Full stored descriptionWooshin Safety Systems Co Ltd, a South Korean automobile manufacturing and automation company, was claimed by the gentlemen on September 30, 2026.
State now. Changed: +41 tier promotions, 0 known-exploited vulnerability additions, 50 leak-site claims, and 0 confirmed breaches since yesterday.
Breaches and leak-site claims
Compare confirmed breaches with clearly labelled, unverified leak-site claims, each linked to its named source.
Two kinds of record, always labeled: CONFIRMED breaches published by a regulator, the Securities and Exchange Commission (SEC), or Have I Been Pwned, and CLAIMS posted by ransomware groups on their leak sites, which stay unverified until the affected organization confirms. Sources are listed at the bottom of the page.
Why now: 94 leak-site claims were first observed in the last 24 hours.
Claims tracked since 2020-01-12. The 24-hour figure is a rolling window; month and year are calendar periods (UTC), so on the first days of a month the 24-hour count can exceed the month-to-date count.
5,684 confirmed rows from government sources show "Not reported" because the source published no count. The California Attorney General portal, which never publishes one, supplied 5,417 confirmed rows.
What changed
This page does not publish a page-specific change count. Open the daily comparison for newly confirmed breaches and newly observed leak-site claims.
Details
The labels separate confirmed incidents from claims, and the filters below narrow the source-linked records.
94 leak-site claims were observed in the last 24 hours, and 1,222 have been observed so far this month.
Newest first, by the date the source gave; each date says what it is (for example, listed by group, filed with the SEC, or submitted to the Department of Health and Human Services Office for Civil Rights, HHS OCR). A row whose source gave no date is placed by the date it was first tracked here, and a source date whose meaning we do not know is labeled "Date meaning unknown".
Full stored descriptionLaw Offices of R. David Williams, P.A. was claimed to be compromised by rhysida on September 30, 2026.
Full stored descriptionWooshin Systems Co., a South Korean automotive manufacturing company, was claimed by the gentlemen on September 30, 2026.
Full stored descriptionAware was claimed by the gentlemen on September 30, 2026.
Full stored descriptionwww.newyjh.com was claimed by ULose on September 30, 2026.
Full stored descriptionWest County Health Centers was claimed by storm on September 30, 2026.
Full stored descriptionStorm claimed Gardeners' Guild, a manufacturing sector organization based in Richmond, California, United States, on September 30, 2026.
Full stored descriptionLegalWise, a Business & Professional Services sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionSamwumed, a medical aid scheme in South Africa, was claimed to be compromised by thegentlemen on September 30, 2026.
Full stored descriptionEdcon, a South African retail company, was claimed compromised by thegentlemen on September 30, 2026.
Full stored descriptionDefenceBit, a cybersecurity consulting firm in Portugal, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionDatacomm Services Corporation, a low-voltage systems contractor based in Memphis, Tennessee, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionWebb Electric Company of Florida, an Energy & Utilities sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionSolaria, a restaurant chain in Indonesia, was claimed by the actor thegentlemen on September 30, 2026.
Full stored descriptionAuren, a professional services firm in Spain, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionQUALITY SPORT Topsport Italia, a Retail sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionEuroprim, a digital printing and reprographics company in France, was subject to a claim by thegentlemen on September 30, 2026.
Full stored descriptionTelrad Networks, a wireless broadband equipment developer, was claimed compromised by thegentlemen on September 30, 2026.
Full stored descriptionGroupe APROSEP was claimed by thegentlemen on September 30, 2026.
Full stored descriptionDrinks Wines Spirits, a Retail sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionCustom Rx Shoppe, a Healthcare sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionWilliamson Dacar Associates, a Business & Professional Services sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionAgospap was claimed by thegentlemen on September 30, 2026.
Full stored descriptionDBU Construction, a Manufacturing sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionNorthern NJ Eye Institute, a Healthcare sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionTommy Garner Air Conditioning Heating, a heating and air conditioning contractor in the United States, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionAuto Höller, a multi-brand car dealership and workshop in Austria, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionVUS - The English Center, an education sector organization in Vietnam, was claimed by the threat actor thegentlemen on September 30, 2026.
Full stored descriptionJosee Bendaaa-Guerrero Asociados, a legal services organization in Nicaragua, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionDon Hierro, a Panama-based engineering, construction and manufacturing firm, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionCorswarem Group was claimed by thegentlemen on September 30, 2026.
Full stored descriptionPulmonary Services Group, a healthcare equipment and respiratory therapy services provider in Puerto Rico, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionUC Components, a fasteners and o-rings manufacturer in the United States, appeared on the Storm leak site on September 30, 2026.
Full stored descriptionStockham Construction, a commercial construction company in the United States, was claimed by Storm on September 30, 2026.
Full stored descriptionStorm claimed Vintners Distributors, a fuel retail organization operating in the United States, on September 30, 2026.
Full stored descriptionAgra Industries, an Agriculture sector organization, was claimed by Storm on September 30, 2026.
Full stored descriptionPoca Valley Bank, a financial services organization in the United States, was claimed by Storm on September 30, 2026.
Full stored descriptionNorth Hills Facility Services, a Business & Professional Services sector organization, was claimed by storm on September 30, 2026.
Full stored descriptionstorm claimed Olnick Rentals, a real estate management organization in the United States, on September 30, 2026.
Full stored descriptionCentury Management Services, a Real Estate sector organization, was claimed by storm on September 30, 2026.
Full stored descriptionSilvercup Studios, a Media & Entertainment sector organization, was claimed by storm on September 30, 2026.
Full stored descriptionintense.pl, a software development and IT consulting company in Poland, was claimed by m3rx on September 29, 2026.
Full stored descriptionCorswarem Group, a Belgian aluminium windows, doors and solar panels manufacturer, was claimed to be compromised by the gentlemen on September 29, 2026.
Full stored descriptionPulmonary Services Group, a healthcare equipment and respiratory therapy services provider in Puerto Rico, was claimed by the gentlemen on September 29, 2026.
Full stored descriptionUnique Repair Services, an appliance repair and maintenance business operating in Des Plaines, Illinois, was claimed by kairos on September 29, 2026.
Full stored descriptionAdvantech was claimed by chaos on September 29, 2026.
Full stored descriptionGibson Area Hospital & Health Services was claimed by wallstreet on September 29, 2026.
Full stored descriptionTekko Enterprises, Inc., a prime contractor based in Tooele, Utah, was claimed to have been breached by interlock on September 29, 2026.
Full stored descriptionPolikem, a manufacturing company in Colombia, was claimed by emperador on September 29, 2026.
Full stored descriptionA Korean hospital claimed by ulose on September 29, 2026.
Per-incident affected-count reconciliation across government breach sources is limited by what each source publishes: HHS OCR reports a nationwide count; the Washington, Oregon, and Maryland Attorneys General each report only their own state's residents affected; the Maine Attorney General portal has been offline since 2026-06-12; and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported, labelled with the population it counts.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the complete set.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal (offline since 2026-06-12; no rows are currently in this index), theWashington Attorney Generalbreach notifications directory, theOregon Attorney Generalbreach directory, theMaryland Attorney Generalsecurity breach notice lists, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).
How this is computed
Confirmed incidents come from the named government and breach-directory sources. Leak-site entries remain unverified claims. Windows use the recorded disclosure or observation date, and missing dates remain explicit.
Method reviewed on .