Skip to content

📡 Media & Telecom

Media, entertainment, gaming, publishing, telecommunications · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D2▼ −5
Prior 30D7
Active actor L90DThe Gentlemen · 4
Active actor L90DUnknown · 3
Active actor L90DQilin · 3

Today — 12 Sep 2026

No industry-tagged items in today's briefing — see recent activity below.

Last 14 days

A 32.8M-record Condé Nast dataset surfaces for sale at $15,000 on a Russian-language forum, pitched as the full set behind December's smaller WIRED subscriber leak.HighMedia & Telecom🟥 Unverified — Condé Nast has not confirmed the breach or the listing. Ransomnews sampled 5,000 of the 32,815,767 records and found them consistent with genuine account data (names, emails, postal addresses, gender, DOB, phone numbers — no passwords or payment data) collected Sep–Oct 2025. If genuine, it's a case study in the data-resale economy: the same underlying dataset re-surfacing at far larger claimed volume nine months after the original, smaller leak it's derived from. SecurityAffairs · Cybernews
Settra (emerging) — 4+ victims across healthcare, construction, telecom on Sep 3; now tracking as a distinct threatHighHealthcare & Life SciencesMedia & TelecomSettra (emerged June 2026, double-extortion RaaS) posted at least four victims on September 3: DiaSorin S.p.A. (Italy, healthcare/biotech), MedEvolve (US, medical billing), Hansler Smith Limited (Canada, professional services), and Teletek Structures Inc. (Canada, telecom infrastructure). The Sep 3 wave marks Settra as a group warranting dedicated monitoring; its targeting of European healthcare and North American telecom/construction on a single day suggests a surge in operational tempo. No reliable victim count or operational timeline published yet. 🟥 All DLS claims; unverified. DeXpose · SOCRadar

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 07 Conde Nast Unknown Ransomware · publishing services · US A dataset of 32,815,767 user records (names, emails, postal addresses, gender, DOB, phone numbers -- no passwords or payment data) listed for sale for $15,000 on a Russian-language cybercrime forum Sep 7, pitched as the full set behind the Dec 2025 WIRED subscriber leak (which itself totaled a fraction of this volume). Ransomnews sampled 5,000 records and found them consistent with genuine Conde Nast account data collected Sep-Oct 2025. Conde Nast has not confirmed the breach or the new sale listing. · Sources: SecurityAffairs · Cybernews

August 2026

Aug 22 Thialf The Gentlemen Ransomware · Sports / Entertainment · Netherlands TheGentlemen ransomware DLS claim August 22 2026; Thialf is an international speed skating venue in Heerenveen, Netherlands; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 11 Stade Français Paris Qilin Ransomware · Sports · FR Qilin DLS August 11, 2026; Aug 15 deadline; player passport/ID data published as proof-of-breach; club filed complaint with French authorities; no payment confirmed. · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-stade-francais/
Aug 08 Daily Trust Unknown Ransomware · Media · NGA DLS claim posted August 8 on ransomware.live; Nigerian national newspaper/news organization; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 07 Stade Français Unknown Ransomware · Sports/Entertainment · France Paris-based Top 14 rugby club; systems restored after cyberattack; data leak under investigation · Sources: https://therecord.media
Aug 03 Service Electric Qilin Ransomware · Telecommunications · US Qilin DLS claim approximately August 3 2026; US regional telecom; no statement from Service Electric; data scope and impact unconfirmed · Sources: https://www.ransomware.live/

July 2026

Jul 23 Czech Philharmonic The Gentlemen Ransomware · arts/culture · Czech Republic TheGentlemen DLS claim July 23; data volume not yet disclosed; cultural heritage institution based in Prague. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 19 Eana Qilin Ransomware · telecommunications (satellite/connectivity) · Argentina Qilin DLS posting July 19; data claimed exfiltrated; unverified — no public statement from Eana · Sources: https://www.ransomware.live
Jul 15 ATCOM Technology DragonForce Ransomware · Telecommunications/Manufacturing · Unknown Telecommunications manufacturer claimed on DragonForce DLS July 15. Country unconfirmed. No public statement. · Sources: https://www.ransomware.live/group/dragonforce
Jul 02 Ingram Content Group ShinyHunters Extortion · publishing services · book distribution/US major US book distribution, print-on-demand, and publishing-services company serving thousands of publishers worldwide; ShinyHunters DLS claim July 2, 2026; group alleged failed negotiations with victim; Salesforce data exfiltration claimed; data scope unconfirmed; no public statement from Ingram; 🟥 unverified · https://breachnews.com/breaches/shinyhunters-adds-ingram-content-group-and-fluke-corporation-to-leak-site/ · https://www.hendryadrian.com/ransom-ingram-content-group-inc-jul-2026/ · Sources: [BreachNews] · [hendryadrian.com]

