloudsek.com/blog/unmasking-media-hungry-ransomware-groups-bashe-apt73 · Sources: [ransomware.live] · [DeXpose] · [CloudSEK]
Jun 23 Flughafen Wien AG APT73 Ransomware · aviation · transportation/Austria Austria's largest airport; APT73/Bashe DLS claim June 23, 2026; group alleges 500,000+ emails and 4,473 files exfiltrated including cargo manifests and weapons-transport records; airport confirmed targeted attack but stated incident was limited and did not affect flight operations; published documents described as outdated fragments posing no operational risk; no widespread encryption occurred — 🟥 unverified: airport disputes scope · https://www.dexpose.io/apt73-bashe-targets-vienna-airport-in-ransomware-attack/ · https://aviation.direct/erpressergruppe-bashe-mutmasslicher-cyberangriffs-auf-die-flughafen-wien-ag/ · Sources: [DeXpose] · [Aviation.Direct]
Jun 23 Coldstat Refrigeration CMD Ransomware · refrigeration services · US refrigeration installation and maintenance for commercial clients (restaurants, retail chains, cafes); DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.ransomware.live/id/Q29sZHN0YXQgUmVmcmlnZXJhdGlvbkBjbWRvcmdhbml6YXRpb24= · Sources: [ransomware.live]
Jun 23 AYA Bank Lapsus$ Ransomware · banking · financial services/Myanmar claimed full dump of main banking platform + customer PII; Lapsus$ stated data will be sold on dark markets if ransom not paid; AYA Bank has not issued a public statement; 🟥 unverified — treat as claimed only · https://www.ransomware.live/id/QVlBIEJBTktAbGFwc3VzJA · https://www.redpacketsecurity.com/lapsus-ransomware-victim-aya-bank/ · https://www.hookphish.com/blog/ransomware-group-lapsus-hits-aya-bank/ · Sources: [ransomware.live] · [RedPacket Security] · [HookPhish]
Jun 22 Central Bank of Libya Qilin Ransomware · banking · central bank/Libya ransomware confirmed; SWIFT payment system components targeted; virtual infrastructure and internal systems hit; CBL isolated affected systems June 22; investigations ongoing; no confirmed customer data breach or correspondent bank data exposure · https://www.ransomware.live/id/Q2VudHJhbCBCYW5rIG9mIExpYnlhQHFpbGlu · https://libyaobserver.ly/news/cbl-cyberattack-contained-investigations-ongoing-no-signs-impact-customer-accounts · Sources: [ransomware.live] · [Libya Observer]
Jun 22 NationsBuilders Insurance Services Aur0ra Ransomware · insurance · US US-based specialty insurance risk management firm offering surplus and specialty lines coverage; Aur0ra DLS claim June 22, 2026; over 2.7 million file-tree entries compromised claimed; data scope and victim statement not confirmed · https://www.dexpose.io/aurora-ransomware-attack-on-nationsbuilders-insurance-services/ · Sources: [DeXpose]
Jun 22 NTP B.V. Civil Engineering Construction Aur0ra Ransomware · civil engineering · Netherlands Dutch civil engineering contractor (road building, cable laying, sewers, ground works; HQ Hattem, Gelderland; ~150-200 employees; offices in Hattem, Enschede, Zevenaar); Aur0ra DLS claim June 22, 2026; file server contents claimed including 10+ years of operations, HR/payroll exports, employee personal files, network device configurations, project bids, and financial records; data scope and victim confirmation pending · https://www.dexpose.io/aurora-ransomware-targets-ntp-b-v-civil-engineering/ · https://www.ransomware.live/id/TlRQIEIuVi4gQ2l2aWwgRW5naW5lZXJpbmcgQ29uc3RydWN0aW9uQGF1cm9yYQ · https://www.redpacketsecurity.com/aurora-ransomware-victim-ntp-b-v-civil-engineering-construction/ · Sources: [DeXpose] · [ransomware.live] · [RedPacket Security]
Jun 22 Hooke Laboratories The Gentlemen Ransomware · biotechnology · US preclinical contract research supplier specialising in autoimmune disease model kits (Hooke Kits) used by academic and pharma research laboratories; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-hooke-laboratories/ · https://www.ransomware.live/id/SG9va2UgTGFib3JhdG9yaWVzQHRoZWdlbnRsZW1lbg== · https://www.breachsense.com/breaches/hooke-laboratories-data-breach/ · Sources: [RedPacket Security] · [ransomware.live] · [Breachsense]
Jun 22 Royal Thai Navy Housing Cooperative The Gentlemen Ransomware · public sector · housing cooperative/Thailand cooperative managing housing projects, financial services, and welfare programs for Royal Thai Navy personnel and their families; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-royal-thai-navy-housing-cooperative/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 22 Klue Icarus Ransomware · market intelligence · Canada OAuth integration credential compromised June 11-12; malicious code pushed to harvest customer OAuth tokens; Salesforce integrations revoked June 12; CrowdStrike engaged for IR · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [SecurityWeek] · [BleepingComputer]
Jun 22 Huntress Icarus Ransomware · cybersecurity · US Salesforce CRM data exfiltrated (business contacts, pricing, sales comms, opportunity notes); no threat data/passwords/engineering data affected · https://www.huntress.com/blog/klue-breach-investigation · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · Sources: [Huntress] · [SecurityWeek]
Jun 22 Recorded Future Icarus Ransomware · cybersecurity · US client contact names, email addresses, potential contract info · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · Sources: [SecurityWeek]
Jun 22 Tanium Icarus Ransomware · cybersecurity · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 Jamf Icarus Ransomware · IT management · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 HackerOne Icarus Ransomware · cybersecurity · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 Snyk Icarus Ransomware · cybersecurity · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 Kudelski Security Icarus Ransomware · cybersecurity · Switzerland Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 Insurity Icarus Ransomware · insurance software · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 Gong Icarus Ransomware · sales intelligence · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 Sprout Social Icarus Ransomware · social media management software · US Salesforce CRM data accessed through Klue OAuth integration · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ · Sources: [BleepingComputer]
Jun 22 HDS Corp Icarus Ransomware · wholesale distribution · US HD Supply Holdings; Icarus DLS claim June 22, 2026; exfiltrated compressed Salesforce data claimed via Klue supply chain OAuth token compromise; 🟥 unverified — no HD Supply public confirmation · https://www.dexpose.io/icarus-ransomware-attack-on-hds-corp/ · https://www.ransomware.live/group/icarus · Sources: [DeXpose] · [ransomware.live]
Jun 22 KTR Real Estate Advisors Anubis Ransomware · financial services · real estate advisory/US client database claimed; attack est. 2026-06-19 · https://www.dexpose.io/anubis-ransomware-group-strikes-ktr-real-estate-advisors/ · https://www.redpacketsecurity.com/anubis-ransomware-victim-ktr-real-estate-advisors/ · Sources: [DeXpose] · [RedPacket Security]
Jun 22 Xsolis, Inc. Unattributed Breach · healthcare technology (utilization management · revenue cycle)/US 1,396,519 individuals; names, DOB, addresses, SSNs, health insurance info, medical treatment data; phishing attack January 20, 2026, detected January 22; actor unattributed · https://www.securityweek.com/xsolis-data-breach-affects-1-4-million-individuals/ · https://www.hipaajournal.com/xsolis-data-breach/ · https://databreaches.net/2026/06/22/xsolis-breach-affected-1396519-of-its-clients-patients/ · Sources: [SecurityWeek] · [HIPAA Journal] · [DataBreaches.net]
Jun 22 AryStinger botnet Unattributed Breach · 4,300+ D-Link DIR-850L · DIR-818LW and QNAP NAS devices compromised as a distributed recon proxy network; exploits CVE-2013-3307, CVE-2016-5681 and CVE-2025-11837; enables intranet scanning, traffic tunneling, DNS hijacking; geographic concentration: South Korea 48.5%, China 31.8%, Sweden 6.4%; no attacker attribution confirmed; not a named-org victim logged as an enabling-access infrastructure event · https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/ · https://www.malwarebytes.com/blog/news/2026/06/thousands-of-d-link-routers-under-control-of-arystinger-botnet · Sources: [BleepingComputer] · [Malwarebytes]
Jun 21 Lockers IT Nova Ransomware · IT services · Bangladesh Sources: ransomware.live DLS
Jun 21 jktornel INC Ransom Ransomware · sector unknown · — client data, proprietary information claimed · Sources: ransomware.live DLS
Jun 21 JAG Group Stormous Ransomware · business services · US US-based business services company; corporate emails (@jaggroup.com), Active Directory domain logins with clear-text passwords, complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration data exfiltrated; full data dump published June 29, 2026 (new link posted after June 24 initial dump); estimated attack date June 20 · https://www.dexpose.io/stormous-ransomware-breach-exposes-jag-group-data/ · https://www.redpacketsecurity.com/stormous-ransomware-victim-jaggroup-com-update-full-data-dump/ · https://www.ransomware.live/id/amFnZ3JvdXAuY29tIFVQREFURS1GVUxMIERBVEEgRFVNUEBzdG9ybW91cw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 21 Artistic Smiles NightSpire Ransomware · consumer services · US https://www.redpacketsecurity.com/nightspire-ransomware-victim-artistic-smiles/ · Sources: ransomware.live DLS / [RedPacket Security]
Jun 21 Texas Parks and Wildlife Dept. Unattributed Breach · government · US 3,087,721 individuals exposed: driver's license numbers, passport numbers, email, phone, residential address; no SSNs/DOB/financial data; actor unattributed · https://www.techtimes.com/articles/318790/20260621/texas-data-breach-hits-3-million-drivers-licenses-passport-numbers-stolen-hunting-vendor.htm · Sources: [TechTimes]
