Full stored descriptionCamorim Serviços Marítimos, a maritime sector organization in Brazil, was claimed by lockbit5 on September 28, 2026.
State now. Changed: +157 tier promotions, 0 known-exploited vulnerability additions, 68 leak-site claims, and 8 confirmed breaches since yesterday.
Breaches and leak-site claims
Compare confirmed breaches with clearly labelled, unverified leak-site claims, each linked to its named source.
Two kinds of record, always labeled: CONFIRMED breaches published by a regulator, the Securities and Exchange Commission (SEC), or Have I Been Pwned, and CLAIMS posted by ransomware groups on their leak sites, which stay unverified until the affected organization confirms. Sources are listed at the bottom of the page.
Why now: 66 leak-site claims were first observed in the last 24 hours.
Claims tracked since 2020-01-12. The 24-hour figure is a rolling window; month and year are calendar periods (UTC), so on the first days of a month the 24-hour count can exceed the month-to-date count.
5,683 confirmed rows from government sources show "Not reported" because the source published no count. The California Attorney General portal, which never publishes one, supplied 5,416 confirmed rows.
What changed
This page does not publish a page-specific change count. Open the daily comparison for newly confirmed breaches and newly observed leak-site claims.
Details
The labels separate confirmed incidents from claims, and the filters below narrow the source-linked records.
66 leak-site claims were observed in the last 24 hours, and 1,101 have been observed so far this month.
Newest first, by the date the source gave; each date says what it is (for example, listed by group, filed with the SEC, or submitted to the Department of Health and Human Services Office for Civil Rights, HHS OCR). A row whose source gave no date is placed by the date it was first tracked here, and a source date whose meaning we do not know is labeled "Date meaning unknown".
Full stored descriptionArnold Center in the education sector had a breach claimed by qilin on September 28, 2026.
Full stored descriptionbakemyday.se was claimed by inc ransom on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionStarr Whitehouse Landscape Architects was claimed by play on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionEver Ready First Aid was claimed by play on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionAHEAD was claimed by inc ransom on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionnsbsd.org was claimed by inc ransom on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionGoodrich Logistics was claimed by doommageddon on September 28, 2026.
Full stored descriptionChem Process Systems Pvt. Ltd. was claimed by doommageddon on September 28, 2026.
Full stored descriptionSKLG, a freight and logistics services organization, was claimed as breached by qilin on September 28, 2026.
Full stored descriptionNew World Diagnostics was claimed by qilin on September 28, 2026.
Full stored descriptionThe Center for Kidney Care was claimed by interlock on September 28, 2026.
Full stored descriptionОткрыто для работы was claimed by vladivostok on September 28, 2026.
Full stored descriptionThe Italy Files was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionTimmermans was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionKlaassen was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionMortel was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionKraft was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionMotlik was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionTabacko was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionKokli was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionAlontsau was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionLiu was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionBodin Fredrik was claimed by imnotavillian on September 28, 2026. No further details were available from the leak-site post.
Full stored descriptionAmazon Informatica, an information technology solutions and managed services organization operating in Brazil, was claimed by the grupo emperador on September 28, 2026.
Full stored descriptionUC Components was claimed by storm on September 28, 2026.
Full stored descriptionglobal cybernetic collective claimed on September 28, 2026 that an unspecified organization faced potential exposure.
Full stored descriptionVigilia, a healthcare and support services provider, was claimed as compromised by global cybernetic collective on September 28, 2026.
Full stored descriptionHangzhou Qihan Biotech Co., Ltd. was claimed by global cybernetic collective on September 28, 2026.
Full stored descriptionShanghai Tunnel Engineering Co Ltd was claimed as compromised by global cybernetic collective on September 28, 2026.
Full stored descriptionAtcomm, a Shanghai-based public relations and digital marketing agency, was claimed by global cybernetic collective on September 28, 2026.
Full stored descriptionThe Town of Sutton, Massachusetts was claimed by global cybernetic collective on September 28, 2026.
Full stored descriptionSutton Public Schools, located in Sutton, Massachusetts, was claimed by global cybernetic collective on September 28, 2026.
Full stored descriptionKellys Home Center, a home appliances and furniture retailer, was claimed by pear on September 28, 2026.
Full stored descriptionleakeddata claimed S...d on September 28, 2026.
Full stored descriptionKnit was claimed by akira on September 28, 2026.
Full stored descriptionGeebee Garments, an apparel manufacturer, was claimed on September 28, 2026 by the akira group.
Full stored descriptionStockham Construction, a construction company in the United States, was claimed by storm on September 28, 2026.
Full stored descriptionVintners Distributors was claimed by storm on September 28, 2026.
Full stored descriptionAgra Industries, a manufacturing organization in the United States, was claimed by storm on September 28, 2026.
Full stored descriptionIT Foods Industries was claimed by shiba on September 28, 2026.
Full stored descriptionFriendly Senior Living, a senior living and healthcare provider, was claimed by shiba on September 28, 2026.
Full stored descriptionATCO Ltd was claimed as compromised by medusalocker on September 28, 2026.
Full stored descriptionLFG Holding was claimed by safepay on September 28, 2026.
Full stored descriptionfedelmundo.com.ph was claimed by safepay on September 28, 2026.
Full stored descriptionBio-Strath was claimed by safepay on September 28, 2026.
Full stored descriptionsumperk.cz, a city information and service portal, was claimed by safepay on September 28, 2026.
Full stored descriptioneagroep.com, located in Deventer, Overijssel, Netherlands, was claimed by safepay on September 28, 2026.
Full stored descriptionHoliday Inn Vilnius, a hospitality sector organization, was claimed on September 28, 2026 by safepay.
Full stored descriptionmanno.ch, a municipal administration organization in Switzerland, was claimed by safepay on September 28, 2026.
Per-incident affected-count reconciliation across government breach sources is limited by what each source publishes: HHS OCR reports a nationwide count; the Washington, Oregon, and Maryland Attorneys General each report only their own state's residents affected; the Maine Attorney General portal has been offline since 2026-06-12; and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported, labelled with the population it counts.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the complete set.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal (offline since 2026-06-12; no rows are currently in this index), theWashington Attorney Generalbreach notifications directory, theOregon Attorney Generalbreach directory, theMaryland Attorney Generalsecurity breach notice lists, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).
How this is computed
Confirmed incidents come from the named government and breach-directory sources. Leak-site entries remain unverified claims. Windows use the recorded disclosure or observation date, and missing dates remain explicit.
Method reviewed on .