Full stored descriptionOnTrac, a transportation and retail company, was claimed by emperador on September 23, 2026.
State now. Changed: +2 tier promotions, 0 known-exploited vulnerability additions, 326 leak-site claims, and 0 confirmed breaches since yesterday.
Breaches and leak-site claims
Compare confirmed breaches with clearly labelled, unverified leak-site claims, each linked to its named source.
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Why now: 52 leak-site claims were first observed in the last 24 hours.
Claims tracked since 2021-01-01. The 24-hour figure is a rolling window; month and year are calendar periods (UTC), so on the first days of a month the 24-hour count can exceed the month-to-date count.
Of 13,409 confirmed breaches, 5,404 show "Not reported" for individuals affected because the portal published no count: all 5,403 California Attorney General rows plus 1 other government-source row. The gap is the source's, not omission on our part.
What changed
This page does not publish a page-specific change count. Open the daily comparison for newly confirmed breaches and newly observed leak-site claims.
Details
The labels separate confirmed incidents from claims, and the filters below narrow the source-linked records.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Full stored descriptionAbtach Ltd., a Pakistani company, was claimed compromised by Barracuda on September 23, 2026.
Full stored descriptionTomix / Grupo JOPER was claimed by space bears on September 23, 2026.
Full stored descriptionGoldstarfinancial.com had a claimed breach by brain cipher on September 23, 2026.
Full stored descriptionBrainCipher claimed the compromise of Goldstarfinancial.com on September 23, 2026.
Full stored descriptionM****n was claimed by payoutsking on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionLegis, a Latin American legal and business publisher, was claimed by rhysida on September 23, 2026.
Full stored descriptionanery.com.br was claimed by lockbit5 on September 23, 2026.
Full stored descriptionSpirals claimed on September 23, 2026 to have breached Asyad Group, a logistics organization in Oman.
Full stored descriptionALDOGROUP.COM(ALDOSHOES.COM), a Retail sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionBRILLONCONSUMER.COM(BRILLONCONSUMER.COM), a Consumer Services sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionSUUNTO.CN(SUUNTO.COM), a Consumer Services sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionSMAPCENTER-UAH.EDU, an Education sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionDAD-CO.TH was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionCLOUD-CLEARWAYGROUP.COM was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionHODERO-HOLDINGS-LTD was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionKVHELI-WORDPRESS.COM was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionCCCM-BC.CA was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionBRINKS-CO.NZ, a Business & Professional Services sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionSAUL-ORG.UK was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionCCED-COM.OM was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionINFINIGATE.CH(INFINIGATE.CO.UK), a Technology sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionSWEETLAKE-LAND-AND-OIL-CO-INC, an Energy & Utilities sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionKIRKLAND-AND-ELLIS.LLP, a Legal sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionPALIG.COM, an Insurance sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionCOLUMBIABANK.COM(UMPQUABANK.COM), a Financial Services sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionUNISALLE-EDU.CO, an Education sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionVALLEY-TRUCK-AND-TRACTOR, a Transportation & Logistics sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionKSS-ARCHITECTS-LLP, a Construction & Engineering sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionELANDRETAIL.COM-KMALL24.COM, a Retail sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionTRANSPORT-NSW.GOV.AU, a Government sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionAMEY-CO.UK, a Construction & Engineering sector organization, was claimed by clop on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionEndZone claimed Trump Mobile, a United States mobile virtual network operator, on September 23, 2026.
Full stored descriptionLemon Law, a Legal sector organization, was claimed by inc ransom on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionApollo 21 – Quality Truck, Bus & Trailer Spare Parts South Africa was claimed by blacklocks on September 23, 2026.
Full stored descriptionApex Litigation Support, a litigation services provider, was claimed to be breached by akira on September 23, 2026.
Full stored descriptionUrban Engineering, an engineering services company headquartered in Annandale, Virginia, was claimed on September 23, 2026 by akira.
Full stored descriptionHIT dd, an entertainment and gaming company based in Nova Gorica, Slovenia, was claimed by akira on September 23, 2026.
Full stored descriptionInkript was claimed by qilin on September 23, 2026.
Full stored descriptionCOSEF - Consorzio di Sviluppo Economico del Friuli was claimed by booba team on September 23, 2026.
Full stored descriptionThe Merrimack County was claimed by booba team on September 23, 2026.
Full stored descriptionbooba team claimed access to Smart Eye Care, an optometry sector organization, on September 23, 2026.
Full stored descriptionWashington County was claimed by booba team on September 23, 2026.
Full stored descriptionAGROFRUTO SAC, an Agriculture sector organization, was claimed by arcus media on September 23, 2026. No further details were available from the leak-site post.
Full stored descriptionAGROFRUTO SAC, an agroindustrial company in Peru, was claimed by arcusmedia on September 23, 2026.
Full stored descriptionCOSEF - Consorzio di Sviluppo Economico del Friuli was claimed by Booba Project on September 23, 2026.
Full stored descriptionSmart Eye Care, operating in the optometry sector, was claimed to be breached by Booba Project on September 23, 2026.
Full stored descriptionWashington County, Government Administration sector, was named in a claim by Booba Project on September 23, 2026.
Full stored descriptionRECEITA FEDERAL DO BRASIL was claimed by emperador on September 23, 2026.
Full stored descriptionAokkef was claimed to be breached by medusalocker on September 23, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal (offline since 2026-06-12; no rows are currently in this index), Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).
How this is computed
Confirmed incidents come from the named government and breach-directory sources. Leak-site entries remain unverified claims. Windows use the recorded disclosure or observation date, and missing dates remain explicit.
Method reviewed on .