Jun 20 Central Florida Cosmetic & Family Dentistry Qilin Ransomware · healthcare · US Sources: ransomware.live DLS
Jun 20 Pacific Lamp & Supply Qilin Ransomware · manufacturing · US industrial lighting and electrical supply company; Qilin DLS claim June 20, 2026; data scope and impact unconfirmed; 🟥 unverified — verify before treating as breach · https://www.redpacketsecurity.com/qilin-ransomware-victim-pacific-lamp-supply/ · https://www.ransomware.live/id/UGFjaWZpYyBMYW1wICYgU3VwcGx5QHFpbGlu · Sources: [RedPacket Security] · [ransomware.live]
Jun 20 sierravistahospital.com LockBit Ransomware · healthcare · US Sources: ransomware.live DLS
Jun 20 BITS Pilani DragonForce Ransomware · higher education · India https://www.redpacketsecurity.com/dragonforce-ransomware-victim-bits-pilani-ac-in/ · https://www.ransomware.live/group/dragonforce · Sources: [RedPacket Security] · [ransomware.live]
Jun 20 Access Dental WorldLeaks Ransomware · healthcare · US Sources: ransomware.live DLS
Jun 20 Super Finishing WorldLeaks Ransomware · manufacturing · Brazil metal parts finishing and surface treatment company; DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.dexpose.io/worldleaks-targets-brazilian-manufacturer-super-finishing/ · Sources: [DeXpose]
Jun 20 L'Archevêque & Rivest Ltée WorldLeaks Ransomware · construction · Canada Canadian general contractor and civil engineering services firm; DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.dexpose.io/worldleaks-hits-larcheveque-rivest-ltee-in-ransomware-attack/ · Sources: [DeXpose]
Jun 20 One Believing Interiors Nova Ransomware · interior design · US interior design studio specializing in built spaces including National Gallery projects; DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-nova-hits-one-believing-interiors/ · https://www.ransomware.live/id/T25lIEJlbGlldmluZyBJbnRlcmlvcnNAbm92YQ== · Sources: [HookPhish] · [ransomware.live]
Jun 20 MIT HJERTE Nova Ransomware · sector unknown · Denmark DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-nova-hits-mit-hjerte/ · https://www.ransomware.live/group/nova · Sources: [HookPhish] · [ransomware.live]
Jun 20 Dosab Nova Ransomware · industrial zone · Turkey organized industrial zone operator in Bursa, Turkey; Nova DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.redpacketsecurity.com/nova-ransomware-victim-dosab/ · https://www.ransomware.live/group/nova · Sources: [RedPacket Security] · [ransomware.live]
Jun 20 Newspaper Media Group INC Ransom Ransomware · media · publishing/US US-based local news organization operating community newspapers and magazines across Central and South Jersey; DLS claim June 20, 2026; data scope and impact unconfirmed; no public statement from victim · https://www.redpacketsecurity.com/incransom-ransomware-victim-newspaper-media-group/ · Sources: [RedPacket Security]
Jun 20 Preferred Properties Payload Ransomware · housing development · property management/US DLS claim June 20, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/payload-ransomware-victim-preferred-properties/ · Sources: [RedPacket Security]
Jun 20 AmiGest The Gentlemen Ransomware · IT services · France French IT integrator specialising in cloud, network, and managed services for SME clients; The Gentlemen ransomware DLS claim June 20, 2026; data scope and impact unconfirmed; attribution confirmed by DeXpose reporting · https://www.dexpose.io/theGentlemen-ransomware-attack-on-amigest/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 19 PJ Daly Contracting Qilin Ransomware · construction · Ireland construction contractor; DLS claim June 19, 2026; data scope and impact unconfirmed · https://www.redpacketsecurity.com/qilin-ransomware-victim-pj-daly-contracting/ · https://ransomware.live/id/UEogRGFseSBDb250cmFjdGluZ0BxaWxpbg== · Sources: [RedPacket Security] · [ransomware.live]
Jun 19 DaikyoNishikawa Corporation LockBit Ransomware · automotive parts · Japan Sources: ransomware.live DLS
Jun 19 Como Furniture Enterprises Co., Ltd. LockBit Ransomware · manufacturing · Taiwan Sources: ransomware.live DLS
Jun 19 ALS Global Limited Aur0ra Ransomware · testing · inspection/certification/Australia ASX-listed global testing, inspection, and certification firm (est. 1863; ~70 countries; mining, environmental, food safety, life sciences, materials testing); attack May 2026 (disclosed June 11 via ASX filing); Aur0ra DLS claim June 19, 2026; data published dark web June 22; 500+ employees' home directories including cached credentials; hundreds of plaintext password files; passport scans; bank account details; payroll data; workplace injury records; client laboratory results and analytical data; ALS confirmed breach, engaged cybersecurity specialists, and notified ACSC and relevant regulators · https://www.cyberdaily.au/security/13794-exclusi · https://www.dexpose.io/aurora-ransomware-strikes-als-global/ · https://www.breachsense.com/breaches/als-global-data-breach/ · Sources: [Cyber Daily] · [DeXpose] · [Breachsense]
Jun 19 Aflac Scattered Spider Extortion · insurance · US June 2025 social-engineering intrusion; 22.6M people notified (≥13.9M with PHI) · Sources: The Record / HIPAA Journal
Jun 19 Al Khaja Holding Unattributed Breach · conglomerate · UAE Sources: breachsense/ransomware.live DLS
Jun 19 Alexander Buch Bilanzbuchhalter Unattributed Breach · accounting · Germany Sources: breachsense/ransomware.live DLS
Jun 19 Apptricity Corporation Unattributed Breach · supply-chain software · US Sources: breachsense/ransomware.live DLS
Jun 19 ATCOM Unattributed Breach · telecom · IT services/Chile Sources: breachsense/ransomware.live DLS
Jun 18 Inter-Con Security Systems ShinyHunters Extortion · physical security services · US provider of armed/unarmed security officers, risk management, executive protection, and facility security for government, corporate, and critical infrastructure; 2.7M records claimed; ShinyHunters DLS June 18, 2026; no victim statement · https://www.dexpose.io/shinyhunters-compromise-ic-security-in-major-ransomware-attack/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-icsecurity-com/ · https://www.breachsense.com/breaches/inter-con-security-systems-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
Jun 18 Horizon Family Medical Group INC Ransom Ransomware · healthcare · US 7TB of sensitive data claimed exfiltrated; includes patient medical records (diagnoses, prescriptions, treatments, lab results), SQL databases, and QuickBooks financial data; victim management notified but did not respond per INC Ransom; 🟥 unconfirmed — no Horizon public statement · https://www.dexpose.io/incransom-compromises-horizon-family-medical-group/ · https://www.ransomware.live/group/incransom · https://malware.news/t/incransom-compromises-horizon-family-medical-group/108055 · Sources: [DeXpose] · [ransomware.live] · [Malware News]
Jun 18 Dean Cosmetic Dentistry NightSpire Ransomware · healthcare · US Sources: ransomware.live DLS
Jun 18 "FortiBleed" mass credential exposure Unattributed Breach · ~73,900 FortiGate firewall · VPN devices, 194 countries, 21,000+ domains; plaintext creds exposed on attacker server; harvested via ~1.16bn credential attempts + cracked SSL-VPN hashes. Device count confirmed at 86,644 by June 22 . Not a ransomware DLS victim logged as an enabling-access event feeding downstream intrusions; seen 2026-06-18 — BleepingComputer / Help Net Security (no CVE, no single attributed actor)
Jun 17 Promepla RansomHouse Ransomware · manufacturing · — Sources: ransomware.live DLS
Jun 17 SUNASS Nova Ransomware · government · water regulator/Peru Sources: ransomware.live DLS
Jun 17 Sumitomo Electric Bordnetze Aur0ra Ransomware · automotive wiring manufacturing · — Sources: ransomware.live DLS
Jun 17 Allan Brothers, Inc. Aur0ra Ransomware · agriculture · US Sources: ransomware.live DLS
Jun 17 Diamond Truck Centres Aur0ra Ransomware · vehicle dealership · Canada Sources: ransomware.live DLS
Jun 17 Framesi INC Ransom Ransomware · professional beauty · cosmetics manufacturing/Italy Sources: ransomware.live DLS
Jun 17 Jasper Plastics Solutions INC Ransom Ransomware · manufacturing · US Sources: ransomware.live DLS
Jun 17 Ecovacs Robotics SpaceBears Ransomware · consumer robotics · China Sources: ransomware.live DLS
Jun 17 Novo Nordisk FulcrumSec Ransomware · pharmaceuticals · Denmark 🟥 unverified group claim; confirm before treating as a breach · Sources: ransomware.live DLS
Jun 17 iRhythm Technologies Unattributed Breach · healthcare (cardiac monitoring) · US proprietary data + patient PHI allegedly exfiltrated from third-party-hosted apps, ransom demanded · actor not yet attributed · Sources: Dark Reading / DataBreachToday
Jun 16 InSite Architects Akira Ransomware · architecture · US Sources: ransomware.live DLS
Jun 16 Golfview Developmental Center Akira Ransomware · healthcare · disability services/US Sources: ransomware.live DLS
Jun 16 Moody Bible Institute ShinyHunters Extortion · education · US 1,300+ files claimed; group alleged "tens of millions of records" related to enrollment, donor relations, payroll, and communications; Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim June 16, 2026; scope unverified; law firm class action investigation underway — 🟥 unverified · https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit · https://www.classaction.org/data-breach-lawsuits/moody-bible-institute-june-2026 · Sources: [Google Cloud Blog] · [classaction.org]
Jun 16 Kedah State Government Nova Ransomware · government · Malaysia official state government portal providing public services for Kedah, Malaysia; Nova DLS claim June 16, 2026; estimated attack date June 16; data scope and impact unconfirmed · https://www.dexpose.io/nova-ransomware-group-targets-kedah-state-government/ · https://www.ransomware.live/id/S2VkYWhAbm92YQ== · Sources: [DeXpose] · [ransomware.live]
