Full stored descriptionConsilio.com was claimed on October 1, 2026 by lockbit5.
State now. Changed: +186 tier promotions, +1 known-exploited vulnerability addition, 6 leak-site claims, and 4 confirmed breaches since yesterday.
Breaches and leak-site claims
Compare confirmed breaches with clearly labelled, unverified leak-site claims, each linked to its named source.
Two kinds of record, always labeled: CONFIRMED breaches published by a regulator, the Securities and Exchange Commission (SEC), or Have I Been Pwned, and CLAIMS posted by ransomware groups on their leak sites, which stay unverified until the affected organization confirms. Sources are listed at the bottom of the page.
Why now: 35 leak-site claims were first observed in the last 24 hours.
Claims tracked since 2020-01-12. The 24-hour figure is a rolling window; month and year are calendar periods (UTC), so on the first days of a month the 24-hour count can exceed the month-to-date count.
5,687 confirmed rows from government sources show "Not reported" because the source published no count. The California Attorney General portal, which never publishes one, supplied 5,420 confirmed rows.
What changed
This page does not publish a page-specific change count. Open the daily comparison for newly confirmed breaches and newly observed leak-site claims.
Details
The labels separate confirmed incidents from claims, and the filters below narrow the source-linked records.
Dated confirmed breaches this tracker collected per sector for 2026-09-24 through 2026-09-30, Coordinated Universal Time (UTC), compared with 2026-09-17 through 2026-09-23. Each row is dated by its own source: a Securities and Exchange Commission (SEC) filing date, a state Attorney General portal's reported date, a Department of Health and Human Services Office for Civil Rights (HHS OCR) submission date, or another government source's own disclosure date. The last column counts disclosures dated in the 24 hours before the data export; a row stored with a date but no time counts when that date is today or yesterday. Rows without a disclosure date are left out of every column, and "Unclassified" collects rows whose sector this tracker has not matched to its sector list.
| Sector | Confirmed, latest 7 days | Prior 7 days | Change | Last 24 hours |
|---|---|---|---|---|
| Financial Services | 5 | 1 | Up 400.0% | 0 |
| Healthcare | 4 | 5 | Down 20.0% | 0 |
| Business & Professional Services | 2 | 3 | Down 33.3% | 0 |
| Insurance | 2 | 1 | Up 100.0% | 0 |
| Government | 1 | 1 | No change | 0 |
| Legal | 1 | 1 | No change | 0 |
| Unclassified | 1 | 1 | No change | 0 |
| Agriculture | 1 | 0 | Up from none in the prior 7 days | 0 |
| Nonprofit | 1 | 0 | Up from none in the prior 7 days | 0 |
| Technology | 1 | 0 | Up from none in the prior 7 days | 0 |
Showing 10 of 13 sectors with a dated confirmed breach in these windows, ordered by confirmed breaches in the latest 7 days, so sectors that went quiet sort last. Every one of them is indata/breaches_index/manifest.json.
35 leak-site claims were observed in the last 24 hours, and 2 have been observed so far this month.
Newest first, by the date the source gave; each date says what it is (for example, listed by group, filed with the SEC, or submitted to the Department of Health and Human Services Office for Civil Rights, HHS OCR). A row whose source gave no date is placed by the date it was first tracked here, and a source date whose meaning we do not know is labeled "Date meaning unknown".
Full stored descriptionengic tech, a Technology sector organization, was claimed by black x on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptionZelham, Inc., a U.S. hospitality renovation general contractor, was claimed by the gentlemen on September 30, 2026.
Full stored descriptionSoftware Answers, a Banyan Software Company, a Technology sector organization, was claimed by pear on September 30, 2026.
Full stored descriptionHouston Thyroid & Endocrine Specialists, a healthcare endocrinology organization in the United States, was claimed by n0n on September 30, 2026.
Full stored descriptionThe Japan Times, a media and publishing organization in Japan, was claimed by eclipse on September 30, 2026.
Full stored descriptionSummit Electric Supply, an electrical products and solutions provider, was claimed as compromised by Vexy Ransomware on September 30, 2026.
Full stored descriptionSummit Electric Supply, a provider of electrical products and solutions, was claimed by vexy on September 30, 2026.
Full stored descriptionwolfusofsky.de was claimed by safepay on September 30, 2026.
Full stored descriptionLe Centre National de l'Expertise Hospitalière (CNEH), a French healthcare sector organization, was claimed by kairos on September 30, 2026.
Full stored descriptionTitus was claimed by play on September 30, 2026. No further details were available from the leak-site post.
Full stored descriptionAirtech Mechanical Services, a Construction & Engineering sector organization, was claimed by play on September 30, 2026. No further details were available from the leak-site post.
Full stored descriptionOrth Automobile, an Automotive sector organization, was claimed by play on September 30, 2026. No further details were available from the leak-site post.
Full stored descriptionBlaise C. Bender, PC was claimed by interlock on September 30, 2026.
Full stored descriptionBuford-Thompson Company, LTD, a construction general contractor in Texas, was claimed to have been compromised by aurora on September 30, 2026.
