Skip to content

🛒 Consumer & Retail

Retail, e-commerce, food & beverage, hospitality, consumer goods · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D1▼ −8
Prior 30D9
Active actor L90DQilin · 6
Active actor L90DThe Gentlemen · 6
Active actor L90DSETTRA · 6

Today — 12 Sep 2026

No industry-tagged items in today's briefing — see recent activity below.

Last 14 days

GT Distributors, a national law-enforcement/tactical-gear distributor, listed on Play's leak site Sep 8.MediumConsumer & Retail🟥 Unverified DLS claim — verify before treating as a breach; data scope unconfirmed. RedPacketSecurity
Yesterday's N-able N-central and Adobe Commerce/Magento zero-days both formalized into CISA's KEV catalog Sep 8 — Magento's flaw finally has a CVE (CVE-2026-75650).HighTechnology & SoftwareConsumer & RetailNo new technical detail beyond what was reported Sep 8 (see yesterday's briefing); this is the federal-mandate follow-through: both are now subject to BOD 26-04's risk-tiered remediation clock, which can compress to as little as three calendar days for flaws that grant full device control on exposed assets. CISA KEV
"StyleSmuggler" zero-day backdoors Magento and Adobe Commerce stores — every current version affected, no authentication required, fully patched stores compromisedCriticalConsumer & RetailTechnology & SoftwareDutch e-commerce security firm Sansec disclosed the flaw Sep 5 after observing live attacks beginning Sep 4; a two-stage chain injects PHP code via a failure report, then executes it through a failed-payment email, installing a Rust-written backdoor disguised as a kernel worker process. The first confirmed victim was running the latest 2.4.9 release with July and August patches fully applied — patch currency provided no protection. Adobe shipped a hotfix Sep 7, three days after exploitation began, but as of Sep 7 no CVE identifier had been assigned. Any Magento/Adobe Commerce store should assume compromise until the hotfix is applied and logs reviewed for the disguised process. The Hacker News · Sansec
The StyleSmuggler zero-day landing three months before peak holiday e-commerce volume is an economic timing problem as much as a technical one.HighConsumer & RetailTechnology & SoftwareEvery current Magento and Adobe Commerce release was vulnerable, including fully patched installations, which means store operators cannot simply point to their patch cadence as a defense — the flaw itself, not operator negligence, was the exposure. E-commerce platforms sit at the intersection of payment-card data, customer PII, and revenue continuity; a backdoor with three days of unauthenticated pre-patch access across an entire platform's install base is the kind of infrastructure-level fragility that a single vendor's fix timeline cannot fully absorb once holiday traffic multiplies the blast radius of any residual compromise. The Hacker News

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 08 GT Distributors Play Ransomware · law enforcement equipment · US Austin, Texas-based national distributor of tactical gear, firearms accessories and uniforms for law enforcement, military and public-safety agencies; listed on Play's leak site Sep 8 claiming internal data theft. Play uses double extortion (no upfront ransom demand in the leak note); data scope and impact unconfirmed. · Sources: RedPacketSecurity

August 2026

Aug 13 D&J Beverage Service Qilin Ransomware · Beverages · US Qilin DLS claim August 13, 2026; scope unconfirmed. · Sources: https://www.ransomware.live/group/qilin
Aug 07 Levi Strauss Unknown Ransomware · Retail/Apparel · US Social engineering of employee computers; attacker accessed corporate files; consumer data not affected; breach contained · Sources: https://therecord.media/levis-data-breach-social-engineering
Aug 03 Winn-Dixie Anubis Ransomware · Retail / Grocery · US Anubis ransomware DLS claim August 3 2026; major US Southeast grocery chain; no statement from Winn-Dixie; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 01 The Butcher Brothers Play Ransomware · Food Processing · US Play DLS claim August 1 2026; US food processing/distribution. No victim statement; no data published; no data volume disclosed. · Sources: https://www.ransomware.live/id/VGhlIEJ1dGNoZXIgQnJvdGhlcnNAcGxheQ==