June 2026

Jun 28 KDDI Corporation Unattributed Breach · telecommunications · Japan Japan's second-largest mobile carrier; 14.22 million email subscriber accounts compromised across six ISPs managed by KDDI (Chuokai, Johoku Communications, KCN Kyoto, Okayama Information Highway, Sanin Godo Bank Net, Tokai Broadband); root cause: vulnerability in third-party email management software; email subscriber account records (addresses, associated metadata) affected; KDDI confirmed breach and began customer notifications June 24-28, 2026; actor unattributed · https://therecord.media/ · https://www.securityweek.com/ · Sources: [The Record] · [SecurityWeek]
Jun 24 Alexandria Nova Ransomware · telecommunications · unknown region teleinfrastructure platform; DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/ · Sources: [ransomware.live]
Jun 24 Stadttheater Giessen The Gentlemen Ransomware · arts · culture/Germany municipal theatre serving the city of Giessen in the Mittelhessen region; publicly funded civic cultural venue; The Gentlemen DLS claim June 24, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-stadttheater-giessen/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 23 Canada Wide Media The Gentlemen Ransomware · media · Canada https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 20 Newspaper Media Group INC Ransom Ransomware · media · publishing/US US-based local news organization operating community newspapers and magazines across Central and South Jersey; DLS claim June 20, 2026; data scope and impact unconfirmed; no public statement from victim · https://www.redpacketsecurity.com/incransom-ransomware-victim-newspaper-media-group/ · Sources: [RedPacket Security]
Jun 19 ATCOM Unattributed Breach · telecom · IT services/Chile Sources: breachsense/ransomware.live DLS
Jun 15 Kodak ShinyHunters Extortion · media technology · US 2.2M records (customer PII and internal corporate data); ShinyHunters listed June 15 with a June 18 ransom deadline; Kodak confirmed "unauthorized third party illegally gained temporary access to a limited amount of company data" June 17 and engaged cybersecurity experts and law enforcement; no proof sample published; no data dump confirmed; claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://cybernews.com/security/shinyhunters-claims-kodak-hack-2-million-records/ · https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/ · https://www.techtimes.com/articles/318565/20260617/kodak-confirms-data-breach-shinyhunters-threatens-leak-22m-records.htm · Sources: [Cybernews] · [BleepingComputer] · [TechTimes]
Jun 14 INK DragonForce Ransomware · creative production · UK UK-based production studio; 102.85 GB exfiltrated; DLS claim June 14, 2026; 7–8 day data-publication ultimatum issued after ransom deadline · https://www.dexpose.io/dragonforce-ransomware-attack-on-ink/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-ink/ · Sources: [DeXpose] · [RedPacket Security]
Jun 12 American Tower Corporation ShinyHunters Extortion · telecommunications infrastructure · US 5.2M records claimed including customer and landowner PII, records linking T-Mobile/Verizon/US DHS as clients, tower asset GPS coordinates, and plaintext physical access/gate codes for cell tower compounds across the US; claimed June 12, ransom deadline June 15 (passed with no confirmed data dump); company has not issued a public statement; 🟥 unverified — treat as claimed only · https://www.dexpose.io/shinyhunters-breach-american-tower-corporation/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-american-tower-corporation/ · https://www.breachsense.com/breaches/american-tower-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
Jun 12 Zayo Group + Allstream ShinyHunters Extortion · telecommunications · US+Canada ShinyHunters claimed June 12, 2026 with a June 16 payment-or-leak deadline; data scope unconfirmed; no victim statement · https://www.dexpose.io/shinyhunters-target-zayo-group-and-allstream-in-ransomware-attack/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-zayo-com-allstream-com/ · https://www.ransomware.live/id/WmF5by5jb20gJiBBbGxzdHJlYW0uY29tQHNoaW55aHVudGVycw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 12 Nintendo of America ShadowByt3$ Ransomware · entertainment · gaming/US ShadowByt3$ claimed June 12, 2026 via compromise of TinyPulse (HR and employee-engagement SaaS platform used by Nintendo); group demanded $2M ransom with 48-hour deadline; Nintendo declined; ShadowByt3$ shifted demand to TinyPulse directly on June 14 with June 16 secondary deadline; data leaked June 16 after deadline passed; Nintendo confirmed breach "limited to internal survey content comprising a small subset of our employees" — Nintendo's own network was not compromised; attack was against TinyPulse's cloud environment; ShadowByt3$ claims 859MB including full employee names, email addresses, bank statements, W-9 tax forms, employee IDs, HR progress plans, analytics, and survey data spanning 2016–2026; 🟨 breach confirmed by Nintendo (survey content); broader scope claims unverified · https://hackread.com/nintendo-america-employee-data-shadowbyt3-tinypulse/ · https://www.nintendolife.com/news/2026/06/hacker-group-claims-to-have-stolen-nintendo-data-posts-usd2-million-ransom · https://www.technadu.com/nintendo-confirms-tinypulse-data-stolen-in-shadowbyt3-extortion-attack/629628/ · https://www.dexpose.io/shadowbyt3-targets-nintendo-via-tinypulse/ · Sources: [HackRead] · [Nintendo Life] · [TechNadu] · [DeXpose]
Jun 09 AireSpring Chaos Ransomware · managed telecom services · US Sources: ransomware.live DLS
Jun 08 Opéra Comique Qilin Ransomware · arts-culture · France Sources: ransomware.live DLS
Jun 05 Madison Square Garden Sports Corp. ShinyHunters Extortion · entertainment · sports/US 45 GB published June 16 (26M customer and corporate records); content includes facial recognition surveillance records, internal threat assessments, and personal customer data; breach June 5, ransom deadline June 15, deadline missed, data published June 16; MSG's second major breach within 6 months (prior: Cl0p/Oracle eBusiness Suite February 2026, 131,070 employees/contractors); claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://thenextweb.com/news/shinyhunters-madison-square-garden-45gb-data-leak-facial-recognition · https://www.dexpose.io/shinyhunters-breach-madison-square-garden-sports-corp/ · Sources: [The Next Web] · [DeXpose]
Jun 01 The Adviser Brain Cipher Ransomware · media · AU 350GB claimed; ransom deadline 2026-06-02 · Sources: Brain Cipher DLS
Jun 01 Dresden State Art Collections Unattributed Breach · arts-culture · Germany digital systems disrupted · actor not yet attributed · Sources: The Record

