Concise previewQuaker State Mexico was claimed on August 21, 2026.
Breaches and leak-site claims
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Claims tracked since 2026-01-01.
Of 13,251 confirmed breaches, 5,352 come from the California Attorney General portal, which publishes no individuals-affected count. Those rows, and any other government-source row whose portal did not publish a count, read "Not reported" here (5,353 in all): the source's own gap, not omission on our part.
Filter to "Removed from leak site" to surface victims a ransomware group has taken off its own leak site. A removal can signal that the incident was resolved or the ransom paid, but a group can also remove a victim after a fake or withdrawn claim, or by taking down its own site, so it is an observation only, never a guarantee or confirmation of payment.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Concise previewiPic was claimed by qilin on August 21, 2026.
Concise previewJC Sales, a wholesaler in the United States, was claimed by akira on August 21, 2026.
Concise previewCinépolis has been claimed by qilin on August 21, 2026.
Concise previewFairview Dental Group, a dental services provider, received a claim on August 21, 2026.
Concise previewQilin claimed Gindre India on August 21, 2026.
Concise previewBattle Creek Public Schools, an educational organization in Nebraska, was claimed by rhysida on August 21, 2026.
Concise previewThe Pendas Law Firm was claimed by qilin on August 21, 2026.
Concise previewqilin claimed Blake Services on August 21, 2026.
Concise previewProfessional was claimed by qilin on August 21, 2026.
Concise previewUOLconsult GmbH, a management consulting firm in Austria, was claimed by thegentlemen on August 21, 2026.
Concise previewdlp motive, a German event technology sector organization, was claimed on August 21, 2026.
Concise previewAWJ Holding, a Saudi Arabian real estate and investment firm, was claimed to be compromised on August 21, 2026.
Concise previewLexacaucho, a manufacturing organization in Peru, was claimed by thegentlemen on August 21, 2026.
Concise previewLOG Systems, a Polish software company in the IT management sector, received a claim on August 21, 2026.
Concise previewMagdalena Grand Beach Golf Resort, a hospitality organization located in Tobago, was claimed by thegentlemen on August 21, 2026.
Concise previewAkatake Engineering, a manufacturing organization based in Japan, was claimed by thegentlemen on August 21, 2026.
Concise previewESCON Group, an electrical contracting company in the United States, was claimed by thegentlemen on August 21, 2026.
Concise previewAlmeer General Contracting Establishment, an industrial construction services organization in Saudi Arabia, appeared on a leak site on August 21, 2026.
Concise previewGeb Sas, a chemical manufacturing organization in France, was named in a claim posted on August 21, 2026.
Concise previewARBEITERKAMMERN, a statutory public organization in Austria, was claimed as compromised on August 21, 2026.
Concise previewAquasea Inc., a clothing and apparel manufacturing company in the United States, was claimed by thegentlemen on August 21, 2026.
Concise previewCAZ Investments, a wealth management firm, was claimed by thegentlemen on August 21, 2026.
Concise previewOceanica Internacional, a logistics and freight forwarding sector organization operating in Central America, was claimed by thegentlemen on August 21, 2026.
Concise previewAriel Energia, an Italian home energy and comfort company, was claimed on August 21, 2026.
Concise previewHogan Omidi P.C., a law firm, was claimed by dragonforce on August 21, 2026.
Concise previewInterim HealthCare Head office, healthcare sector, claimed on August 21, 2026.
Concise previewNorthStar, operating in Enterprise Resource Planning, became the subject of a claim by direwolf on August 21, 2026.
Concise previewDirewolf claimed Aztec Software, an engineering software organization, on August 21, 2026.
Concise previewThe Revel Collective, a hospitality sector organization, was claimed by direwolf on August 21, 2026.
Concise previewdirewolf claimed ProSim Aviation Research, an engineering software organization, on August 21, 2026.
Concise previewAuthenticate Information Systems was claimed by direwolf on August 21, 2026.
Concise previewDiaco Global, a jewelry and watch retail organization, was claimed by direwolf on August 21, 2026.
Concise previewdirewolf claims iSON XPERIENCES, a business services organization, on August 21, 2026.
Concise previewDeer Creek-Mackinaw CUSD, an education sector organization, received a claim on August 21, 2026.
Concise previewDirewolf claimed on August 21, 2026 that Allstar Industries, a business services organization, was compromised.
Concise previewHP Carriers was claimed by direwolf on August 21, 2026.
Concise previewMCT Group of Companies, a building materials organization, was claimed by direwolf on August 21, 2026.
Concise previewReviso Cloud Accounting Limited, a financial technology company based in the United Kingdom, was claimed on August 21, 2026.
Concise previewdirewolf claimed to have breached Studee, an education technology organization based in the United Kingdom, on August 21, 2026.
Concise previewAn organization designated as D... was claimed by SilentRansomGroup on August 20, 2026.
Concise previewThe University of Delhi, a public higher education institution in India, was claimed by DYSPHOR1A on August 20, 2026.
Concise previewGruppo Spaggiari Parma, an organization in the education sector operating in Italy, appeared on the xpl0itrs leak site on August 20, 2026.
Concise previewAyuntamiento de Velilla de San Antonio, a local government organization in Spain, was claimed by kairos on August 20, 2026.
Concise previewCyrus****** was claimed by shinyhunters on August 20, 2026.
Concise previewRegency Centers was claimed by iah6477 on August 20, 2026.
Concise previewAcima was claimed by iah6477 on August 20, 2026.
Concise previewmarvin was claimed as a victim by iah6477 on August 20, 2026.
Concise previewNetExam, a US-based education sector software-as-a-service provider, was claimed by emperador on August 20, 2026.
Concise previewBe Media, a United States-based organization, was claimed on August 20, 2026 by the play group.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).