July 2026

Jul 22 Estee Lauder Clop Extortion · consumer/cosmetics · US Clop exploited Oracle E-Business Suite zero-day CVE-2025-61882 to access EL HR systems (attack Aug 9 2025, discovered Jun 19 2026, disclosed via CA AG filing Jul 22 2026); exposed SSNs, passport numbers, bank account details, health info, payroll and performance data for employees; 24 months Kroll identity monitoring offered · Sources: https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
Jul 21 Fairlife (Coca-Cola subsidiary) Anubis Ransomware · food and beverage · US Anubis RaaS (emerged Dec 2024) claimed the July 16 Fairlife ransomware attack on its DLS July 21, 2026; claims ~1TB exfiltrated corporate data with ransom deadline end of week; Coca-Cola confirmed attack via SEC filing (third-party access to Fairlife IT environment); US dairy production suspended; Canadian operations unaffected; 🟥 data scope and exfiltration volume unverified · Sources: BleepingComputer · Cybernews · Coca-Cola SEC filing
Jul 18 Salina Supply Qilin Ransomware · retail (home improvement/building supplies) · United States Qilin DLS posting July 18; data claimed exfiltrated; unverified — no public statement from Salina Supply · Sources: https://www.ransomware.live
Jul 17 Danone Qilin Ransomware · food/beverage manufacturing · FR Qilin DLS claim July 17: 221 GB claimed (91,558 files) including year-end financial summaries, customer account database, NDAs, and quarterly sales reports 2023-2025. Danone has not confirmed; treat as claim only. · Sources: https://cybernews.com/news/danone-evian-silk-international-delight-qilin-ransomware-attack/ · https://www.ransomware.live/group/qilin
Jul 16 Fairlife LLC (Coca-Cola subsidiary) Unattributed Breach · Food & Beverage / Dairy Manufacturing · US Coca-Cola subsidiary Fairlife detected unauthorised third-party access to production-related systems on July 16 2026; ransomware event halted all US dairy production including Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan; Canada operations unaffected; no actor claimed responsibility; no data theft confirmed; investigation ongoing with outside advisors; law enforcement notified · Sources: https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/ · https://www.theregister.com/cyber-crime/2026/07/17/ransomware-curdles-production-at-coca-colas-fairlife-dairy-biz/5274157 · https://www.helpnetsecurity.com/2026/07/17/coca-cola-fairlife-ransomware-attack/
Jul 13 Nichirei Corporation RansomHouse Ransomware · Food & Logistics · Japan Ransomware attack disrupted 140 cold-chain distribution centers; impact on KFC Japan (1,300+ restaurants), Aeon, Kura Sushi supply chains. DLS claim posted Jul 22-23; data theft scope unverified. · Sources: https://www.japantimes.co.jp/business/2026/07/22/companies/nichirei-cyberattack-ransomhouse/
Jul 11 Carita The Gentlemen Ransomware · retail · France French luxury skincare and cosmetics brand claimed on The Gentlemen data leak site July 11; data type and volume unconfirmed; company has not issued a public statement · Sources: ransomware.live · breachsense.com
Jul 10 Lidl Unattributed Breach · retail · Germany Third-party IT service provider breach; customer data from Lidl online shops in Germany, Belgium, and Netherlands exfiltrated; names, phone numbers, email addresses, dates of birth, customer numbers, and salutations exposed; passwords, billing/delivery addresses, bank details, and payment information potentially compromised; Lidl notified affected customers July 10; Dutch and Belgian data protection authorities notified; forensic investigation ongoing · Sources: BleepingComputer · Help Net Security · SC Media
