Full stored descriptionSuperior Plating Technology CO was claimed by morpheus on October 1, 2026.
State now. Changed: +188 tier promotions, +1 known-exploited vulnerability addition, 31 leak-site claims, and 27 confirmed breaches since yesterday.
Breaches and leak-site claims
Compare confirmed breaches with clearly labelled, unverified leak-site claims, each linked to its named source.
Two kinds of record, always labeled: CONFIRMED breaches published by a regulator, the Securities and Exchange Commission (SEC), or Have I Been Pwned, and CLAIMS posted by ransomware groups on their leak sites, which stay unverified until the affected organization confirms. Sources are listed at the bottom of the page.
Why now: 35 leak-site claims were first observed in the last 24 hours.
Claims tracked since 2020-01-12. The 24-hour figure is a rolling window; month and year are calendar periods (UTC), so on the first days of a month the 24-hour count can exceed the month-to-date count.
5,687 confirmed rows from government sources show "Not reported" because the source published no count. The California Attorney General portal, which never publishes one, supplied 5,420 confirmed rows.
What changed
This page does not publish a page-specific change count. Open the daily comparison for newly confirmed breaches and newly observed leak-site claims.
Details
The labels separate confirmed incidents from claims, and the filters below narrow the source-linked records.
Dated confirmed breaches this tracker collected per sector for 2026-09-24 through 2026-09-30, Coordinated Universal Time (UTC), compared with 2026-09-17 through 2026-09-23. Each row is dated by its own source: a Securities and Exchange Commission (SEC) filing date, a state Attorney General portal's reported date, a Department of Health and Human Services Office for Civil Rights (HHS OCR) submission date, or another government source's own disclosure date. The last column counts disclosures dated in the 24 hours before the data export; a row stored with a date but no time counts when that date is today or yesterday. Rows without a disclosure date are left out of every column, and "Unclassified" collects rows whose sector this tracker has not matched to its sector list.
| Sector | Confirmed, latest 7 days | Prior 7 days | Change | Last 24 hours |
|---|---|---|---|---|
| Financial Services | 4 | 1 | Up 300.0% | 0 |
| Healthcare | 3 | 5 | Down 40.0% | 0 |
| Unclassified | 3 | 1 | Up 200.0% | 0 |
| Business & Professional Services | 2 | 3 | Down 33.3% | 0 |
| Insurance | 2 | 1 | Up 100.0% | 0 |
| Government | 1 | 1 | No change | 0 |
| Legal | 1 | 1 | No change | 0 |
| Agriculture | 1 | 0 | Up from none in the prior 7 days | 0 |
| Nonprofit | 1 | 0 | Up from none in the prior 7 days | 0 |
| Technology | 1 | 0 | Up from none in the prior 7 days | 0 |
Showing 10 of 13 sectors with a dated confirmed breach in these windows, ordered by confirmed breaches in the latest 7 days, so sectors that went quiet sort last. Every one of them is indata/breaches_index/manifest.json.
35 leak-site claims were observed in the last 24 hours, and 27 have been observed so far this month.
Newest first, by the date the source gave; each date says what it is (for example, listed by group, filed with the SEC, or submitted to the Department of Health and Human Services Office for Civil Rights, HHS OCR). A row whose source gave no date is placed by the date it was first tracked here, and a source date whose meaning we do not know is labeled "Date meaning unknown".
Full stored descriptionFUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" had a claimed breach disclosed by booba team on October 1, 2026.
Full stored descriptionAssociated Gastroenterologists of Central New York, P.C., a healthcare organization operating in the United States, was claimed by booba team on October 1, 2026.
Full stored descriptionSteelco was claimed by audit team on October 1, 2026.
Full stored descriptionAUDIT ENTITY: ProMind IT was claimed by audit team on October 1, 2026.
Full stored descriptionKrycler, Ervin, Taubman & Kaminsky, an accounting, litigation support, and consulting firm in the United States, was claimed by akira on October 1, 2026.
Full stored descriptionWesmar, a marine technology organization, was claimed by akira on October 1, 2026.
Full stored descriptionDPL Group, a building materials and home improvement products supplier, was claimed by akira on October 1, 2026.
Full stored descriptionTerca was claimed by ransomhouse on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptionDisk Precision Group, a Singapore-based organization, was claimed to be compromised by krybit on October 1, 2026.
Full stored descriptionGuardian Pharmacy LLC was claimed by inc ransom on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptionDen Hartog Industries was claimed by inc ransom on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptionNorthern Counties Health Care was claimed by inc ransom on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptionPost Metal Recycling was claimed by inc ransom on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptionRimrock Foundation was claimed by inc ransom on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptionGraybar Electric Company, Inc., an electrical equipment sector organization, was claimed by redact on October 1, 2026.
Full stored descriptionC*ro *nty *es was claimed by nightspire on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptiongenesis claimed a breach of VPNE, a service management company, on October 1, 2026.