Jun 16 River Bank & Trust Unattributed Breach · banking · financial services/US ransomware attack June 16, 2026; SEC 8-K filed June 25, 2026; PII of customers and employees potentially exposed; investigation ongoing; operational impact not disclosed; actor unattributed · https://www.sec.gov/Archives/edgar/data/1641601/000119312526282946/ck0001641601-20260619.htm · https://1819news.com/news/item/river-bank-trust-hit-by-ransomware-attack-from-unauthorized-threat-actor · Sources: [SEC 8-K] · [1819 News]
Jun 15 distinetmurcia.es Qilin Ransomware · services · Spain Sources: ransomware.live DLS
Jun 15 Grupo Indi Qilin Ransomware · civil engineering · construction/Mexico prominent Mexican civil engineering and construction company; Qilin DLS claim June 15, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-targets-mexican-construction-leader-grupo-indi/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jun 15 Kawai Musical Instruments Mfg. Co., Ltd. SafePay Ransomware · musical instruments manufacturing · Japan renowned Japanese manufacturer of pianos, digital keyboards, and band/orchestral instruments; SafePay DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/safepay-ransomware-attack-on-kawai-musical-instruments/ · https://www.ransomware.live/id/a2F3YWl1cy5jb21Ac2FmZXBheQ== · https://www.hendryadrian.com/ransom-kawaius-com-jun-2026/ · Sources: [DeXpose] · [ransomware.live] · [hendryadrian.com]
Jun 15 Hugh Stirling Ltd SafePay Ransomware · construction · UK established UK construction company; SafePay DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/safepay-ransomware-attack-on-hugh-stirling-ltd/ · https://www.ransomware.live/group/safepay · Sources: [DeXpose] · [ransomware.live]
Jun 15 ddcnyc.com Akira Ransomware · services · US Sources: ransomware.live DLS
Jun 15 Kodak ShinyHunters Extortion · media technology · US 2.2M records (customer PII and internal corporate data); ShinyHunters listed June 15 with a June 18 ransom deadline; Kodak confirmed "unauthorized third party illegally gained temporary access to a limited amount of company data" June 17 and engaged cybersecurity experts and law enforcement; no proof sample published; no data dump confirmed; claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://cybernews.com/security/shinyhunters-claims-kodak-hack-2-million-records/ · https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/ · https://www.techtimes.com/articles/318565/20260617/kodak-confirms-data-breach-shinyhunters-threatens-leak-22m-records.htm · Sources: [Cybernews] · [BleepingComputer] · [TechTimes]
Jun 15 Sysco ShinyHunters Extortion · food distribution · US 61M Salesforce records claimed; ShinyHunters listed June 15, weeks after Sysco was separately targeted by Qilin ransomware (two distinct threat actors targeting the same org); Sysco has not publicly confirmed this incident; 🟥 unverified — treat as claimed only · https://cybernews.com/news/sysco-shinyhunters-61-million-salesforce-records/ · Sources: [Cybernews]
Jun 15 Glendale Community College ShinyHunters Extortion · education · US 62GB exfiltrated (304,000+ files); Oracle PeopleSoft Campus Solutions compromised via CVE-2026-35273; 150,000+ student records including names, DOBs, student emails, enrollment, financial aid, and transcript data (Sept 2020–June 2026); DLS claim June 15–16, 2026; final ransom warning before June 18 deadline · https://www.ransomware.live/id/Z2xlbmRhbGUuZWR1QHNoaW55aHVudGVycw · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-glendale-edu/ · https://cybernews.com/security/google-shinyhunters-oracle-peoplesoft-zero-day-extortion/ · Sources: [ransomware.live] · [RedPacket Security] · [Cybernews]
Jun 15 Illinois Central College ShinyHunters Extortion · education · US 28GB data claimed; Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim June 15, 2026; final ransom warning issued · https://www.dexpose.io/shinyhunters-breach-illinois-central-college/ · https://www.breachsense.com/breaches/illinois-central-college-data-breach/ · Sources: [DeXpose] · [Breachsense]
Jun 15 Deep Well Services ShinyHunters Extortion · oilfield services · US provider of downhole tools and services to the oil and gas industry; 7,000+ customer PII and internal corporate data records claimed; ShinyHunters DLS June 15, 2026; ransom deadline June 18 passed without data publication at time of initial report; no victim statement · https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-deep-well-services/ · https://www.ransomware.live/id/RGVlcCBXZWxsIFNlcnZpY2VzQHNoaW55aHVudGVycw · https://breachnews.com/breaches/kodak-and-deep-well-services-added-to-shinyhunters-leak-site/ · Sources: [HookPhish] · [ransomware.live] · [BreachNews]
Jun 15 Mahajak Development Co., Ltd. The Gentlemen Ransomware · technology distribution · Thailand leading IT and technology distributor in Thailand; The Gentlemen DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/the-gentlemen-ransomware-targets-mahajak-development/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 14 INK DragonForce Ransomware · creative production · UK UK-based production studio; 102.85 GB exfiltrated; DLS claim June 14, 2026; 7–8 day data-publication ultimatum issued after ransom deadline · https://www.dexpose.io/dragonforce-ransomware-attack-on-ink/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-ink/ · Sources: [DeXpose] · [RedPacket Security]
Jun 14 Council of Europe ShinyHunters Extortion · intergovernmental organisation · France 297 GB published June 16, 2026, after ransom deadline not met; content: 409,000+ payslips (2011–2026), 3,700+ personnel files, 14,000+ CVs, and employee personal/financial records (names, DOB, home addresses, phone, salaries, bank account details, SSN/tax information, medical records) for 10,000+ staff; claimed access vector: Oracle PeopleSoft CVE-2026-35273; Council of Europe states investigation is ongoing; data authenticity not yet independently verified by forensics · https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/ · https://www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/ · https://cybernews.com/security/council-of-europe-data-breach-claim/ · Sources: [SecurityWeek] · [BleepingComputer] · [Cybernews]
Jun 14 Winona County NightSpire Ransomware · government · US second ransomware attack on county in 2026; attack detected April 7; county network partially taken offline; MN National Guard assisted; NightSpire leaked data June 14 2026; county confirmed data leak same day; personal info affected pending review; 🟨 county-confirmed · https://www.govtech.com/security/cyber-criminals-leak-data-from-minnesota-ransomware-incident · https://www.dexpose.io/nightspire-ransomware-attack-on-k-county/ · Sources: [GovTech] · [DeXpose]
Jun 13 One Medical ShinyHunters Extortion · healthcare · US legacy One Medical Seniors patient file storage compromised (demographic + clinical records, 9 US cities: Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, Seattle); 8.8TB claimed; breach June 8-11, detected June 13; ShinyHunters deadline June 22; company confirmed unauthorized access; core EHR and non-Seniors systems unaffected; vector unconfirmed (not PeopleSoft CVE-2026-35273) · https://www.hipaajournal.com/one-medical-data-breach/ · https://cybernews.com/security/amazon-one-medical-data-breach/ · https://www.bankinfosecurity.com/shinyhunters-threatens-to-leak-amazon-one-medical-records-a-32027 · Sources: [HIPAA Journal] · [Cybernews] · [BankInfoSecurity]
Jun 12 Al Shafar GRC DragonForce Ransomware · construction · UAE UAE construction and governance, risk, and compliance services company; DragonForce DLS claim June 12, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jun 12 Al Ishrak Contracting DragonForce Ransomware · construction · UAE Dubai-based contracting company; DragonForce DLS claim June 12, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jun 12 JCPenney / Catalyst Brands / Authentic Brands Group ShinyHunters Extortion · retail · US hundreds of thousands of records claimed (SSNs, DOBs, W-2 tax forms, payroll records, driver's licenses, government-issued IDs); ShinyHunters claimed June 12; threatened to publish by June 15; no JCPenney/Catalyst/Authentic public statement; class action investigation launched (Edelson Lechtzin LLP, June 18); no data samples published; 🟥 unverified — treat as claimed only · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-jcpenney-several-other-subsdiaries-under-catalyst-brands-authentic-brands-group/ · https://cybernews.com/security/shinyhunters-jcpenney-retail-data-leak-claim/ · https://www.dexpose.io/shinyhunters-breaches-jcpenney-and-catalyst-brands/ · Sources: [RedPacket Security] · [Cybernews] · [DeXpose]
Jun 12 American Tower Corporation ShinyHunters Extortion · telecommunications infrastructure · US 5.2M records claimed including customer and landowner PII, records linking T-Mobile/Verizon/US DHS as clients, tower asset GPS coordinates, and plaintext physical access/gate codes for cell tower compounds across the US; claimed June 12, ransom deadline June 15 (passed with no confirmed data dump); company has not issued a public statement; 🟥 unverified — treat as claimed only · https://www.dexpose.io/shinyhunters-breach-american-tower-corporation/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-american-tower-corporation/ · https://www.breachsense.com/breaches/american-tower-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