Jul 08 Wade's Dairy Akira Ransomware · food · dairy manufacturing/US Akira DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/akira · Sources: [SharkStriker] · [ransomware.live]
Jul 07 Mercado Libre The Gentlemen Ransomware · e-commerce · technology/Argentina Latin America's largest e-commerce and fintech platform; The Gentlemen DLS claim July 7, 2026; approximately 118,244 users reportedly affected; company has not issued a public statement; data scope and impact unconfirmed; 🟥 unverified — verify before treating as breach · https://www.escudodigital.com/en/cybersecurity/mercado-libre-hit-by-ransomware-attack.html · https://blog.rankiteo.com/mer1783492030-mercado-libre-ransomware-july-2026/ · https://www.ransomware.live/id/TWVyY2FkbyBMaWJyZUB0aGVnZW50bGVtZW4= · Sources: [EscudoDigital] · [Rankiteo] · [ransomware.live]
Jul 06 AC Beverage Unattributed Breach · beverage · US PEAR DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/pear · Sources: [ransomware.live]
Jul 02 Dixie Beverage West Qilin Ransomware · beverage distribution · US Qilin DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 02 Pennant Hills Golf Club Qilin Ransomware · hospitality · Australia Qilin DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · https://www.hendryadrian.com/ransom-pennant-hills-golf-club-jul-2026/ · Sources: [ransomware.live] · [hendryadrian.com]
Jul 02 Tofutown Payload Ransomware · food manufacturing · organic plant-based foods/Germany traditional organic food manufacturer (est. 1981; vegan spreads, tofu, seitan products); Payload DLS claim July 2, 2026 (07:26 UTC); data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/payload · https://www.hendryadrian.com/ransom-tofutown-jul-2026/ · Sources: [ransomware.live] · [hendryadrian.com]
Jul 02 JS Hotels LockBit Ransomware · Hospitality · Spain Spanish hospitality group (jshotels.com) operating 10 hotel properties in Majorca; listed on LockBit 5.0 DLS approximately July 2 2026. DLS claim unverified. · Sources: https://www.ransomware.live/id/anNob3RlbHMuY29tQGxvY2tiaXQ1
Jul 01 Refinery Hotel Akira Ransomware · hospitality · hotel/US luxury boutique hotel near Bryant Park (197 rooms, Parker & Quinn restaurant, Refinery Rooftop bar); Akira DLS claim July 1, 2026; 15 GB claimed including employee PII (passports, driver's licenses, SSNs, W-9 forms), guest information, financials, contracts and agreements, and NDAs; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.redpacketsecurity.com/akira-ransomware-victim-refinery-hotel/ · https://www.hookphish.com/blog/ransomware-group-akira-hits-refinery-hotel/ · https://ransomware.live/id/UmVmaW5lcnkgSG90ZWxAYWtpcmE= · Sources: [RedPacket Security] · [HookPhish] · [ransomware.live]
Jul 01 Starpool WorldLeaks Ransomware · wellness · spas/Italy Italian designer and manufacturer of premium wellness cabins, saunas, steam rooms, and hydromassage systems; WorldLeaks DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/worldleaks · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jul 01 B'Laofood Joint Stock Company KRYBIT Ransomware · food manufacturing · Vietnam KRYBIT DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/krybit-ransomware-attack-on-blaofood-joint-stock-company/ · https://www.ransomware.live/id/Ymxhb2Zvb2QuY29tQGtyeWJpdA · Sources: [DeXpose] · [ransomware.live]
Jul 01 Hotel de la Bourse LockBit Ransomware · Hospitality · France Hotel in Mulhouse, France (hotel-bourse.com) listed on LockBit 5.0 DLS approximately July 1 2026, discovered July 11 2026. DLS claim unverified. · Sources: https://ransomware.live/id/aG90ZWwtYm91cnNlLmNvbUBsb2NrYml0NQ==

