Concise previewQilin claims Teikoku USA on August 16, 2026.
Breaches and leak-site claims
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Claims tracked since 2026-01-01.
Of 13,223 confirmed breaches, 5,343 come from the California Attorney General portal, which publishes no individuals-affected count. Those rows, and any other government-source row whose portal did not publish a count, read "Not reported" here (5,344 in all): the source's own gap, not omission on our part.
Filter to "Removed from leak site" to surface victims a ransomware group has taken off its own leak site. A removal can signal that the incident was resolved or the ransom paid, but a group can also remove a victim after a fake or withdrawn claim, or by taking down its own site, so it is an observation only, never a guarantee or confirmation of payment.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Concise previewAGUNSA was claimed as a victim by the qilin group on August 16, 2026.
Concise previewQilin claimed Coface on August 16, 2026.
Concise previewSpoonful of Comfort was claimed by qilin on August 16, 2026.
Concise previewPanzer claims to have breached SAGASTA sro, a design and engineering company, on August 16, 2026.
Concise previewMoscord, a digital marketplace in the maritime sector, was the subject of a claim by Eclipse on August 16, 2026.
Concise previewMulino Padano was claimed by qilin on August 16, 2026.
Concise previewQilin claimed WEBA Meubelen on August 16, 2026.
Concise previewTwal Family IT Lab, a personal IT organization in Canada, was claimed by medusalocker on August 16, 2026.
Concise previewAll Parts Dry Cleaning, a dry cleaning and laundry organization in the United Kingdom, was listed by medusalocker on August 16, 2026.
Concise previewIdex Group was claimed as compromised by medusalocker on August 16, 2026.
Concise previewBija Industrie, an organization, was claimed by medusalocker on August 16, 2026.
Concise previewThecourierguy was claimed by medusalocker on August 16, 2026.
Concise previewKennedy Jenks was claimed by Helix on August 16, 2026.
Concise previewGroupe Actua, a recruitment and temporary staffing agency, was claimed as breached by lockbit5 on August 16, 2026.
Concise previewDupouy et Associes, an accounting services company, was claimed to be compromised by lockbit5 on August 16, 2026.
Concise previewAgricola Galbusera, an agricultural organization, appeared on a leak site on August 16, 2026.
Concise previewLockBit5 claimed on August 16, 2026 to have breached Tecosim.com, a computer-aided engineering technology corporation.
Concise previewMOSAID Technologies was named in a claim by qilin on August 16, 2026.
Concise previewINVENSITY was claimed by the qilin group on August 16, 2026.
Concise previewMegawide was claimed on the leak site on August 16, 2026.
Concise previewInfosat, a technology and communications company, was claimed by Panzer on August 16, 2026.
Concise previewQilin claims involvement with Desatera Sdn Bhd on August 16, 2026.
Concise previewLoescher editore Torino was claimed on August 16, 2026 by qilin.
Concise previewBotek was claimed as a victim by qilin on August 16, 2026.
Concise previewZanichelli was claimed to be breached by qilin on August 16, 2026.
Concise previewQilin claimed Jone Précision on August 16, 2026.
Concise previewQilin posted a claim involving Arnall Golden Gregory on August 16, 2026.
Concise previewASCII Group received a claim from qilin on August 16, 2026.
Concise previewQilin claimed DELTA WAYS on August 16, 2026.
Concise previewMotorenmaier GmbH was claimed by qilin on August 16, 2026.
Concise previewDouble H Equipment was claimed by the qilin group on August 16, 2026.
Concise previewSmartsoft was claimed as compromised by Orova on August 16, 2026.
Concise previewOz Hair & Beauty, a hair and beauty products organization, was claimed by xpl0itrs on August 15, 2026.
Concise previewAn unnamed victim in the school management software sector was claimed by xpl0itrs on August 15, 2026.
Concise previewRapidFort, a software supply chain security organization, was claimed as compromised by xpl0itrs on August 15, 2026.
Concise previewDodoPayments, a financial software organization, appears on the direwolf leak-site claim posted on August 15, 2026.
Concise previewAAM:HOA Management was claimed by direwolf on August 15, 2026.
Concise previewColla Health, a healthcare organization, was claimed by direwolf on August 15, 2026.
Concise previewPayrHealth, a healthcare sector organization, became the subject of a claim by direwolf on August 15, 2026.
Concise previewservmarmg.cl was claimed by ms13089 on August 15, 2026.
Concise previewSEARS (Grupo Sanborns), a Mexican retail company, was claimed by spacebears on August 15, 2026.
Concise previewSecurotrop claimed Lepi Enterprises on August 15, 2026.
Concise previewBarracuda claimed to have obtained data from VR Advogados, a Brazilian law firm, on August 15, 2026.
Concise previewwww.amca.org.ar received a claim from blackwater on August 15, 2026.
Concise previewwww.shalina.com experienced a claimed system breach on August 15, 2026.
Concise previewInterim HealthCare, a home healthcare and medical staffing organization, appeared in a claim by anubis on August 15, 2026.
Concise previewAlpine Electronics Europe, an automotive electronics and audio products distributor, was claimed by Panzer on August 15, 2026.
Concise previewFERRARI MANGIMI SRL was claimed to be breached by the actor qilin on August 14, 2026.
Concise previewgranjarinya.com was claimed by safepay on August 14, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).