📡 Media & Telecom¶
Media, entertainment, gaming, publishing, telecommunications · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed
Victims L30D2▼ −5
Prior 30D7
Active actor L90DThe Gentlemen · 4
Active actor L90DUnknown · 3
Active actor L90DQilin · 3
Today — 12 Sep 2026¶
No industry-tagged items in today's briefing — see recent activity below.
Last 14 days¶
Recent victim claims¶
Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.
September 2026
Sep 07
Conde Nast
Unknown
A dataset of 32,815,767 user records (names, emails, postal addresses, gender, DOB, phone numbers -- no passwords or payment data) listed for sale for $15,000 on a Russian-language cybercrime forum Sep 7, pitched as the full set behind the Dec 2025 WIRED subscriber leak (which itself totaled a fraction of this volume). Ransomnews sampled 5,000 records and found them consistent with genuine Conde Nast account data collected Sep-Oct 2025. Conde Nast has not confirmed the breach or the new sale listing. · Sources: SecurityAffairs · Cybernews
August 2026
Aug 22
Thialf
The Gentlemen
TheGentlemen ransomware DLS claim August 22 2026; Thialf is an international speed skating venue in Heerenveen, Netherlands; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 11
Stade Français Paris
Qilin
Qilin DLS August 11, 2026; Aug 15 deadline; player passport/ID data published as proof-of-breach; club filed complaint with French authorities; no payment confirmed. · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-stade-francais/
Aug 08
Daily Trust
Unknown
DLS claim posted August 8 on ransomware.live; Nigerian national newspaper/news organization; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 07
Stade Français
Unknown
Paris-based Top 14 rugby club; systems restored after cyberattack; data leak under investigation · Sources: https://therecord.media
Aug 03
Service Electric
Qilin
Qilin DLS claim approximately August 3 2026; US regional telecom; no statement from Service Electric; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
July 2026
Jul 23
Czech Philharmonic
The Gentlemen
TheGentlemen DLS claim July 23; data volume not yet disclosed; cultural heritage institution based in Prague. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 19
Eana
Qilin
Qilin DLS posting July 19; data claimed exfiltrated; unverified — no public statement from Eana · Sources: https://www.ransomware.live
Jul 15
ATCOM Technology
DragonForce
Telecommunications manufacturer claimed on DragonForce DLS July 15. Country unconfirmed. No public statement. · Sources: https://www.ransomware.live/group/dragonforce
Jul 02
Ingram Content Group
ShinyHunters
major US book distribution, print-on-demand, and publishing-services company serving thousands of publishers worldwide; ShinyHunters DLS claim July 2, 2026; group alleged failed negotiations with victim; Salesforce data exfiltration claimed; data scope unconfirmed; no public statement from Ingram; 🟥 unverified · https://breachnews.com/breaches/shinyhunters-adds-ingram-content-group-and-fluke-corporation-to-leak-site/ · https://www.hendryadrian.com/ransom-ingram-content-group-inc-jul-2026/ · Sources: [BreachNews] · [hendryadrian.com]
June 2026
Jun 28
KDDI Corporation
Unattributed
Japan's second-largest mobile carrier; 14.22 million email subscriber accounts compromised across six ISPs managed by KDDI (Chuokai, Johoku Communications, KCN Kyoto, Okayama Information Highway, Sanin Godo Bank Net, Tokai Broadband); root cause: vulnerability in third-party email management software; email subscriber account records (addresses, associated metadata) affected; KDDI confirmed breach and began customer notifications June 24-28, 2026; actor unattributed · https://therecord.media/ · https://www.securityweek.com/ · Sources: [The Record] · [SecurityWeek]
Jun 24
Alexandria
Nova
teleinfrastructure platform; DLS claim June 24, 2026; data scope unconfirmed · https://www.ransomware.live/ · Sources: [ransomware.live]
Jun 24
Stadttheater Giessen
The Gentlemen