June 2026

Jun 30 Hwa Seng Water Resources Biotech Co., Ltd. DragonForce Ransomware · beverage manufacturing · Taiwan DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 Pou Sheng International Holdings The Gentlemen Ransomware · footwear retail · China+Hong Kong China-based athletic footwear retailer and Yue Yuen Group subsidiary; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jun 30 SDEZ The Gentlemen Ransomware · textile services · France historic French family-owned company (est. 1816) specialising in industrial rental and maintenance of professional linen, workwear, and hygiene equipment; national network of industrial laundries across France and Belgium; 700+ employees; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/U0RFWkB0aGVnZW50bGVtZW4= · Sources: [ransomware.live]
Jun 30 Mondottica The Gentlemen Ransomware · fashion · luxury eyewear/Italy global luxury eyewear company specialising in design, production, and worldwide distribution of premium sunglasses and optical frames under licensed brand names; international operations across Europe and APAC; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-mondottica/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30 Arkın Group BlackNevas Ransomware · hospitality · casino/Northern Cyprus diversified hospitality and gaming conglomerate in Northern Cyprus (casino resorts, hotels); BlackNevas DLS claim June 30, 2026; 1.4 TB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/blacknevas · https://www.redpacketsecurity.com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 30 Tour Edge SETTRA Ransomware · sporting goods · golf equipment manufacturing/US US-based golf equipment manufacturer producing irons, woods, hybrids, and wedges across multiple premium lines; SETTRA DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-targets-golf-manufacturer-tour-edge/ · https://www.ransomware.live/group/settra · Sources: [DeXpose] · [ransomware.live]
Jun 30 VCNY Home SETTRA Ransomware · home textiles · consumer goods/US US-based home textiles company (bedding, bath, and decorative products; distributed through major US retail chains); SETTRA DLS claim June 30, 2026; estimated attack date June 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/id/dmNueWhvbWUuY29tQHNldHRyYQ== · Sources: [FalconFeeds] · [ransomware.live]
Jun 29 GDN AR INC Ransom Ransomware · grocery · food retail/Argentina Argentine grocery store operator headquartered in Ciudad Autónoma de Buenos Aires; INC Ransom DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/R0ROIEFSKERvcmlua2EpQGluY3JhbnNvbQ · Sources: [ransomware.live]
Jun 29 Canopy Brands SETTRA Ransomware · consumer goods · US SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/Y2Fub3B5YnJhbmRzLnVzQHNldHRyYQ== · https://x.com/FalconFeedsio/status/2070588706558550063 · Sources: [ransomware.live] · [FalconFeeds]
Jun 29 Quality Dining Inc. SETTRA Ransomware · food services · restaurant operator/US one of the largest US Burger King and Chili's franchise operators (Indiana-based); SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/settra · Sources: [ransomware.live]
Jun 28 1-800-Dentist Qilin Ransomware · consumer services · dental referral/US US national dental referral and appointment-scheduling service (connects patients with 25,000+ dentist offices nationwide); Qilin DLS claim June 28, 2026; estimated attack date June 28; data scope and impact unconfirmed; 🟥 unverified — verify before treating as a breach · https://www.redpacketsecurity.com/qilin-ransomware-victim-1-800-dentist/ · https://www.ransomware.live/id/MS04MDAtZGVudGlzdEBxaWxpbg== · Sources: [RedPacket Security] · [ransomware.live]
Jun 28 ESHA Research/ESHA Cloud Services Stormous Ransomware · food · nutrition software/US food and beverage nutrition database and regulatory compliance software company (Salem, Oregon); core product development databases allegedly accessed; Stormous DLS claim June 28, 2026; 🟥 unverified — no vendor statement · https://www.hookphish.com/blog/ransomware-group-stormous-hits-eshacloudqa-com/ · https://socradar.io/free-tools/ransomware-intelligence/victims/eshacloudqa-com-352c7808 · Sources: [HookPhish] · [SOCRadar]
Jun 28 Monoprix.tn Stormous Ransomware · retail · Tunisia Tunisian supermarket and retail chain (monoprix.tn); Stormous DLS claim June 28, 2026; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/id/bW9ub3ByaXgudG5Ac3Rvcm1vdXM · Sources: [ransomware.live]
