Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
13201 confirmed5377 unverified claims
24 victims last 24 hours456 victims · Month to date through 2026-08-11 13:58 UTC5,370 victims · Year to date through 2026-08-11 13:58 UTC49 groups active · Month to date through 2026-08-11 13:58 UTC
Claims tracked since 2026-01-01.
Of 13,201 confirmed breaches, 5,331 come from the California Attorney General portal, which publishes no individuals-affected count. Those rows, and any other government-source row whose portal did not publish a count, read "Not reported" here (5,332 in all): the source's own gap, not omission on our part.
Filter to "Removed from leak site" to surface victims a ransomware group has taken off its own leak site. A removal can signal that the incident was resolved or the ransom paid, but a group can also remove a victim after a fake or withdrawn claim, or by taking down its own site, so it is an observation only, never a guarantee or confirmation of payment.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
No breach entries match your current filters. Reset search and filters to show all breach entries.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (including its 42 CFR Part 2 records), Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).