Full stored descriptionecon-tec.com, an industrial engineering and automation organization, was claimed by safepay on September 30, 2026.
Full stored descriptionassist2enjoy.be, a company operating in the wholesale and retail electrical household appliances sector in Belgium, was claimed by safepay on September 30, 2026.
Full stored descriptionMCAP, a mortgage securitization and servicing organization in Canada, was claimed by n0n on September 30, 2026.
Full stored descriptionDr Damiel Pugliese was claimed by lamashtu on September 30, 2026; the country and sector were not stated.
Full stored descriptionAstidental di Sabbione, a dental equipment distributor in Italy, was claimed as compromised by lamashtu on September 30, 2026.
Full stored descriptionVinco Energy, an oilfield services company operating in the oil and gas sector in Mexico, was claimed by lamashtu on September 30, 2026.
Full stored descriptionBecker Logistik, a logistics and transportation company in Germany, was claimed by lamashtu on September 30, 2026.
Full stored descriptionWilhelm Kühne, a facility services company in Germany, was claimed by lamashtu on September 30, 2026.
Full stored descriptionFiducial, a French accounting, payroll, legal, audit, banking, IT solutions, office supplies, security, and asset management organization, was claimed by lamashtu on September 30, 2026.
Full stored descriptionVirtual Ideas, a 3D visualisation and digital content studio in Australia, was claimed by lamashtu on September 30, 2026.
Full stored descriptionPROJAHN, a German manufacturer and distributor of professional precision and hand tools, was claimed by lamashtu on September 30, 2026.
Full stored descriptionAltmannshofer Sicherheits-Videotechnik, a security systems company in Germany, was claimed by lamashtu on September 30, 2026.
Full stored descriptionGERLON was claimed by lamashtu on September 30, 2026.
Full stored descriptionP***** M***** I** was claimed by netrunner on September 30, 2026. No further details were available from the leak-site post.
Full stored descriptionSitePro Rentals, a construction sector organization, was named in a claim by emperador on September 30, 2026.
Full stored descriptionclicks digital GmbH Information, a digital marketing and online projects agency based in Germany, was claimed by rhysida on September 30, 2026.
Full stored descriptionWooshin Safety Systems Co Ltd, a South Korean automobile manufacturing and automation company, was claimed by the gentlemen on September 30, 2026.
Full stored descriptionLaw Offices of R. David Williams, P.A. was claimed to be compromised by rhysida on September 30, 2026.
Full stored descriptionWooshin Systems Co., a South Korean automotive manufacturing company, was claimed by the gentlemen on September 30, 2026.
Full stored descriptionAware was claimed by the gentlemen on September 30, 2026.
Full stored descriptionwww.newyjh.com was claimed by ULose on September 30, 2026.
Full stored descriptionWest County Health Centers was claimed by storm on September 30, 2026.
Full stored descriptionStorm claimed Gardeners' Guild, a manufacturing sector organization based in Richmond, California, United States, on September 30, 2026.
Full stored descriptionLegalWise, a Business & Professional Services sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionSamwumed, a medical aid scheme in South Africa, was claimed to be compromised by thegentlemen on September 30, 2026.
Full stored descriptionEdcon, a South African retail company, was claimed compromised by thegentlemen on September 30, 2026.
Full stored descriptionDefenceBit, a cybersecurity consulting firm in Portugal, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionDatacomm Services Corporation, a low-voltage systems contractor based in Memphis, Tennessee, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionWebb Electric Company of Florida, an Energy & Utilities sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionSolaria, a restaurant chain in Indonesia, was claimed by the actor thegentlemen on September 30, 2026.
Full stored descriptionAuren, a professional services firm in Spain, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionQUALITY SPORT Topsport Italia, a Retail sector organization, was claimed by thegentlemen on September 30, 2026.
Full stored descriptionEuroprim, a digital printing and reprographics company in France, was subject to a claim by thegentlemen on September 30, 2026.
Full stored descriptionTelrad Networks, a wireless broadband equipment developer, was claimed compromised by thegentlemen on September 30, 2026.
Full stored descriptionGroupe APROSEP was claimed by thegentlemen on September 30, 2026.
Per-incident affected-count reconciliation across government breach sources is limited by what each source publishes: HHS OCR reports a nationwide count; the Washington, Oregon, and Maryland Attorneys General each report only their own state's residents affected; the Maine Attorney General portal has been offline since 2026-06-12; and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported, labelled with the population it counts.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the complete set.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited and linked as its terms require (Source: Ransomware.live). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal (offline since 2026-06-12; no rows are currently in this index), theWashington Attorney Generalbreach notifications directory, theOregon Attorney Generalbreach directory, theMaryland Attorney Generalsecurity breach notice lists, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).
How this is computed
Confirmed incidents come from the named government and breach-directory sources. Leak-site entries remain unverified claims. Windows use the recorded disclosure or observation date, and missing dates remain explicit.
Method reviewed on .