Jun 12 Zayo Group + Allstream ShinyHunters Extortion · telecommunications · US+Canada ShinyHunters claimed June 12, 2026 with a June 16 payment-or-leak deadline; data scope unconfirmed; no victim statement · https://www.dexpose.io/shinyhunters-target-zayo-group-and-allstream-in-ransomware-attack/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-zayo-com-allstream-com/ · https://www.ransomware.live/id/WmF5by5jb20gJiBBbGxzdHJlYW0uY29tQHNoaW55aHVudGVycw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 12 BeyondTrust Icarus Ransomware · cybersecurity · PAM solutions/US Salesforce CRM business contact and general sales-related customer information accessed via Klue OAuth integration; notified June 12, publicly disclosed June 24 via BeyondTrust Trust Center; 13th confirmed Klue supply-chain victim · https://www.beyondtrust.com/trust-center/security-advisories/klue-security-incident · https://www.securityweek.com/beyondtrust-lastpass-impacted-by-klue-salesforce-incident/ · Sources: [BeyondTrust] · [SecurityWeek]
Jun 12 8×8 Icarus Ransomware · communications technology · US Salesforce CRM data accessed via Klue OAuth integration; disclosed June 24; 14th confirmed Klue supply-chain victim · https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ · Sources: [SecurityWeek]
Jun 12 Pendo Icarus Ransomware · product analytics software · US Salesforce CRM data accessed via Klue OAuth integration; disclosed June 24; 15th confirmed Klue supply-chain victim · https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ · Sources: [SecurityWeek]
Jun 12 AlertMedia Icarus Ransomware · enterprise communications software · US Salesforce CRM business contact and sales data accessed via Klue OAuth integration; disclosed June 30, 2026; 17th confirmed Klue supply-chain victim · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Blackbaud Icarus Ransomware · nonprofit · social-good CRM software/US Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026; 🟨 scope unverified · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Camunda Icarus Ransomware · process automation · workflow software/Germany Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Cresta Icarus Ransomware · AI-powered contact center software · US Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Deel Icarus Ransomware · HR · payroll/global compliance platform/US Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Lucanet Icarus Ransomware · financial performance management software · Germany Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Link11 Icarus Ransomware · DDoS protection · cybersecurity/Germany Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Tines Icarus Ransomware · security automation · SOAR/Ireland Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Nintendo of America ShadowByt3$ Ransomware · entertainment · gaming/US ShadowByt3$ claimed June 12, 2026 via compromise of TinyPulse (HR and employee-engagement SaaS platform used by Nintendo); group demanded $2M ransom with 48-hour deadline; Nintendo declined; ShadowByt3$ shifted demand to TinyPulse directly on June 14 with June 16 secondary deadline; data leaked June 16 after deadline passed; Nintendo confirmed breach "limited to internal survey content comprising a small subset of our employees" — Nintendo's own network was not compromised; attack was against TinyPulse's cloud environment; ShadowByt3$ claims 859MB including full employee names, email addresses, bank statements, W-9 tax forms, employee IDs, HR progress plans, analytics, and survey data spanning 2016–2026; 🟨 breach confirmed by Nintendo (survey content); broader scope claims unverified · https://hackread.com/nintendo-america-employee-data-shadowbyt3-tinypulse/ · https://www.nintendolife.com/news/2026/06/hacker-group-claims-to-have-stolen-nintendo-data-posts-usd2-million-ransom · https://www.technadu.com/nintendo-confirms-tinypulse-data-stolen-in-shadowbyt3-extortion-attack/629628/ · https://www.dexpose.io/shadowbyt3-targets-nintendo-via-tinypulse/ · Sources: [HackRead] · [Nintendo Life] · [TechNadu] · [DeXpose]
Jun 11 Central Romana Corporation LockBit Ransomware · agribusiness · Dominican Republic Sources: ransomware.live DLS / FalconFeeds
Jun 11 Shougang Hierro Perú S.A.A. LockBit Ransomware · mining · Peru Sources: ransomware.live DLS / FalconFeeds
Jun 11 Stahlwille B.V. LockBit Ransomware · tool manufacturing · Netherlands Sources: ransomware.live DLS / FalconFeeds
Jun 11 JEC Eye Hospitals and Clinics LockBit Ransomware · healthcare · Indonesia Sources: FalconFeeds
Jun 11 Colégio Santo Inácio LockBit Ransomware · education · Brazil Sources: FalconFeeds
Jun 11 LBR Engineering and Consulting LockBit Ransomware · engineering · Brazil Sources: FalconFeeds
Jun 11 Areco DragonForce Ransomware · construction materials · Sweden leading Swedish construction materials sector company; DLS claim June 11, 2026; data scope and impact unconfirmed · https://www.dexpose.io/dragonforce-ransomware-attack-on-areco/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-areco/ · Sources: [DeXpose] · [RedPacket Security]
Jun 11 National Association of Insurance Commissioners ShinyHunters Extortion · insurance regulatory · US 3.1TB and 105,000+ files claimed; investigation confirmed (July 1): only publicly available statutory financial reports, outdated logs, and config files accessed; key systems SERFF/OPTins/UCAA/EDP/RDC confirmed intact; no consumer PII or payment data; breach via PeopleSoft CVE-2026-35273, access June 11; data published online by June 25; 🟩 breach confirmed, impact minimal (public regulatory data only) · https://www.insurancejournal.com/news/national/2026/06/24/875119.htm · https://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/ · https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack · Sources: [Insurance Journal] · [BleepingComputer] · [TechRadar]
Jun 11 Baylor Genetics Unknown Ransomware · Genomics / Healthcare · USA Unauthorized access to Baylor Genetics systems June 11-17 2026; 305,066 individuals notified (248,430 Texas, 56,636 Massachusetts); exposed: genetic test results, SSNs, dates of birth, health insurance info, employee financial account numbers; breach detected ~June 15; data review concluded ~July 30; notifications dispatched August 20 2026 · Sources: https://www.bankinfosecurity.com/genomics-testing-lab-notifies-nearly-310000-hack-a-32618
Jun 10 Sayre Associates DragonForce Ransomware · civil engineering · land surveying/US civil engineering and land surveying firm (est. 1969; land development, parks and recreation design, drainage/erosion control, construction administration); sensitive client data, project files, emails, and financial documents claimed; DLS claim June 10, 2026 · https://www.dexpose.io/dragonforce-strikes-sayre-associates-in-ransomware-attack/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-sayre-associates/ · Sources: [DeXpose] · [RedPacket Security]
Jun 10 Port Air Express Akira Ransomware · logistics · — Sources: ransomware.live DLS
Jun 10 Tata Electronics WorldLeaks Ransomware · electronics manufacturing (iPhone assembly) · India 200,000+ files (630+ GB) exfiltrated: Apple iPhone manufacturing records, technical drawings, component specifications, Tesla engineering documents, employee passport scans; attack date est. early June 2026; Tata confirmed breach June 23; operations reported unaffected; Apple investigating; ransom demand confirmed but payment status unknown · https://cybernews.com/security/tata-electronics-breach-apple-tesla-secret-files/ · https://www.cnbc.com/amp/2026/06/23/indias-tata-electronics-hit-by-cyber-breach-claiming-to-expose-apple-tesla-trade-secrets.html · Sources: [Cybernews] · [CNBC]
Jun 10 Liberty Insurance Corporation Krybit Ransomware · insurance · Philippines Sources: ransomware.live DLS
Jun 10 PROBE S.A. Krybit Ransomware · services · El Salvador Sources: ransomware.live DLS
Jun 10 Lösing Filtertechnik SpaceBears Ransomware · manufacturing · Germany Sources: ransomware.live DLS
Jun 10 Global Schools Foundation FulcrumSec Ransomware · education · Singapore Sources: ransomware.live DLS
Jun 10 Mackay Sugar The Gentlemen Ransomware · agri-industrial · Australia mills shut, harvest disrupted; ransomware confirmed (The Gentlemen attribution) · Sources: SecurityWeek / The Record
Jun 09 Spray Equipment & Service Center Akira Ransomware · industrial equipment · US Sources: ransomware.live DLS
Jun 09 Rockaway River Country Club Akira Ransomware · hospitality · US Sources: ransomware.live DLS
Jun 09 SMPC Architects Akira Ransomware · architecture · US Sources: ransomware.live DLS
Jun 09 Centre Ellipse Akira Ransomware · services · — Sources: ransomware.live DLS
Jun 09 Cal Fresh Termite Ransomware · government benefits · US Sources: ransomware.live DLS
Jun 09 Apollo Pipes WorldLeaks Ransomware · manufacturing · India Sources: ransomware.live DLS
Jun 09 GDL Transport WorldLeaks Ransomware · logistics · Sweden Sources: ransomware.live DLS
Jun 09 M1xchange WorldLeaks Ransomware · fintech · India Sources: ransomware.live DLS
Jun 09 University of Nottingham ShinyHunters Extortion · education · UK 454,600+ student and alumni records including names, addresses, phone numbers, passport numbers, ethnicity and disability data, and academic records; Oracle PeopleSoft CVE-2026-35273 confirmed access vector (attack window May 27–June 9); university confirmed incident June 11, 2026 · https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/ · https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-raids-nottingham-uni-for-student-alumni-data/5253961 · https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/ · Sources: [BleepingComputer] · [The Register] · [Help Net Security]
