Concise previewValor Defense Solutions, Inc., a defense contractor based in Odon, Indiana, was claimed by Storm on August 18, 2026.
Breaches and leak-site claims
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Claims tracked since 2026-01-01.
Of 13,237 confirmed breaches, 5,346 come from the California Attorney General portal, which publishes no individuals-affected count. Those rows, and any other government-source row whose portal did not publish a count, read "Not reported" here (5,347 in all): the source's own gap, not omission on our part.
Filter to "Removed from leak site" to surface victims a ransomware group has taken off its own leak site. A removal can signal that the incident was resolved or the ransom paid, but a group can also remove a victim after a fake or withdrawn claim, or by taking down its own site, so it is an observation only, never a guarantee or confirmation of payment.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Concise previewStandard Tool & Die, a manufacturing organization in the United States, was claimed by Storm on August 18, 2026.
Concise previewWestco Motors Cairns, an automotive dealership in Australia, was claimed by Storm on August 18, 2026.
Concise previewWindRose Health Network, a healthcare organization in the United States, was claimed on August 18, 2026.
Concise previewPenfold, a financial technology sector organization in the United Kingdom, was claimed on August 18, 2026.
Concise previewRamsey Bros, an authorized Case IH dealer operating in the agricultural sector in Australia, was claimed by the Storm group on August 18, 2026.
Concise previewTerra-Petra, an environmental engineering firm, was claimed by lockbit5 on August 18, 2026.
Concise previewScholle IPN / SIG, a packaging manufacturing organization, was named in a claim dated August 18, 2026.
Concise previewDe***up was claimed by AuditTeam on August 18, 2026. No further details were available from the leak-site post.
Concise previewincransom claimed to have compromised SD Associates Sdn Bhd on August 18, 2026.
Concise previewThird Coast Bancshares, a financial services organization, was claimed as compromised by incransom on August 18, 2026.
Concise previewWhite-Daters & Associates, Inc was claimed on August 17, 2026.
Concise previewThe University of the West Indies was claimed by qilin on August 17, 2026.
Concise previewEmpireWorks was claimed as a breach victim by the qilin group on August 17, 2026.
Concise previewBridgeport Capital Services in the United States received a claim on August 17, 2026.
Concise previewSam Pack Auto Group was claimed by play on August 17, 2026.
Concise previewBMW Group, a luxury vehicles organization, was claimed by xpl0itrs on August 17, 2026.
Concise previewincransom claimed Lansing Urgent Care on August 17, 2026.
Concise previewThe Rubber Group, a plastics manufacturing and tire and rubber organization located in the United States, was claimed on August 17, 2026.
Concise previewDL E&C, a South Korean construction and engineering company, was claimed by Panzer on August 17, 2026.
Concise preview4M Realty Company, a real estate brokerage firm in Texas, United States, was claimed on August 17, 2026.
Concise previewPlanungsgruppe M+M AG, an architecture and urban planning firm in Germany, was claimed to have had data exfiltrated on August 17, 2026.
Concise previewdirewolf claimed a breach of Arizona State University, an educational institution, on August 17, 2026.
Concise previewdirewolf posted a claim against Wishfully Studios on August 17, 2026.
Concise previewdirewolf claims access to Mighty Kingdom, a games and multimedia organization, on August 17, 2026.
Concise previewEva AI Limited was claimed by direwolf on August 17, 2026.
Concise previewAurora claimed the compromise of Natco Home Group, a home furnishings manufacturer headquartered in West Warwick, Rhode Island, on August 17, 2026.
Concise previewCastilla La Mancha, a public administration organization in Spain, was claimed to be breached by Panzer on August 17, 2026.
Concise previewDoimo Cucine, a kitchen furniture manufacturer in Italy, was claimed on August 17, 2026.
Concise previewLloyd Coils Europe, a heat exchanger manufacturer based in Czech Republic, was claimed to be compromised on August 17, 2026.
Concise previewVermont XCenter, a contact center and technology solutions organization, was claimed by dragonforce on August 17, 2026.
Concise previewMoores, a kitchen solutions provider for housing developers, was claimed to be breached by bravox on August 17, 2026.
Concise previewAlbania's Official National Teacher Training Portal, an education and government organization in Albania, claimed on August 17, 2026.
Concise previewReported to the California Attorney General under the state data breach notification law.
Concise previewReported to the California Attorney General under the state data breach notification law.
Concise previewReported to the California Attorney General under the state data breach notification law.
Concise previewAlbania's official national teacher training portal in the education and government sectors was claimed by emperador on August 16, 2026.
Concise previewQilin claims Teikoku USA on August 16, 2026.
Concise previewAGUNSA was claimed as a victim by the qilin group on August 16, 2026.
Concise previewQilin claimed Coface on August 16, 2026.
Concise previewSpoonful of Comfort was claimed by qilin on August 16, 2026.
Concise previewPanzer claims to have breached SAGASTA sro, a design and engineering company, on August 16, 2026.
Concise previewMoscord, a digital marketplace in the maritime sector, was the subject of a claim by Eclipse on August 16, 2026.
Concise previewMulino Padano was claimed by qilin on August 16, 2026.
Concise previewQilin claimed WEBA Meubelen on August 16, 2026.
Concise previewTwal Family IT Lab, a personal IT organization in Canada, was claimed by medusalocker on August 16, 2026.
Concise previewAll Parts Dry Cleaning, a dry cleaning and laundry organization in the United Kingdom, was listed by medusalocker on August 16, 2026.
Concise previewIdex Group was claimed as compromised by medusalocker on August 16, 2026.
Concise previewBija Industrie, an organization, was claimed by medusalocker on August 16, 2026.
Concise previewThecourierguy was claimed by medusalocker on August 16, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).