Full stored descriptionanubis claims to have obtained employee data and internal files from Quest Group on September 18, 2026.
State now. Changed: +281 tier promotions, 0 known-exploited vulnerability additions, 10 leak-site claims, and 0 confirmed breaches since yesterday.
Breaches and leak-site claims
Compare confirmed breaches with clearly labelled, unverified leak-site claims, each linked to its named source.
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Why now: 24 leak-site claims were first observed in the last 24 hours.
Claims tracked since 2024-04-19. The 24-hour figure is a rolling window; month and year are calendar periods (UTC), so on the first days of a month the 24-hour count can exceed the month-to-date count.
Of 13,384 confirmed breaches, 5,397 show "Not reported" for individuals affected because the portal published no count: all 5,396 California Attorney General rows plus 1 other government-source row. The gap is the source's, not omission on our part.
What changed
This page does not publish a page-specific change count. Open the daily comparison for newly confirmed breaches and newly observed leak-site claims.
Details
The labels separate confirmed incidents from claims, and the filters below narrow the source-linked records.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Full stored descriptionK3G Solutions Brazil, a telecommunications and information technology consulting organization in Brazil, was claimed by Panzer on September 18, 2026.
Full stored descriptionhygear.com was claimed by lockbit5 on September 18, 2026.
Full stored descriptionforus.cl, a Business & Professional Services sector organization, was claimed by lockbit5 on September 18, 2026.
Full stored descriptionVista Plastic Solutions, a plastic manufacturing organization in Canada, was claimed by play on September 18, 2026.
Full stored descriptionInglewood Golf, a Hospitality sector organization, was claimed by play on September 18, 2026.
Full stored descriptionBarrett Mahony Consulting Engineers was claimed by the play group on September 18, 2026.
Full stored descriptionPITTSRAD, a Healthcare sector organization, was claimed by Spirals on September 18, 2026.
Full stored descriptionInter, Venezuela's largest internet provider in the telecommunications and ISP sector, was claimed to be breached by N0n on September 18, 2026.
Full stored descriptionPremier Lighting & Controls was claimed by Gammax on September 18, 2026.
Full stored descriptionAuditTeam claimed an organization identified as Paid Victim 192EB2B6AD7B98D9 on September 18, 2026.
Full stored descriptionPrefix Corp was claimed by securotrop on September 18, 2026.
Full stored descriptionPayPal support operations (Transcom WorldWide), a Financial Services sector organization, was claimed by N0n on September 18, 2026.
Full stored descriptionMinistry of Education — Argentina, government and education sector, claimed by N0n on September 18, 2026.
Full stored descriptionN0n claimed on September 18, 2026 to have obtained data from AstraZeneca Türkiye, a pharmaceutical manufacturing organization in Türkiye.
Full stored descriptionN0n claims to have obtained data from STOKR, a digital securities platform in Luxembourg, on September 18, 2026.
Full stored descriptionKonnatus, a legal services and real estate organization in Brazil, was claimed by N0n on September 18, 2026.
Full stored descriptionBeLi Teacher / FSC education centers (AWS), an education and edtech sector organization in Vietnam, was claimed by N0n on September 18, 2026.
Full stored descriptionN0n claimed on September 18, 2026 to have obtained data from a Vietnamese betting operator associated with the GC789 network and Boundless TE, reportedly operating in the online gambling and agent platform sector.
Full stored descriptionUnited Federation of Teachers, an education and labor union organization in the United States, was claimed by N0n on September 18, 2026.
Full stored descriptionMPA Pharma GmbH, a pharmaceutical company, was claimed by rhysida on September 18, 2026.
Full stored descriptionAnderson Industries, a Manufacturing sector organization, was claimed by akira on September 18, 2026.
Full stored descriptionwww.roancampingholidays.com, a Hospitality sector organization, was claimed by incransom on September 18, 2026.
Full stored descriptionKendall Hunt Publishing, an educational publishing organization in the United States, was claimed by incransom on September 18, 2026.
Full stored descriptionAscend Com was reported claimed by the qilin group on September 18, 2026.
Full stored descriptionCeres Tolvas was claimed by qilin on September 18, 2026.
Full stored descriptionQilin claimed Futuro Forestal on September 18, 2026.
Full stored descriptionGrupo Juste was listed by qilin on September 18, 2026.
Full stored descriptionQilin claimed Inland and Offshore Contractors on September 18, 2026.
Full stored descriptionStorm claimed American Casting Company, an aerospace and medical investment casting foundry in the United States, on September 18, 2026.
Full stored descriptionJohnson Investment Counsel, a Financial Services sector organization, was claimed by Storm on September 18, 2026.
Full stored descriptionFirst Secure Community Bank, a financial services organization in the United States, was claimed by Storm on September 18, 2026.
Full stored descriptionThe State Bank, a banking organization in the United States, was claimed by Storm on September 18, 2026.
Full stored descriptionFirst Secure Bank and Trust, a banking organization in the United States, was claimed by Storm on September 18, 2026.
Full stored descriptionAccela.com, a cloud-based software platform serving state and local governments, was claimed to be compromised by EndZone on September 18, 2026.
Full stored descriptionAT&T, a telecommunications sector organization, was claimed to be compromised by EndZone on September 18, 2026.
Full stored descriptionANYTHINGIT, an IT asset disposition and e-waste management organization, was claimed as compromised by Spirals on September 18, 2026.
Full stored descriptionGiti Corp was claimed to be compromised by killsec on September 18, 2026.
Full stored descriptionUniversität Hamburg, a research and educational institution in Germany, was named in a claim by Panzer on September 18, 2026.
Full stored descriptionInovapy, a technology sector organization, was claimed by Panzer on September 18, 2026.
Full stored descriptionStim, a video surveillance solutions provider in France, was claimed compromised by Panzer on September 18, 2026.
Full stored descriptionReported to the California Attorney General under the state data breach notification law.
Full stored descriptionC... received a claim from SilentRansomGroup on September 17, 2026.
Full stored descriptionHarput Yapı, a residential real estate developer and construction company based in Istanbul, was claimed by krybit on September 17, 2026.
Full stored descriptionDiakoniewerk Apolda gGmbH, a social welfare organization in Germany, was claimed by krybit on September 17, 2026.
Full stored descriptionVigatec was claimed by qilin on September 17, 2026.
Full stored descriptionQilin claimed Invincible GG on September 17, 2026.
Full stored descriptionExpress Employment Professionals was claimed by Chaos on September 17, 2026.
Full stored descriptionBrainCipher claimed hoyletanner.com on September 17, 2026.
Full stored descriptionAECOM, a global infrastructure and engineering services firm, was claimed as breached by BrainCipher on September 17, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal (offline since 2026-06-12; no rows are currently in this index), Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).
How this is computed
Confirmed incidents come from the named government and breach-directory sources. Leak-site entries remain unverified claims. Windows use the recorded disclosure or observation date, and missing dates remain explicit.
Method reviewed on .