Jun 09 Houston City College ShinyHunters Extortion · education · US Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim first posted June 9 onwards; named victim confirmed in Google Cloud/Mandiant ShinyHunters education sector campaign report (June 2026) · https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit · https://www.highereddive.com/news/colleges-hit-in-cyberattack-by-group-behind-canvas-breach-google-says/822831/ · Sources: [Google Cloud Blog] · [Higher Ed Dive]
Jun 09 Auburn Electrical Construction Embargo Ransomware · construction · US Sources: ransomware.live DLS
Jun 09 Mid-Cumberland Human Resource Agency Insomnia Ransomware · public services · US Sources: ransomware.live DLS
Jun 09 Trevi Nova Ransomware · construction-engineering · Italy Sources: ransomware.live DLS
Jun 09 AireSpring Chaos Ransomware · managed telecom services · US Sources: ransomware.live DLS
Jun 09 Spratley's of Mortimer PrinzEugen Ransomware · retail-consumer services · UK posted twice on DLS; de-duped · Sources: ransomware.live DLS
Jun 09 Cambridge Law Chambers Gunra Ransomware · legal · Bahamas Sources: ransomware.live DLS
Jun 09 Katholiek Amersfoort Stormous Ransomware · religious org · Netherlands re-post "FOR SALE" · Sources: ransomware.live DLS
Jun 09 sa2000.com Stormous Ransomware · services (French-language records, 150GB claimed) · — Sources: ransomware.live DLS
Jun 09 Philadelphia Insurance Companies Ethics Ransomware · Insurance · USA DLS claim by new group Ethics (debuted Aug 12, 2026); one of 3 simultaneous inaugural postings; estimated attack date Jun 2026; scope unverified · Sources: https://www.dexpose.io/ethics-ransomware-group-targets-philadelphia-insurance-companies/
Jun 08 Covenant Health Qilin Ransomware · healthcare · US Qilin attack May 2025; ~850GB leaked, 478,188 individuals affected (notifications confirmed) · Sources: The Record / SecurityWeek
Jun 08 The Banyans Health and Wellness Qilin Ransomware · healthcare · Australia Sources: ransomware.live DLS
Jun 08 Kinetic Education Qilin Ransomware · education · Australia Sources: ransomware.live DLS
Jun 08 SatCom CX Qilin Ransomware · marketing services · US Sources: ransomware.live DLS
Jun 08 Isuzu Motors Qilin Ransomware · automotive manufacturing · Thailand Sources: ransomware.live DLS
Jun 08 Opéra Comique Qilin Ransomware · arts-culture · France Sources: ransomware.live DLS
Jun 08 Shipping Association of NY and NJ Qilin Ransomware · maritime-logistics · US Sources: ransomware.live DLS
Jun 08 Wiese USA Termite Ransomware · material handling · US Sources: ransomware.live DLS
Jun 08 Roland Machinery Termite Ransomware · machinery dealer · — Sources: ransomware.live DLS
Jun 08 Aegle Aviation RansomHouse Ransomware · aviation · India Sources: ransomware.live DLS
Jun 08 Ma Pak Leung Company RansomHouse Ransomware · pharma-retail · Hong Kong Sources: ransomware.live DLS
Jun 08 Plaza Lama Payload Ransomware · retail · Dominican Republic Sources: ransomware.live DLS
Jun 08 Hansoll Textile Payload Ransomware · manufacturing · Vietnam Sources: ransomware.live DLS
Jun 08 Villea Hotels Payload Ransomware · hospitality · — Sources: ransomware.live DLS
Jun 06 Pearson Ford Play Ransomware · auto dealership · US Sources: ransomware.live DLS
Jun 05 Avcon Jet Qilin Ransomware · aviation · Austria Sources: ransomware.live DLS
Jun 05 Trican Well Service Qilin Ransomware · oilfield services · Canada Sources: ransomware.live DLS
Jun 05 Don Don Qilin Ransomware · retail · food Sources: ransomware.live DLS
Jun 05 Corley Manufacturing Play Ransomware · manufacturing · US Sources: ransomware.live DLS
Jun 05 Dallis Law Firm Play Ransomware · legal · US Sources: ransomware.live DLS
Jun 05 REHA-ACTIV DragonForce Ransomware · healthcare · medical supply/Germany medical rehabilitation equipment, mobility aids, orthotics, prosthetics, home care products; 48.55 GB exfiltrated; DLS claim June 5, 2026 · https://www.dexpose.io/dragonforce-targets-german-medical-supplier-reha-activ/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-reha-activ/ · Sources: [DeXpose] · [RedPacket Security]
Jun 05 Madison Square Garden Sports Corp. ShinyHunters Extortion · entertainment · sports/US 45 GB published June 16 (26M customer and corporate records); content includes facial recognition surveillance records, internal threat assessments, and personal customer data; breach June 5, ransom deadline June 15, deadline missed, data published June 16; MSG's second major breach within 6 months (prior: Cl0p/Oracle eBusiness Suite February 2026, 131,070 employees/contractors); claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://thenextweb.com/news/shinyhunters-madison-square-garden-45gb-data-leak-facial-recognition · https://www.dexpose.io/shinyhunters-breach-madison-square-garden-sports-corp/ · Sources: [The Next Web] · [DeXpose]
Jun 04 National Industries The Gentlemen Ransomware · automotive manufacturing · India Indian precision-engineered automotive components manufacturer under the Metalman Group; supplies major two-wheeler OEMs; The Gentlemen DLS claim June 4, 2026; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.dexpose.io/thegentlemen-ransomware-attack-on-national-industries/ · https://www.ransomware.live/group/thegentlemen · Sources: [DeXpose] · [ransomware.live]
Jun 03 Copamex DragonForce Ransomware · paper manufacturing · Mexico Monterrey-based paper products manufacturer (est. 1928); DLS claim June 3, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-copamex/ · Sources: [RedPacket Security]
Jun 03 SETS Solutions DragonForce Ransomware · IT services · Lebanon technology solutions provider (est. 1990; HR management system People365, data centre, cloud, end-user computing); DLS claim June 3, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-sets-solutions/ · Sources: [RedPacket Security]
Jun 02 Cropwise ShadowByt3$ Ransomware · agri-tech · global Syngenta's digital farming platform offering GIS mapping, field crop scouting, and agronomic advisory tools deployed across 100+ countries; ShadowByt3$ DLS claim June 2, 2026; 10.4 MB of data exfiltrated including agricultural GIS data, crop field data, and user credentials; no Syngenta or Cropwise public statement · https://hackread.com/ · Sources: [HackRead]
Jun 01 MyPillow Play Ransomware · manufacturing · retail/US payroll, tax, employee-ID data claimed · Sources: Play DLS
Jun 01 Energy Action SafePay Ransomware · energy management · Australia ~470GB claimed; under investigation · Sources: SafePay DLS
Jun 01 Synex International Pvt Ltd DragonForce Ransomware · MEP systems · ELV solutions/solar energy/India integrated mechanical, electrical, and plumbing (MEP), extra-low voltage (ELV), and solar energy solutions provider; DragonForce DLS claim June 1, 2026; 13.63 GB claimed; estimated attack date May 30, 2026 · https://www.dexpose.io/dragonforce-strikes-synex-international-pvt-ltd-in-sophisticated-ransomware-attack/ · https://www.hookphish.com/blog/ransomware-group-dragonforce-hits-synex-international-pvt-ltd/ · https://www.ransomware.live/id/U3luZXggSW50ZXJuYXRpb25hbCBQdnQgTHRkQGRyYWdvbmZvcmNl · Sources: [DeXpose] · [HookPhish] · [ransomware.live]
Jun 01 The Adviser Brain Cipher Ransomware · media · AU 350GB claimed; ransom deadline 2026-06-02 · Sources: Brain Cipher DLS
Jun 01 School Facility Consultants Abyss Ransomware · education planning and consulting · US California-based firm advising school districts on facility planning, project management, and construction; Abyss DLS claim June 1, 2026; sensitive information threatened for release; scope unconfirmed · https://www.dexpose.io/abyss-ransomware-targets-school-facility-consultants/ · https://www.hookphish.com/blog/ransomware-group-abyss-hits-school-facility-consultants/ · Sources: [DeXpose] · [HookPhish]
Jun 01 Expert MRI Unattributed Breach · healthcare · radiology/US PEAR DLS claim seen 2026-06, attack est. Aug 2025 — ransomware.live DLS — 🟥 attack predates PEAR posting; 617GB alleged, 209,560 individuals' PHI (names, addresses, DOB, diagnosis/treatment, SSNs); verify PEAR attribution independently
Jun 01 RRCA Accounts Management Unattributed Breach · collections · US 115,837 individuals affected
Jun 01 Dairy Farmers of America Unattributed Breach · agriculture co-op · US employee + member data leaked · actor not yet attributed · Sources: The Record
Jun 01 Dresden State Art Collections Unattributed Breach · arts-culture · Germany digital systems disrupted · actor not yet attributed · Sources: The Record
Jun 01 DHS Homeland Security Information Network Unattributed Breach · government · law enforcement information sharing/US HSIN servers and an associated SharePoint collaboration system compromised; used by state/local law enforcement fusion centers and federal agencies to share threat intelligence; attack estimated late May–early June 2026; disclosed July 1, 2026; DHS confirmed attack and isolated affected systems; forensic investigation underway; no classified networks affected; sensitive law enforcement operational data (open investigations, facility-threat mappings, inter-agency partner identities) potentially exposed; actor unattributed · https://www.bleepingcomputer.com/ · https://www.nextgov.com/ · Sources: [BleepingComputer] · [Nextgov/FCW]
Jun 01 Department of Homeland Security (HSIN) Unknown Ransomware · government-federal · US DHS confirmed intrusion into Homeland Security Information Network (HSIN), the SBU inter-agency intelligence-sharing platform; attackers stole credential files, ran malicious code, and deleted logs; initial alerts were dismissed as false positives giving extended dwell time (late May - early June 2026); classified systems not affected; House Homeland Security Committee requested formal briefing; 🟩 confirmed by DHS · Sources: https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/ · https://www.nextgov.com/cybersecurity/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414724/