May 2026

May 22 TVN Media APT73 Ransomware · multimedia · broadcasting/Panama leading multimedia company and broadcaster based in Panama; APT73/Bashe DLS claim May 22, 2026; data scope and impact unconfirmed; APT73 noted for fabricating some high-profile claims — 🟥 unverified pending independent confirmation · https://www.dexpose.io/apt73-bashe-strikes-panamas-tvn-media/ · https://www.ransomware.live/group/apt73 · Sources: [DeXpose] · [ransomware.live]

April 2026

Apr 28 Mediaworks Kft WorldLeaks Ransomware · media · broadcasting/Hungary Hungary's largest pro-government media company (Orbán-aligned conglomerate operating national TV, radio, and print outlets); WorldLeaks DLS claim April 28-29, 2026; 15 million files (~8.5 TB) published including payroll records, contracts, financial statements, and internal communications; Hungary's National Authority for Data Protection and Freedom of Information (NAIH) confirmed unlawful exfiltration and scale; Mediaworks confirmed breach and warned journalists against circulating leaked material; 🟨 confirmed breach, scope verified by Hungarian data authority · https://therecord.media/ransomware-group-claims-breach-of-pro-orban-media-firm · https://www.redpacketsecurity.com/worldleaks-ransomware-victim-mediaworks-kft/ · https://www.dexpose.io/worldleaks-targets-hungarian-mediaworks-kft/ · Sources: [The Record] · [RedPacket Security] · [DeXpose]
Apr 11 Rockstar Games ShinyHunters Extortion · gaming · technology/US 78.6M records claimed (GTA Online/Red Dead Online analytics, internal business metrics); breach April 11 via Anodot (third-party SaaS analytics) → Snowflake; ransom deadline April 14 missed, partial data published; Rockstar confirmed "limited, non-material" information; Snowflake confirmed breach was Anodot credential compromise, not Snowflake infrastructure; SaaS supply chain vector (not PeopleSoft CVE-2026-35273) · https://www.benzinga.com/markets/tech/26/04/51795873/rockstar-games-data-breach-80-million-records-anodot-snowflake · https://www.bitdefender.com/en-us/blog/hotforsecurity/rockstar-games-data-breach · https://www.deepwatch.com/labs/ca-a-26-006-shinyhunters-breaches-rockstar-games-via-third-party-cloud-integration/ · Sources: [Benzinga] · [Bitdefender] · [DeepWatch]
Apr 01 Charter Communications ShinyHunters Extortion · telecommunications · US 40-42M records claimed (13M+ individually confirmed); names, email/physical addresses, phone numbers, subscription plan details, support tickets, CPNI; vishing attack April 1 2026 targeting Microsoft Entra credentials; attacker pivoted to Salesforce CRM; Charter disclosed publicly May 26 one day before ShinyHunters' May 27 ransom deadline; 50GB data published after ransom refusal; Charter disputes CPNI exfiltration, ShinyHunters disputes claim with screenshots; access via Salesforce/Entra (not PeopleSoft CVE-2026-35273); among the largest US telecom breaches on record · https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/ · https://www.techradar.com/pro/security/charter-communications-confirms-data-breach-shinyhunters-blamed-after-threat-to-leak-user-info-online/ · https://www.scworld.com/brief/shinyhunters-extorts-charter-communications-after-data-breach · Sources: [BleepingComputer] · [TechRadar] · [SC Media]

← All industries · Victim database →