Jun 28 LifeVantage Corporation SETTRA Ransomware · health and wellness supplements · US publicly traded direct-sales nutritional supplement company (NASDAQ: LFVN); SETTRA DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-hits-lifevantage-corporation/ · https://ransomware.live/id/bGlmZXZhbnRhZ2UuY29tQHNldHRyYQ== · Sources: [DeXpose] · [ransomware.live]
Jun 28 PChome Online Inc. SETTRA Ransomware · e-commerce · Taiwan one of Taiwan's largest online retail and e-commerce platforms; breach estimated June 10, 2026 via infostealer malware compromising employee and customer accounts; 35,000+ users and employees' credentials and personal data exposed; SETTRA DLS claim June 28, 2026; 🟥 unverified — no PChome public statement · https://www.dexpose.io/settra-ransomware-attack-on-pchome-online-inc/ · https://www.galaxywarden.com/blog/breach/pchome-settra-ransomware-june-2026 · https://socradar.io/free-tools/ransomware-intelligence/victims/pchome-com-tw-bcdbab3d · Sources: [DeXpose] · [GalaxyWarden] · [SOCRadar]
Jun 25 impulso-store.com Stormous Ransomware · e-commerce · Italy Italian online retail platform; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25 Au Vieux Campeur The Gentlemen Ransomware · outdoor equipment retail · France French outdoor gear chain (24 stores, 180,000+ members); company confirmed cyberattack June 2, 2026 and mobilised incident response; DLS claim appeared June 25 after 23-day negotiation window closed without ransom payment; data scope unconfirmed · https://frenchbreaches.com/alertes/au-vieux-campeur-mq5ponk61juevh4e5fj · https://www.cyberattaque.org/au-vieux-campeur-victime-dune-cyberattaque-une-enquete-est-en-cours/ · https://www.ransomware.live/ · Sources: [FrenchBreaches] · [Cyberattaque.org] · [ransomware.live]
Jun 25 Frosty Acres Brands Booba Ransomware · foodservice · food distribution cooperative/US US-based national foodservice cooperative and purchasing organisation (member-owned, c.5,000+ restaurants and foodservice operators); Booba DLS claim June 25, 2026; data scope unconfirmed; group warned full data leak unless negotiations initiated; no victim statement · https://www.dexpose.io/booba-ransomware-strikes-frosty-acres-brands/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 24 montechiaro-store.com Stormous Ransomware · consumer services · e-commerce/unknown DLS claim June 24, 2026; "complete customer and buyer data" claimed; scope unconfirmed · https://www.redpacketsecurity.com/stormous-ransomware-victim-montechiaro-store-com/ · Sources: [RedPacket Security]
Jun 24 lorenzoni-store.com Stormous Ransomware · fashion · knitwear retail/Italy Lorenzoni brand of Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969; Italian family-run knitwear manufacturer with three brands: Lorenzoni, Montechiaro, Impulso); DLS claim June 24, 2026; "complete data" belonging to customers and buyers claimed; part of the same parent-company incident as montechiaro-store.com (June 24) and impulso-store.com (June 25) · https://www.redpacketsecurity.com/stormous-ransomware-victim-lorenzoni-store-com/ · https://x.com/FalconFeedsio/status/2069899152281207018 · Sources: [RedPacket Security] · [FalconFeeds]
Jun 24 maglificioliliana.com Stormous Ransomware · textile · knitwear manufacturing/Italy parent company Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969, Montichiari; specialises in high-quality knitwear, operates three brands: Lorenzoni, Montechiaro, Impulso); 400+ GB of sensitive data claimed exfiltrated, including product designs, orders, and customer and operational records; DLS claim June 24, 2026; scope of all four brand/domain listings suggests a full-group compromise · https://www.hookphish.com/blog/ransomware-group-stormous-hits-maglificioliliana-com/ · https://x.com/FalconFeedsio/status/2069899152281207018 · Sources: [HookPhish] · [FalconFeeds]
Jun 24 Sapporo Holdings Unattributed Breach · food and beverage · Japan Sapporo Holdings Ltd. disclosed June 24, 2026 that two overseas subsidiaries sustained suspected unauthorized access: Pokka Corporation Singapore (regional food and beverage company) and Sleeman Breweries (Canadian craft brewer); suspicious network activity detected, affected systems shut down pending investigation; no confirmed data exfiltration as of initial disclosure; no confirmed domestic (Japan) impact; actor unattributed; part of broader wave of cyberattacks against Japanese multinationals in June 2026 (alongside Aflac Japan, KDDI, Nidec) · https://therecord.media/japan-cyber-breaches-aflac-sapporo-nidec-kddi · https://www.ppln.co/en/post/japan-cyber-incidents-june-2026-eng · Sources: [The Record] · [Pipeline.co]