municipal theatre serving the city of Giessen in the Mittelhessen region; publicly funded civic cultural venue; The Gentlemen DLS claim June 24, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-stadttheater-giessen/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 23
Canada Wide Media
The Gentlemen
https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 20
Newspaper Media Group
INC Ransom
US-based local news organization operating community newspapers and magazines across Central and South Jersey; DLS claim June 20, 2026; data scope and impact unconfirmed; no public statement from victim · https://www.redpacketsecurity.com/incransom-ransomware-victim-newspaper-media-group/ · Sources: [RedPacket Security]
Jun 15
Kodak
ShinyHunters
2.2M records (customer PII and internal corporate data); ShinyHunters listed June 15 with a June 18 ransom deadline; Kodak confirmed "unauthorized third party illegally gained temporary access to a limited amount of company data" June 17 and engaged cybersecurity experts and law enforcement; no proof sample published; no data dump confirmed; claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://cybernews.com/security/shinyhunters-claims-kodak-hack-2-million-records/ · https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/ · https://www.techtimes.com/articles/318565/20260617/kodak-confirms-data-breach-shinyhunters-threatens-leak-22m-records.htm · Sources: [Cybernews] · [BleepingComputer] · [TechTimes]
Jun 14
INK
DragonForce
UK-based production studio; 102.85 GB exfiltrated; DLS claim June 14, 2026; 7–8 day data-publication ultimatum issued after ransom deadline · https://www.dexpose.io/dragonforce-ransomware-attack-on-ink/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-ink/ · Sources: [DeXpose] · [RedPacket Security]
Jun 12
American Tower Corporation
ShinyHunters
5.2M records claimed including customer and landowner PII, records linking T-Mobile/Verizon/US DHS as clients, tower asset GPS coordinates, and plaintext physical access/gate codes for cell tower compounds across the US; claimed June 12, ransom deadline June 15 (passed with no confirmed data dump); company has not issued a public statement; 🟥 unverified — treat as claimed only · https://www.dexpose.io/shinyhunters-breach-american-tower-corporation/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-american-tower-corporation/ · https://www.breachsense.com/breaches/american-tower-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
Jun 12
Zayo Group + Allstream
ShinyHunters
ShinyHunters claimed June 12, 2026 with a June 16 payment-or-leak deadline; data scope unconfirmed; no victim statement · https://www.dexpose.io/shinyhunters-target-zayo-group-and-allstream-in-ransomware-attack/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-zayo-com-allstream-com/ · https://www.ransomware.live/id/WmF5by5jb20gJiBBbGxzdHJlYW0uY29tQHNoaW55aHVudGVycw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 12
Nintendo of America
ShadowByt3$
ShadowByt3$ claimed June 12, 2026 via compromise of TinyPulse (HR and employee-engagement SaaS platform used by Nintendo); group demanded $2M ransom with 48-hour deadline; Nintendo declined; ShadowByt3$ shifted demand to TinyPulse directly on June 14 with June 16 secondary deadline; data leaked June 16 after deadline passed; Nintendo confirmed breach "limited to internal survey content comprising a small subset of our employees" — Nintendo's own network was not compromised; attack was against TinyPulse's cloud environment; ShadowByt3$ claims 859MB including full employee names, email addresses, bank statements, W-9 tax forms, employee IDs, HR progress plans, analytics, and survey data spanning 2016–2026; 🟨 breach confirmed by Nintendo (survey content); broader scope claims unverified · https://hackread.com/nintendo-america-employee-data-shadowbyt3-tinypulse/ · https://www.nintendolife.com/news/2026/06/hacker-group-claims-to-have-stolen-nintendo-data-posts-usd2-million-ransom · https://www.technadu.com/nintendo-confirms-tinypulse-data-stolen-in-shadowbyt3-extortion-attack/629628/ · https://www.dexpose.io/shadowbyt3-targets-nintendo-via-tinypulse/ · Sources: [HackRead] · [Nintendo Life] · [TechNadu] · [DeXpose]
Jun 05
Madison Square Garden Sports Corp.
