Concise previewOz Hair & Beauty, a hair and beauty products organization, was claimed by xpl0itrs on August 15, 2026.
Breaches and leak-site claims
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Claims tracked since 2026-01-01.
Of 13,213 confirmed breaches, 5,333 come from the California Attorney General portal, which publishes no individuals-affected count. Those rows, and any other government-source row whose portal did not publish a count, read "Not reported" here (5,334 in all): the source's own gap, not omission on our part.
Filter to "Removed from leak site" to surface victims a ransomware group has taken off its own leak site. A removal can signal that the incident was resolved or the ransom paid, but a group can also remove a victim after a fake or withdrawn claim, or by taking down its own site, so it is an observation only, never a guarantee or confirmation of payment.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Concise previewAn unnamed victim in the school management software sector was claimed by xpl0itrs on August 15, 2026.
Concise previewRapidFort, a software supply chain security organization, was claimed as compromised by xpl0itrs on August 15, 2026.
Concise previewDodoPayments, a financial software organization, appears on the direwolf leak-site claim posted on August 15, 2026.
Concise previewAAM:HOA Management was claimed by direwolf on August 15, 2026.
Concise previewColla Health, a healthcare organization, was claimed by direwolf on August 15, 2026.
Concise previewPayrHealth, a healthcare sector organization, became the subject of a claim by direwolf on August 15, 2026.
Concise previewservmarmg.cl was claimed by ms13089 on August 15, 2026.
Concise previewSEARS (Grupo Sanborns), a Mexican retail company, was claimed by spacebears on August 15, 2026.
Concise previewSecurotrop claimed Lepi Enterprises on August 15, 2026.
Concise previewBarracuda claimed to have obtained data from VR Advogados, a Brazilian law firm, on August 15, 2026.
Concise previewwww.amca.org.ar received a claim from blackwater on August 15, 2026.
Concise previewwww.shalina.com experienced a claimed system breach on August 15, 2026.
Concise previewInterim HealthCare, a home healthcare and medical staffing organization, appeared in a claim by anubis on August 15, 2026.
Concise previewAlpine Electronics Europe, an automotive electronics and audio products distributor, was claimed by Panzer on August 15, 2026.
Concise previewFERRARI MANGIMI SRL was claimed to be breached by the actor qilin on August 14, 2026.
Concise previewgranjarinya.com was claimed by safepay on August 14, 2026.
Concise previewConnections received a claim from qilin on August 14, 2026.
Concise previewConnell Enterprises LLC was claimed to be compromised by interlock on August 14, 2026.
Concise previewTurner and Townsend, a professional services firm, was claimed by coinbasecartel on August 14, 2026.
Concise previewSerruya Private Equity, a private equity firm in Canada, was claimed by coinbasecartel on August 14, 2026.
Concise previewSweet Water Holdings was claimed by coinbasecartel on August 14, 2026.
Concise previewKeystops, a fuel distribution and petroleum products company, was claimed by akira on August 14, 2026.
Concise previewCozad Asset Management, a financial services firm, was claimed by akira on August 14, 2026.
Concise previewQilin posted a claim involving Aletex Group on August 14, 2026.
Concise previewPierce Township, a municipality in Ohio, had data claimed on August 14, 2026.
Concise previewRadiant was claimed to be breached by qilin on August 14, 2026.
Concise previewZEBRA.COM had data claimed exfiltrated by clop on August 14, 2026.
Concise previewLercher Werkzeugbau was claimed by the qilin group on August 14, 2026.
Concise preview3f was claimed by qilin on August 14, 2026.
Concise previewPenLink experienced a claimed breach by qilin on August 14, 2026.
Concise previewUrban Worldwide received a claim from the qilin group on August 14, 2026.
Concise previewTecnologías de Código Abierto S.L., a software development company in Spain, was claimed to be compromised on August 14, 2026.
Concise previewHinman Straub, a law firm in the United States, was claimed by Storm on August 14, 2026.
Concise preview3-point Australia, a project management consultancy in Australia, was claimed by Storm on August 14, 2026.
Concise previewRood & Riddle Equine Hospital, an equine healthcare organization operating in the United States, was claimed by Storm on August 14, 2026.
Concise previewCanadian Mental Health Association, a mental health services organization in Canada, was claimed by Storm on August 14, 2026.
Concise previewTapper Cuddy LLP, a law firm in Canada, was the subject of a claim posted by Storm on August 14, 2026.
Concise previewIntegra Castings, a manufacturing organization in Canada, was claimed by Storm on August 14, 2026.
Concise previewSouthern Metals Company, a metals recycling organization based in Charlotte, North Carolina, United States, was claimed by Storm on August 14, 2026.
Concise previewMetabase was claimed by shinyhunters on August 14, 2026.
Concise previewSharecare, Inc. was claimed to be compromised by shinyhunters on August 14, 2026.
Concise previewIPS Srl, an environmental services and waste recycling organization in Italy, was claimed by the thegentlemen group on August 14, 2026.
Concise previewCarhartt, Inc. was claimed as compromised by shinyhunters on August 14, 2026.
Concise previewGfeller Treuhand und Verwaltungs AG, a real estate and fiduciary services organization in Switzerland, was claimed by thegentlemen on August 14, 2026.
Concise previewGravity Coffee was claimed by thegentlemen on August 14, 2026.
Concise previewBaxter International, Inc. was claimed to have had data compromised on August 14, 2026.
Concise previewOllies Place Kidswear, an Australian retailer in the clothing sector, experienced a claimed breach on August 14, 2026.
Concise previewThe Coffee Bean, a café and beverage sector organization in Malaysia, was claimed in a leak-site post on August 14, 2026.
Concise previewKFC Kosova, a fast-food sector organization in Kosovo, was claimed by thegentlemen on August 14, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (including its 42 CFR Part 2 records), Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).