Concise previewClear Align is alleged to have been claimed by group qilin on August 23, 2026.
Breaches and leak-site claims
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Claims tracked since 2026-01-01.
Of 13,259 confirmed breaches, 5,356 come from the California Attorney General portal, which publishes no individuals-affected count. Those rows, and any other government-source row whose portal did not publish a count, read "Not reported" here (5,357 in all): the source's own gap, not omission on our part.
Filter to "Removed from leak site" to surface victims a ransomware group has taken off its own leak site. A removal can signal that the incident was resolved or the ransom paid, but a group can also remove a victim after a fake or withdrawn claim, or by taking down its own site, so it is an observation only, never a guarantee or confirmation of payment.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Concise previewDifor was claimed by qilin on August 23, 2026.
Concise previewBlack Cat Engineering & Construction WLL was claimed by qilin on August 23, 2026.
Concise previewFRUCASTRO SL, a manufacturing organization, was claimed on August 23, 2026.
Concise previewPappyJoe, a healthcare technology organization in India, was claimed on August 23, 2026.
Concise previewInstituto Ferrero de Neurología y Sueño, a healthcare organization in Argentina, was claimed on August 23, 2026.
Concise previewBrazil Mobilemed, a healthcare technology organization operating in Brazil, was claimed by kazu on August 23, 2026.
Concise previewYocale, a Canadian appointment management system provider, was claimed by kazu on August 23, 2026.
Concise previewPawlyClinic, a digital veterinary care platform, was claimed on August 23, 2026.
Concise previewDr Akbar Niazi Teaching Hospital, a healthcare organization in Pakistan, was claimed by kazu on August 23, 2026.
Concise previewCentro Médico Especializado OSI, a healthcare organization in Peru, was claimed by kazu on August 23, 2026.
Concise previewMeducar, a telemedicine and patient management system provider, was claimed by the kazu group on August 23, 2026.
Concise previewConsultorioMovil, a telemedicine and healthcare system organization, was claimed by kazu on August 23, 2026.
Concise previewWoodlore International Inc., a laminate casegood manufacturer in the furniture sector, was claimed as compromised on August 23, 2026.
Concise previewWeber Water Resources, a water resources organization, received a claim on August 23, 2026.
Concise previewMPA Pharma GmbH, a pharmaceutical company, was claimed by metaencryptor on August 23, 2026.
Concise previewAquamar Inc, a seafood products organization in the United States, was claimed by metaencryptor on August 23, 2026.
Concise previewCorona Corporation, a heating, cooling, and hot water technologies company, was claimed on August 23, 2026.
Concise previewFactory Five Racing Inc., a kit-car manufacturer in the United States, was claimed to have been compromised by metaencryptor on August 23, 2026.
Concise previewBarracuda claimed responsibility for a breach of Skyline Implants & Periodontics on August 23, 2026.
Concise previewNamyang Industrial Co., Ltd. was claimed by Barracuda on August 23, 2026.
Concise previewClinical Associates of the Finger Lakes was claimed by Barracuda on August 23, 2026.
Concise previewPCA ***** was claimed by majinahanashi on August 23, 2026.
Concise previewAutoDie, a metal stamping die manufacturer in the United States, has been claimed by Storm on August 23, 2026.
Concise previewPinnacle Hospital, a healthcare organization in Crown Point, Indiana, was claimed by the Storm group on August 23, 2026.
Concise previewStorm claimed the compromise of Phoenix Group of Companies, a print solutions provider headquartered in Philadelphia, Pennsylvania, on August 23, 2026.
Concise previewSchardein Mechanical, a mechanical contracting firm in the United States, was claimed by Storm on August 23, 2026.
Concise previewThe Cecilian Bank, a financial services organization in the United States, was claimed by Storm on August 23, 2026.
Concise previewEclipse claimed Crystal Pharmatech, a contract research organization in the pharmaceutical sector with operations across China, the United States, and Canada, on August 23, 2026.
Concise previewAGS Cinemas, a film exhibition and multiplex chain in India, was claimed on August 23, 2026.
Concise previewEyecare Center of Snohomish, a healthcare organization in the United States, was claimed by thegentlemen on August 23, 2026.
Concise previewGould Sherwood Consulting, an information technology services organization based in the United States, was claimed by thegentlemen on August 23, 2026.
Concise previewEspac, a Chilean construction materials and equipment rental company, was claimed by the_gentlemen on August 23, 2026.
Concise previewLayher, a scaffolding and access systems manufacturer, was claimed compromised by thegentlemen on August 23, 2026.
Concise previewVolktek, a Taiwanese manufacturer in the industrial networking sector, was claimed on August 23, 2026.
Concise previewReliaQuest, LLC received a claim from shinyhunters on August 23, 2026.
Concise previewel-group had a claimed data incident on August 22, 2026.
Concise previewAmSpec received a claim notice on August 22, 2026.
Concise previewVietnam Electricity (EVNHANOI), a government and energy sector organization in Vietnam, was claimed by emperador on August 22, 2026.
Concise previewNovoCure Limited received a claim from shinyhunters on August 22, 2026.
Concise previewBOK Financial was claimed on August 22, 2026 by shinyhunters.
Concise previewIntegrated Health Systems was claimed on August 22, 2026.
Concise previewRXPE Group was listed on a leak site by coinbasecartel on August 22, 2026.
Concise previewTower Insurance, an insurance sector organization in New Zealand, faced a claim from coinbasecartel on August 22, 2026.
Concise previewFlecha Bus, an intercity bus company in Argentina, was claimed by coinbasecartel on August 22, 2026.
Concise previewOTEIS Conseil & Ingénierie, an engineering and consulting firm in France, was claimed by coinbasecartel on August 22, 2026.
Concise previewLonghorn Investments was listed in a claim by coinbasecartel on August 22, 2026.
Concise previewKessler Creative was claimed as breached by coinbasecartel on August 22, 2026.
Concise previewKlasko Immigration Law Partners, a legal services organization in the United States, was claimed by the coinbasecartel group on August 22, 2026.
Concise previewPatel was claimed as compromised by coinbasecartel on August 22, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).