Jun 23 Nike, Inc. WorldLeaks Ransomware · consumer goods · US 1.4TB claimed; 188,347 files alleged to include R&D technical packs, bill-of-materials (BoMs), product prototypes, manufacturing schematics, and internal documents; WorldLeaks DLS claim June 23, 2026; full data dump published live; Nike confirmed it is investigating the incident and has engaged external cybersecurity experts; scope and authenticity not independently verified; 🟨 breach under investigation · https://www.infosecurity-magazine.com/news/worldleaks-ransomware-14tb-nike/ · https://www.darkreading.com/cyberattacks-data-breaches/worldeaks-extortion-group-stole-1-4tb-nike-data · https://www.computing.co.uk/news/2026/security/nike-confirms-investigation-of-1-4tb-nike-data · Sources: [Infosecurity Magazine] · [Dark Reading] · [Computing]
Jun 23 Randa Apparel & Accessories Chaos Ransomware · apparel · fashion/US global apparel and accessories manufacturer (Dockers, Tommy Hilfiger, PGA TOUR licensed brands); DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.dexpose.io/chaos-ransomware-strikes-randa-apparel-accessories/ · https://www.ransomware.live/group/chaos · Sources: [DeXpose] · [ransomware.live]
Jun 23 KliknKlik.com APT73 Ransomware · retail · computer equipment/Indonesia online retailer and distributor of computer hardware; APT73 DLS claim June 23; data exposure scope unconfirmed; APT73 (aka Bashe) noted for fabricating some high-profile claims — treat as 🟥 unverified pending confirmation · https://www.ransomware.live/group/apt73 · https://www.dexpose.io/apt73-bashe-ransomware-attack-on-medika-plaza/ · https://www.cloudsek.com/blog/unmasking-media-hungry-ransomware-groups-bashe-apt73 · Sources: [ransomware.live] · [DeXpose] · [CloudSEK]
Jun 21 Artistic Smiles NightSpire Ransomware · consumer services · US https://www.redpacketsecurity.com/nightspire-ransomware-victim-artistic-smiles/ · Sources: ransomware.live DLS / [RedPacket Security]
Jun 17 Diamond Truck Centres Aur0ra Ransomware · vehicle dealership · Canada Sources: ransomware.live DLS
Jun 17 Framesi INC Ransom Ransomware · professional beauty · cosmetics manufacturing/Italy Sources: ransomware.live DLS
Jun 17 Ecovacs Robotics SpaceBears Ransomware · consumer robotics · China Sources: ransomware.live DLS
Jun 15 Kawai Musical Instruments Mfg. Co., Ltd. SafePay Ransomware · musical instruments manufacturing · Japan renowned Japanese manufacturer of pianos, digital keyboards, and band/orchestral instruments; SafePay DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/safepay-ransomware-attack-on-kawai-musical-instruments/ · https://www.ransomware.live/id/a2F3YWl1cy5jb21Ac2FmZXBheQ== · https://www.hendryadrian.com/ransom-kawaius-com-jun-2026/ · Sources: [DeXpose] · [ransomware.live] · [hendryadrian.com]
Jun 15 Sysco ShinyHunters Extortion · food distribution · US 61M Salesforce records claimed; ShinyHunters listed June 15, weeks after Sysco was separately targeted by Qilin ransomware (two distinct threat actors targeting the same org); Sysco has not publicly confirmed this incident; 🟥 unverified — treat as claimed only · https://cybernews.com/news/sysco-shinyhunters-61-million-salesforce-records/ · Sources: [Cybernews]
Jun 12 JCPenney / Catalyst Brands / Authentic Brands Group ShinyHunters Extortion · retail · US hundreds of thousands of records claimed (SSNs, DOBs, W-2 tax forms, payroll records, driver's licenses, government-issued IDs); ShinyHunters claimed June 12; threatened to publish by June 15; no JCPenney/Catalyst/Authentic public statement; class action investigation launched (Edelson Lechtzin LLP, June 18); no data samples published; 🟥 unverified — treat as claimed only · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-jcpenney-several-other-subsdiaries-under-catalyst-brands-authentic-brands-group/ · https://cybernews.com/security/shinyhunters-jcpenney-retail-data-leak-claim/ · https://www.dexpose.io/shinyhunters-breaches-jcpenney-and-catalyst-brands/ · Sources: [RedPacket Security] · [Cybernews] · [DeXpose]
Jun 09 Rockaway River Country Club Akira Ransomware · hospitality · US Sources: ransomware.live DLS
Jun 09 Spratley's of Mortimer PrinzEugen Ransomware · retail-consumer services · UK posted twice on DLS; de-duped · Sources: ransomware.live DLS
Jun 08 Plaza Lama Payload Ransomware · retail · Dominican Republic Sources: ransomware.live DLS
Jun 08 Villea Hotels Payload Ransomware · hospitality · — Sources: ransomware.live DLS

← All industries · Victim database →