ShinyHunters
45 GB published June 16 (26M customer and corporate records); content includes facial recognition surveillance records, internal threat assessments, and personal customer data; breach June 5, ransom deadline June 15, deadline missed, data published June 16; MSG's second major breach within 6 months (prior: Cl0p/Oracle eBusiness Suite February 2026, 131,070 employees/contractors); claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://thenextweb.com/news/shinyhunters-madison-square-garden-45gb-data-leak-facial-recognition · https://www.dexpose.io/shinyhunters-breach-madison-square-garden-sports-corp/ · Sources: [The Next Web] · [DeXpose]
Jun 01
The Adviser
Brain Cipher
350GB claimed; ransom deadline 2026-06-02 · Sources: Brain Cipher DLS
Jun 01
Dresden State Art Collections
Unattributed
digital systems disrupted · actor not yet attributed · Sources: The Record
May 2026
May 22
TVN Media
APT73
leading multimedia company and broadcaster based in Panama; APT73/Bashe DLS claim May 22, 2026; data scope and impact unconfirmed; APT73 noted for fabricating some high-profile claims — 🟥 unverified pending independent confirmation · https://www.dexpose.io/apt73-bashe-strikes-panamas-tvn-media/ · https://www.ransomware.live/group/apt73 · Sources: [DeXpose] · [ransomware.live]
April 2026
Apr 28
Mediaworks Kft
WorldLeaks
Hungary's largest pro-government media company (Orbán-aligned conglomerate operating national TV, radio, and print outlets); WorldLeaks DLS claim April 28-29, 2026; 15 million files (~8.5 TB) published including payroll records, contracts, financial statements, and internal communications; Hungary's National Authority for Data Protection and Freedom of Information (NAIH) confirmed unlawful exfiltration and scale; Mediaworks confirmed breach and warned journalists against circulating leaked material; 🟨 confirmed breach, scope verified by Hungarian data authority · https://therecord.media/ransomware-group-claims-breach-of-pro-orban-media-firm · https://www.redpacketsecurity.com/worldleaks-ransomware-victim-mediaworks-kft/ · https://www.dexpose.io/worldleaks-targets-hungarian-mediaworks-kft/ · Sources: [The Record] · [RedPacket Security] · [DeXpose]
Apr 11
Rockstar Games
ShinyHunters
78.6M records claimed (GTA Online/Red Dead Online analytics, internal business metrics); breach April 11 via Anodot (third-party SaaS analytics) → Snowflake; ransom deadline April 14 missed, partial data published; Rockstar confirmed "limited, non-material" information; Snowflake confirmed breach was Anodot credential compromise, not Snowflake infrastructure; SaaS supply chain vector (not PeopleSoft CVE-2026-35273) · https://www.benzinga.com/markets/tech/26/04/51795873/rockstar-games-data-breach-80-million-records-anodot-snowflake · https://www.bitdefender.com/en-us/blog/hotforsecurity/rockstar-games-data-breach · https://www.deepwatch.com/labs/ca-a-26-006-shinyhunters-breaches-rockstar-games-via-third-party-cloud-integration/ · Sources: [Benzinga] · [Bitdefender] · [DeepWatch]
Apr 01
Charter Communications
ShinyHunters
40-42M records claimed (13M+ individually confirmed); names, email/physical addresses, phone numbers, subscription plan details, support tickets, CPNI; vishing attack April 1 2026 targeting Microsoft Entra credentials; attacker pivoted to Salesforce CRM; Charter disclosed publicly May 26 one day before ShinyHunters' May 27 ransom deadline; 50GB data published after ransom refusal; Charter disputes CPNI exfiltration, ShinyHunters disputes claim with screenshots; access via Salesforce/Entra (not PeopleSoft CVE-2026-35273); among the largest US telecom breaches on record · https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/ · https://www.techradar.com/pro/security/charter-communications-confirms-data-breach-shinyhunters-blamed-after-threat-to-leak-user-info-online/ · https://www.scworld.com/brief/shinyhunters-extorts-charter-communications-after-data-breach · Sources: [BleepingComputer] · [TechRadar] · [SC Media]