May 2026

May 28 VVO Finance Everest Ransomware · financial services · Germany Everest DLS May 28, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-vvo-finance/ · https://www.redpacketsecurity.com/everest-ransomware-victim-vvo-finance/ · Sources: [HookPhish] · [RedPacket Security]
May 27 QLS Group DragonForce Ransomware · retail · domestic appliances logistics/Australia large Australian domestic appliances retailer and logistics group; DragonForce DLS claim May 27, 2026; threat to release data; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/dragonforce-targets-qls-group-in-ransomware-attack/ · https://www.ransomware.live/group/dragonforce · Sources: [DeXpose] · [ransomware.live]
May 27 Carnival Corporation ShinyHunters Extortion · travel · hospitality/US 5,995,277 individuals affected; names, dates of birth, addresses, email, phone, passport and driver's license numbers; social-engineering attack on Carnival employee led to account compromise April 14, 2026; data exfiltrated before access blocked; breach notification letters dated May 27, 2026 · https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/ · https://www.theregister.com/cyber-crime/2026/05/28/carnival-shinyhunters-cruised-off-with-6m-customer-records/5247808 · https://www.malwarebytes.com/blog/data-breaches/2026/05/carnival-confirms-data-breach-impacting-nearly-6-million · Sources: [BleepingComputer] · [The Register] · [Malwarebytes]
May 23 DentaQuest ShinyHunters Extortion · dental benefits administration · US 2.6M members' PII and PHI exposed (names, DOBs, email, phone, home addresses, gender, government-issued IDs, health insurance info, Medicaid IDs); 234GB exfiltrated; ShinyHunters posted May 23, data published after ransom negotiation failure; DentaQuest confirmed breach June 2, 2026; 2,553,599 unique emails confirmed via HIBP June 3; attack vector unconfirmed · https://securityaffairs.com/193274/data-breach/dentaquest-breach-shinyhunters-publish-data-impacting-2-6m-people.html · https://www.bankinfosecurity.com/shinyhunters-leaks-234gb-dentaquest-data-trove-a-31883 · https://www.rescana.com/post/dentaquest-data-breach-analysis-shinyhunters-leak-exposes-pii-and-phi-of-2-6-million-members-in-2026 · https://www.hipaajournal.com/dentaquest-data-breach/ · Sources: [SecurityAffairs] · [BankInfoSecurity] · [Rescana] · [HIPAA Journal]
May 22 TVN Media APT73 Ransomware · multimedia · broadcasting/Panama leading multimedia company and broadcaster based in Panama; APT73/Bashe DLS claim May 22, 2026; data scope and impact unconfirmed; APT73 noted for fabricating some high-profile claims — 🟥 unverified pending independent confirmation · https://www.dexpose.io/apt73-bashe-strikes-panamas-tvn-media/ · https://www.ransomware.live/group/apt73 · Sources: [DeXpose] · [ransomware.live]
May 20 GitHub Internal Lapsus$ Ransomware · software development platform · US ~3,800–4,000 internal source code repositories exfiltrated; attack May 20, 2026 via poisoned "Nx Console" VS Code extension (nrwl.angular-console v18.95.0, published May 18 by threat actor); primary actor: TeamPCP (UNC6780); Lapsus$ listed as extortion partner (operational collaboration confirmed since March 2026 per Resecurity); joint dark-web listing: $50K (TeamPCP standalone) / $95K (TeamPCP x Lapsus$); exfiltrated content includes GitHub Actions, Copilot internal tooling, CodeQL, security tools, Codespaces, and Dependabot source; GitHub confirmed unauthorized access to internal repositories; GitHub stated customer repositories, enterprise accounts, and user data NOT affected; Lapsus$ DLS claim June 13, 2026 · https://therecord.media/github-confirms-teampcp-hack-customers-unaffected · https://www.infosecurity-magazine.com/news/github-confirms-breach-vs-code/ · https://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html · https://www.bleepingcomputer.com/news/security/github-investigates-internal-repositories-breach-claimed-by-teampcp/ · Sources: [The Record] · [Infosecurity Magazine] · [The Hacker News] · [BleepingComputer]
May 15 Krum Public Library NightSpire Ransomware · education-library · US 50 GB claimed exfiltrated: financial docs, HR data, supervisor info; attack May 14 2026; city of Krum confirmed ransomware in June 3 public notice; no SSNs/financial account info compromised; backups prevented permanent data loss; 🟨 city-confirmed · https://dysruptionhub.com/krum-library-ransomware-wifi/ · https://www.ransomware.live/id/S3J1bSBQdWJsaWMgTGlicmFyeUBuaWdodHNwaXJl · Sources: [Dysruption Hub] · [ransomware.live]
May 06 Keretapi Tanah Melayu Berhad The Gentlemen Ransomware · transportation · railway/Malaysia Malaysia's national railway company; The Gentlemen DLS claim May 6, 2026; 3,858 employees and 8,428 users exposed; 21 third-party employee credentials and 143 external attack surface vulnerabilities identified; estimated attack date May 3, 2026; rail operations unaffected · https://www.dexpose.io/the-gentlemen-ransomware-group-targets-keretapi-tanah-melayu-berhad/ · https://www.ransomware.live/id/S2VyZXRhcGkgVGFuYWhAdGhlZ2VudGxlbWVu · Sources: [DeXpose] · [ransomware.live]
May 04 Hokuyo 2006 Co., Ltd. SafePay Ransomware · manufacturing · packaging-logistics/Japan SafePay DLS claim; data exfiltration from multiple directories claimed incl. employee records and business documents; no victim statement · https://www.redpacketsecurity.com/safepay-ransomware-victim-hokuyo2006-co-jp/ · https://www.ransomware.live/id/aG9rdXlvMjAwNi5jby5qcEBzYWZlcGF5 · Sources: [RedPacket Security] · [ransomware.live]
May 03 Fiserv Inc. Everest Ransomware · fintech · US powers core banking systems, digital platforms, merchant acquiring, and Clover POS for thousands of financial institutions worldwide; Everest DLS May 3, 2026; no ransom demand stated; Fiserv has not confirmed; 🟥 unverified · https://www.dexpose.io/everest-ransomware-attack-targets-financial-tech-leader-fiserv/ · https://www.redpacketsecurity.com/everest-ransomware-victim-fiserv/ · https://www.breachsense.com/breaches/fiserv-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
May 02 Epiq Global Everest Ransomware · legal services · US global eDiscovery, class action administration, bankruptcy case management provider; Everest DLS May 2, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-epiq-global/ · https://www.redpacketsecurity.com/everest-ransomware-victim-epiq-global/ · Sources: [HookPhish] · [RedPacket Security]
May 02 TSYS Everest Ransomware · payment processing · US Global Payments' core payment-processing and card-issuer subsidiary; Everest DLS May 2, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-tsys/ · https://www.redpacketsecurity.com/everest-ransomware-victim-tsys/ · Sources: [HookPhish] · [RedPacket Security]
May 02 Symcor Inc. Everest Ransomware · business process outsourcing · Canada Canada's primary bank-statement and tax-document processor for the Big Five Canadian banks; Everest DLS May 2, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-symcor/ · https://www.dexpose.io/everest-ransomware-group-strikes-canadian-firm-symcor/ · Sources: [HookPhish] · [DeXpose]
May 01 BCD Travel ShinyHunters Extortion · travel services · Netherlands 396,313 customer email addresses and 700,000+ Salesforce records (30 GB+ compressed) published after June 1 ransom deadline; data includes names, physical addresses, phone numbers, job titles, and support tickets; access via direct Salesforce/SharePoint compromise (not Oracle PeopleSoft CVE-2026-35273) · https://cybernews.com/security/shinyhunters-400k-bcd-travel-customers-data-online/ · https://www.dutchnews.nl/2026/06/dutch-travel-firm-bcd-hacked-700000-customers-reportedly-hit/ · Sources: [Cybernews] · [DutchNews.nl]
May 01 Cushman & Wakefield ShinyHunters Extortion · commercial real estate services · US 500,000+ Salesforce records (310,400 accounts confirmed via HIBP May 12); names, job titles, company addresses, phone numbers, email addresses; vishing attack May 1 2026; 50GB data published May 7 after ransom talks failed (May 6 deadline); Qilin also listed Cushman & Wakefield on DLS May 4 — relationship unconfirmed, may reflect separate opportunistic access; access via Salesforce (not PeopleSoft CVE-2026-35273) · https://cybernews.com/security/shinyhunters-cushman-wakefield-salesforce-dataset-leak/ · https://www.theregister.com/security/2026/05/05/cushman-wakefield-confirms-vishing-cyberattack/5228718/ · https://socradar.io/blog/charter-data-breach-shinyhunters-42m-records/ · Sources: [Cybernews] · [The Register] · [SOCRadar]