Full stored descriptionTLC Perinatal, a healthcare services provider, was claimed as compromised by genesis on October 1, 2026.
Full stored descriptionVera Science, a biotechnology company, was claimed by the genesis group on October 1, 2026.
Full stored descriptionOwens Distributors was claimed by genesis on October 1, 2026.
Full stored descriptionPark Dental received a claim from the chaos group on October 1, 2026.
Full stored descriptionLaboratorios Roemmers SAICF, a pharmaceutical company in Argentina, was claimed to be breached by aurora on October 1, 2026.
Full stored descriptionDynamic Office Solutions was claimed by qilin on October 1, 2026.
Full stored descriptionGranja Avícola La Ponderosa, a poultry manufacturing organization in Venezuela, was claimed by emperador on October 1, 2026.
Full stored descriptionConsilio.com was claimed on October 1, 2026 by lockbit5.
Full stored descriptionengic tech, a Technology sector organization, was claimed by black x on October 1, 2026. No further details were available from the leak-site post.
Full stored descriptionZelham, Inc., a U.S. hospitality renovation general contractor, was claimed by the gentlemen on September 30, 2026.
Full stored descriptionSoftware Answers, a Banyan Software Company, a Technology sector organization, was claimed by pear on September 30, 2026.
Full stored descriptionHouston Thyroid & Endocrine Specialists, a healthcare endocrinology organization in the United States, was claimed by n0n on September 30, 2026.
Full stored descriptionThe Japan Times, a media and publishing organization in Japan, was claimed by eclipse on September 30, 2026.
Full stored descriptionSummit Electric Supply, an electrical products and solutions provider, was claimed as compromised by Vexy Ransomware on September 30, 2026.
Full stored descriptionSummit Electric Supply, a provider of electrical products and solutions, was claimed by vexy on September 30, 2026.
Full stored descriptionwolfusofsky.de was claimed by safepay on September 30, 2026.
Full stored descriptionLe Centre National de l'Expertise Hospitalière (CNEH), a French healthcare sector organization, was claimed by kairos on September 30, 2026.
Full stored descriptionTitus was claimed by play on September 30, 2026. No further details were available from the leak-site post.
Full stored descriptionAirtech Mechanical Services, a Construction & Engineering sector organization, was claimed by play on September 30, 2026. No further details were available from the leak-site post.
Full stored descriptionOrth Automobile, an Automotive sector organization, was claimed by play on September 30, 2026. No further details were available from the leak-site post.
Full stored descriptionBlaise C. Bender, PC was claimed by interlock on September 30, 2026.
Full stored descriptionBuford-Thompson Company, LTD, a construction general contractor in Texas, was claimed to have been compromised by aurora on September 30, 2026.
Full stored descriptionecon-tec.com, an industrial engineering and automation organization, was claimed by safepay on September 30, 2026.
Full stored descriptionassist2enjoy.be, a company operating in the wholesale and retail electrical household appliances sector in Belgium, was claimed by safepay on September 30, 2026.
Full stored descriptionMCAP, a mortgage securitization and servicing organization in Canada, was claimed by n0n on September 30, 2026.
Full stored descriptionDr Damiel Pugliese was claimed by lamashtu on September 30, 2026; the country and sector were not stated.
Full stored descriptionAstidental di Sabbione, a dental equipment distributor in Italy, was claimed as compromised by lamashtu on September 30, 2026.
Full stored descriptionVinco Energy, an oilfield services company operating in the oil and gas sector in Mexico, was claimed by lamashtu on September 30, 2026.
Full stored descriptionBecker Logistik, a logistics and transportation company in Germany, was claimed by lamashtu on September 30, 2026.
Full stored descriptionWilhelm Kühne, a facility services company in Germany, was claimed by lamashtu on September 30, 2026.
Full stored descriptionFiducial, a French accounting, payroll, legal, audit, banking, IT solutions, office supplies, security, and asset management organization, was claimed by lamashtu on September 30, 2026.
Full stored descriptionVirtual Ideas, a 3D visualisation and digital content studio in Australia, was claimed by lamashtu on September 30, 2026.
Per-incident affected-count reconciliation across government breach sources is limited by what each source publishes: HHS OCR reports a nationwide count; the Washington, Oregon, and Maryland Attorneys General each report only their own state's residents affected; the Maine Attorney General portal has been offline since 2026-06-12; and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported, labelled with the population it counts.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the complete set.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited and linked as its terms require (Source: Ransomware.live). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal (offline since 2026-06-12; no rows are currently in this index), theWashington Attorney Generalbreach notifications directory, theOregon Attorney Generalbreach directory, theMaryland Attorney Generalsecurity breach notice lists, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).
How this is computed
Confirmed incidents come from the named government and breach-directory sources. Leak-site entries remain unverified claims. Windows use the recorded disclosure or observation date, and missing dates remain explicit.
Method reviewed on .