April 2026

Apr 30 Liberty Mutual Insurance Everest Ransomware · insurance · US 108 GB (52,429 files) dumped May 4 after ransom deadline; policyholder names, addresses, policy numbers, financial details; Liberty Mutual confirmed "third-party vendor" investigation and denied direct system compromise; 🟨 vendor breach confirmed · https://www.bankinfosecurity.com/everest-group-begins-leaking-alleged-liberty-mutual-data-a-31589 · https://cybernews.com/security/liberty-mutual-ransomware-attack-policyholder-data/ · Sources: [BankInfoSecurity] · [Cybernews]
Apr 28 Mediaworks Kft WorldLeaks Ransomware · media · broadcasting/Hungary Hungary's largest pro-government media company (Orbán-aligned conglomerate operating national TV, radio, and print outlets); WorldLeaks DLS claim April 28-29, 2026; 15 million files (~8.5 TB) published including payroll records, contracts, financial statements, and internal communications; Hungary's National Authority for Data Protection and Freedom of Information (NAIH) confirmed unlawful exfiltration and scale; Mediaworks confirmed breach and warned journalists against circulating leaked material; 🟨 confirmed breach, scope verified by Hungarian data authority · https://therecord.media/ransomware-group-claims-breach-of-pro-orban-media-firm · https://www.redpacketsecurity.com/worldleaks-ransomware-victim-mediaworks-kft/ · https://www.dexpose.io/worldleaks-targets-hungarian-mediaworks-kft/ · Sources: [The Record] · [RedPacket Security] · [DeXpose]
Apr 25 Instructure/Canvas ShinyHunters Extortion · education technology platform · US 275 million users across 8,809 universities, educational ministries, and institutions worldwide; attack April 25, 2026; Instructure detected intrusion April 29 and revoked access; disclosed May 1; data includes student names, email addresses, student ID numbers, and user messages; described as the largest educational data breach on record; Instructure paid ransom, "shred logs" provided May 11; FBI warned students and staff of ongoing phishing risk post-ransom · https://www.malwarebytes.com/blog/news/2026/05/millions-of-students-personal-data-stolen-in-major-education-cyberattack · https://www.bitdefender.com/en-us/blog/hotforsecurity/canvas-data-breach-2026 · Sources: [Malwarebytes] · [Bitdefender]
Apr 24 Udemy ShinyHunters Extortion · education technology · US 1.4 million records claimed; listed DLS April 24, data published April 27 after ransom deadline; no Udemy public confirmation — 🟥 unverified · https://cybernews.com/security/shinyhunters-claim-udemy-data-theft/ · https://www.scworld.com/brief/udemy-allegedly-breached-by-shinyhunters-data-leak-warned · Sources: [Cybernews] · [SC Media]
Apr 21 Zara ShinyHunters Extortion · fashion retail · Spain 197,400 customer emails, product order data (order IDs, SKUs, market of purchase); Anodot/BigQuery SaaS supply chain (not PeopleSoft CVE-2026-35273); ransom deadline April 21, data published April 22 after deadline; Inditex confirmed "unauthorized access to BigQuery data via a retired third-party analytics provider" early May 2026; HIBP added May 8; no passwords or payment data affected · https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/ · https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html · https://www.infosecurity-magazine.com/news/zara-data-breach-impacts-200000/ · Sources: [BleepingComputer] · [SecurityAffairs] · [Infosecurity Magazine]
Apr 21 7-Eleven ShinyHunters Extortion · retail · convenience stores/Japan 600,000+ Salesforce CRM records; listed DLS April 21-27, 2026; data published after ransom deadline; Salesforce environment vector (not PeopleSoft CVE-2026-35273); no 7-Eleven public confirmation — 🟥 unverified · https://cybernews.com/news/shinyhunters-myteresa-zara-carnival-7eleven-data-leak/ · https://www.techradar.com/pro/security/shinyhunters-exposes-data-on-mytheresa-zara-carnival-7-eleven-over-40-organizations-tied-up-in-new-data-trove-which-will-stay-up-indefinitely · Sources: [Cybernews] · [TechRadar]
Apr 20 ADT ShinyHunters Extortion · home security · US 5.5M individuals affected (names, phone numbers, physical addresses; partial SSNs and DOBs for subset); vishing attack on ADT employee Okta SSO credentials → attacker pivoted to Salesforce CRM; breach detected April 20, access confirmed revoked April 24; ShinyHunters claimed 10M records; ADT confirmed 5.5M via HIBP notification; ADT filed breach notification and notified law enforcement; Salesforce vector (not Oracle PeopleSoft CVE-2026-35273) · https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/ · https://www.bankinfosecurity.com/home-security-firm-adt-breach-55m-customers-data-exposed-a-31511 · https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack · Sources: [BleepingComputer] · [BankInfoSecurity] · [Rescana]
Apr 20 Citizens Financial Group Everest Ransomware · banking · US shared statement-printing vendor compromised; 3.4M records (names, home addresses, account numbers, internal document flags; no SSNs confirmed); Everest DLS April 20, 2026; Citizens confirmed third-party vendor breach; class action filed US District Court Providence April 24; 🟨 vendor breach confirmed · https://www.scworld.com/brief/extensive-citizens-financial-group-frost-bank-breaches-claimed-by-everest-ransomware · https://www.americanbanker.com/news/citizens-frost-blame-vendor-after-data-breach-claim · Sources: [SC Media] · [American Banker]
Apr 20 Frost Bank Everest Ransomware · banking · US same shared vendor as Citizens Financial Group; 250K records incl. SSNs, tax IDs, mortgage rates, income data, home addresses; Everest DLS April 20, 2026; Frost confirmed third-party vendor breach; full data dumped after 6-day deadline; 🟨 vendor breach confirmed · https://www.scworld.com/brief/extensive-citizens-financial-group-frost-bank-breaches-claimed-by-everest-ransomware · https://cybernews.com/security/everest-ransomware-frost-citizens-bank-breach/ · Sources: [SC Media] · [Cybernews]
Apr 19 Cherry Health Unattributed Breach · healthcare · FQHC/US Michigan's largest independent federally qualified health center; ransomware attack detected April 19, 2026 causing days-long network outage; preliminary breach notice published June 18, 2026; unauthorized actor accessed and copied patient and staff data; compromised data varies by individual: names, addresses, phone numbers, dates of birth, health insurance ID numbers, patient ID numbers, provider names, service dates, and Social Security numbers; total affected count not yet disclosed (prior incident 2023 affected 184,000); actor unattributed; breach is distinct from the 2023 incident · https://databreaches.net/2026/06/22/cherry-health-provides-preliminary-notice-of-recent-data-breach/ · https://www.hipaajournal.com/ · https://therecord.media/cherry-health-ransomware-michigan · Sources: [DataBreaches.net] · [HIPAA Journal] · [The Record]
Apr 18 Polmed ShinyHunters Extortion · healthcare · medical scheme/South Africa Police Medical Benefits Scheme serving South African Police Service (SAPS) members and their families; 214 GB claimed; 1.7M member records exposed including 68,000 active SAPS employee numbers, home addresses, bank account details, mental health diagnostic codes, and undercover officer designations (creating national security exposure); initial access via password-spray on abandoned SAP consultant account last active 2019 but retaining domain-admin rights; ShinyHunters $1M ransom demand; Polmed board approved R67M emergency response budget (Mandiant IR retainer + credit-protection cover for all members + remediation costs); undercover officer identifiers in the dataset represent the highest-sensitivity element of this breach · https://capetown.today/news/massive-police-data-breach-raises-national-security-alarm-in-south-africa · https://www.itweb.co.za/article/saps-medical-aid-scheme-probes-potential-data-breach/P3gQ2MGA5VNvnRD1 · https://www.malwarebytes.com/blog/news/2026/05/biometrics-diagnoses-and-bank-details-exposed-in-major-healthcare-breach · Sources: [Cape Town Today] · [ITWeb] · [Malwarebytes]
Apr 16 Empower Group DragonForce Ransomware · financial services · UAE UAE financial services firm; DragonForce DLS claim April 16, 2026; 316.38 GB exfiltrated claimed; data scope unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Apr 16 Standard Bank Group PrinzEugen Ransomware · banking · financial services/South Africa 1.2 TB exfiltrated; 1 BTC ransom demanded and refused; Group is South Africa's largest bank by assets; DLS claim April 16; first widely documented Prinz Eugen victim (new Go-based strain analyzed June 20 by ThreatDown) · https://www.bleepingcomputer.com/news/security/new-prinz-eugen-ransomware-prioritizes-recent-files-for-encryption/ · https://www.threatdown.com/blog/prinz-eugen-ransomware-a-deep-dive-into-a-new-go-based-encryptor/ · Sources: [BleepingComputer] · [ThreatDown]
Apr 13 Medtronic ShinyHunters Extortion · medical devices · US global medical device manufacturer; breach April 13–19, 2026 via third-party vendor credential compromise; 3.8M individuals affected (names, contact information, product/service history; scope confirmed per Medtronic's HIPAA breach notification to HHS/OCR); customer notification letters sent July 2, 2026; class action investigation opened; medical devices and patient safety systems confirmed unaffected; 🟨 breach confirmed by Medtronic, group attribution based on ShinyHunters DLS · https://www.securityweek.com/medtronic-discloses-data-breach-impacting-3-8-million-people/ · https://www.hipaajournal.com/medtronic-data-breach-3-8-million/ · https://www.bleepingcomputer.com/news/security/medtronic-discloses-data-breach-impacting-38-million-customers/ · https://therecord.media/medtronic-data-breach-3-million · Sources: [SecurityWeek] · [HIPAA Journal] · [BleepingComputer] · [The Record]
Apr 12 Mytheresa ShinyHunters Extortion · fashion e-commerce · Germany data published post-deadline; Anodot/BigQuery SaaS supply chain vector (same vector as Rockstar Games; not PeopleSoft CVE-2026-35273); no Mytheresa public confirmation — 🟥 unverified · https://cybernews.com/news/shinyhunters-myteresa-zara-carnival-7eleven-data-leak/ · https://www.techradar.com/pro/security/shinyhunters-exposes-data-on-mytheresa-zara-carnival-7-eleven-over-40-organizations-tied-up-in-new-data-trove-which-will-stay-up-indefinitely · Sources: [Cybernews] · [TechRadar]
Apr 12 Marcus & Millichap ShinyHunters Extortion · commercial real estate brokerage · US 30M Salesforce records claimed including employee/client PII and internal corporate data; ShinyHunters claimed April 12, 2026; HIBP confirmed; no Marcus & Millichap public statement · https://www.dexpose.io/shinyhunters-target-marcus-millichap-in-major-ransomware-attack/ · https://haveibeenpwned.com/Breach/MarcusMillichap · https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-marcus-and-millichap-inc/ · https://www.breachsense.com/breaches/marcus-and-millichap-data-breach/ · Sources: [DeXpose] · [HIBP] · [HookPhish] · [Breachsense]
Apr 11 Rockstar Games ShinyHunters Extortion · gaming · technology/US 78.6M records claimed (GTA Online/Red Dead Online analytics, internal business metrics); breach April 11 via Anodot (third-party SaaS analytics) → Snowflake; ransom deadline April 14 missed, partial data published; Rockstar confirmed "limited, non-material" information; Snowflake confirmed breach was Anodot credential compromise, not Snowflake infrastructure; SaaS supply chain vector (not PeopleSoft CVE-2026-35273) · https://www.benzinga.com/markets/tech/26/04/51795873/rockstar-games-data-breach-80-million-records-anodot-snowflake · https://www.bitdefender.com/en-us/blog/hotforsecurity/rockstar-games-data-breach · https://www.deepwatch.com/labs/ca-a-26-006-shinyhunters-breaches-rockstar-games-via-third-party-cloud-integration/ · Sources: [Benzinga] · [Bitdefender] · [DeepWatch]
Apr 09 Pitney Bowes ShinyHunters Extortion · business services · logistics technology/US 8,243,989 unique customer email addresses + names, phone numbers, physical addresses (business customer Salesforce contacts); phishing attack April 8 harvested employee credentials; attacker used credentials to access Salesforce CRM and exfiltrate records; Pitney Bowes confirmed breach, secured environment, notified law enforcement; HIBP confirmed 8.2M records April 27; no SSNs or payment data accessed · https://www.theregister.com/2026/04/28/pitney_bowes_is_the_latest/ · https://www.dexpose.io/shinyhunters-breach-pitney-bowes-inc/ · https://www.teiss.co.uk/news/pitney-bowes-confirms-cyber-intrusion-as-shinyhunters-claims-breach-of-millions-of-records-17436 · Sources: [The Register] · [DeXpose] · [teiss]
Apr 01 Charter Communications ShinyHunters Extortion · telecommunications · US 40-42M records claimed (13M+ individually confirmed); names, email/physical addresses, phone numbers, subscription plan details, support tickets, CPNI; vishing attack April 1 2026 targeting Microsoft Entra credentials; attacker pivoted to Salesforce CRM; Charter disclosed publicly May 26 one day before ShinyHunters' May 27 ransom deadline; 50GB data published after ransom refusal; Charter disputes CPNI exfiltration, ShinyHunters disputes claim with screenshots; access via Salesforce/Entra (not PeopleSoft CVE-2026-35273); among the largest US telecom breaches on record · https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/ · https://www.techradar.com/pro/security/charter-communications-confirms-data-breach-shinyhunters-blamed-after-threat-to-leak-user-info-online/ · https://www.scworld.com/brief/shinyhunters-extorts-charter-communications-after-data-breach · Sources: [BleepingComputer] · [TechRadar] · [SC Media]

March 2026

Mar 18 Infinite Campus ShinyHunters Extortion · education technology · US student information system serving 3,200+ school districts and 11M students across 46 US states; Salesforce account vishing attack March 18, 2026; 137,123 unique school staff accounts' data exfiltrated: names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets; Infinite Campus confirmed breach (staff data only; no evidence student databases compromised); HIBP notification June 15, 2026; Salesforce vector (not PeopleSoft CVE-2026-35273) · https://www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/ · https://cybernews.com/cybercrime/shinyhunters-data-infinite-campus-137k-students-exposed/ · https://www.techradar.com/pro/security/11-million-students-possibly-at-risk-after-classroom-software-used-by-millions-hacked · Sources: [BleepingComputer] · [Cybernews] · [TechRadar]
Mar 17 AssuranceAmerica Unattributed Breach · insurance · auto/US 14-state auto insurer headquartered in Atlanta, GA; employee credential compromise allowed unauthorized access March 17 – June 15, 2026; 6,990,000+ individuals' driver's licence numbers exfiltrated across 14 states; notification letters began July 10, 2026; actor unattributed · https://www.bleepingcomputer.com/ · https://securityaffairs.com/ · https://www.technadu.com/ · Sources: [BleepingComputer] · [SecurityAffairs] · [TechNadu]
Mar 16 Kubota North America Corporation Unattributed Breach · agricultural equipment manufacturing · US unauthorized access to HR system files March 16 – April 20, 2026; attackers exfiltrated files containing employee and dependent personal data: names, Social Security numbers, Social Insurance numbers, dates of birth, and taxpayer IDs; attack identified April 30, 2026; breach scope confirmed June 16, 2026; employee notification emails sent June 30, 2026; at minimum 2,237 Texas residents confirmed affected; no operational disruption reported; no ransomware group has claimed responsibility; actor unattributed · https://www.bleepingcomputer.com/news/security/kubota-says-hackers-had-month-long-access-to-network-systems/ · https://www.claimdepot.com/investigations/kubota-data-breach-2026 · Sources: [BleepingComputer] · [ClaimDepot]
Mar 10 CareCloud Unknown Ransomware · Healthcare Technology · USA Unauthorized access to CareCloud AWS environment March 10-16 2026; 3.7 million patients affected (names SSNs DOBs health insurance and medical records); 8-hour network disruption; notified HHS; confirmed 5th-largest healthcare data theft of 2026 · Sources: https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/
Mar 01 Kennedy McLaughlin & Associates Qilin Ransomware · accounting · Australia Qilin ransomware attack; company confirmed "cyber incident" publicly; data published approximately May 28, 2026; reported to ACSC and OAIC; 🟨 company-confirmed breach · https://www.cyberdaily.au/security/13668-exclusive-accounting-firm-kennedy-mclaughlin-confirms-cyber-incident-following-qilin-ransomware-attack · https://ransomware.live/id/S2VubmVkeSwgTWNMYXVnaGxpbiAmIEFzc29jaWF0ZXNAcWlsaW4= · Sources: [Cyber Daily] · [ransomware.live]

February 2026

Feb 24 Wynn Resorts ShinyHunters Extortion · hospitality · US 21,000 employees affected; 800,000+ records claimed including full names, SSNs, dates of birth, email addresses, and phone numbers; unauthorized access identified September 2025; Wynn confirmed breach February 24, 2026; ShinyHunters removed Wynn from DLS after ransom reportedly paid (~22 BTC / ~$1.5M); SEC 8-K filed · https://www.securityweek.com/wynn-resorts-says-21000-employees-affected-by-shinyhunters-hack/ · https://www.bleepingcomputer.com/news/security/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/ · Sources: [SecurityWeek] · [BleepingComputer]
Feb 24 LexisNexis Legal & Professional FulcrumSec Ransomware · legal research · information services/US 400,000 cloud user profiles (names, emails, phone numbers, job functions) + 2GB structured data exfiltrated from AWS environment; access via React2Shell vulnerability in unpatched React frontend app; initial access February 24, 2026; 118 .gov users exposed (federal judges, law clerks, DOJ attorneys, SEC staff); disclosed March 2026; LexisNexis characterised the accessed data as "old, non-critical" but acknowledged the intrusion; law enforcement notified · https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/ · https://therecord.media/lexisnexis-says-hackers-accessed-legacy-data · https://www.theregister.com/security/2026/03/04/lexisnexis-legal-professional-confirms-data-breach/4305422 · Sources: [BleepingComputer] · [The Record] · [The Register]
Feb 24 Strategic Education Unattributed Breach · education · US incident 23–25 Feb 2026

January 2026

Jan 13 Tepco-Group DireWolf Ransomware · electronics manufacturing · Egypt Egypt-based electronics manufacturing company; DireWolf DLS claim January 13, 2026; ~300 GB exfiltrated claimed; full data publication threatened after ransom deadline; 🟥 unverified · https://www.dexpose.io/direwolf-ransomware-attack-on-tepco-group/ · https://www.redpacketsecurity.com/direwolf-ransomware-victim-tepco-group/ · https://www.hookphish.com/blog/ransomware-group-direwolf-hits-tepco-group/ · Sources: [DeXpose] · [RedPacket Security] · [HookPhish]

September 2025

Sep 11 BerlinerLuft Technology GmbH Ethics Ransomware · Industrial/HVAC Manufacturing · DEU DLS claim by new group Ethics (debuted Aug 12, 2026); German industrial ventilation and air conditioning systems manufacturer; estimated attack date Sep 2025 · Sources: https://www.ransomlook.io/group/ethics
Sep 11 Holstrom, Block & Parke Ethics Ransomware · Legal/Professional Services · USA DLS claim by new group Ethics (debuted Aug 12, 2026); California family law and estate planning firm; one of 3 inaugural victims; estimated attack date Sep 2025 · Sources: https://www.ransomlook.io/group/ethics

May 2025

May 01 Harrods DragonForce Ransomware · retail · UK third UK retailer hit; attack confirmed 1 May 2025, access restricted to contain it · https://www.acronis.com/en/blog/posts/the-harrods-cyberattacks-a-legendary-retailer-becomes-a-target/ · https://www.picussecurity.com/resource/blog/dragonforce-ransomware-attacks-retail-giants · Sources: [Acronis] · [Picus]

April 2025

Apr 30 Co-op DragonForce Ransomware · retail · UK back-office & call-centre disruption; 10,000+ members' personal data exposed · https://www.infosecurity-magazine.com/news/dragonforce-goup-ms-coop-harrods/ · Sources: [Infosecurity]
Apr 22 Marks & Spencer DragonForce Ransomware · retail · UK ~£300M profit hit; online orders & payments disrupted for weeks; customer + employee data threatened (Scattered Spider service-desk initial access) · https://www.blackfog.com/marks-and-spencer-ransomware-attack/ · https://www.infosecurity-magazine.com/news/dragonforce-goup-ms-coop-harrods/ · Sources: [BlackFog] · [Infosecurity]