Full stored descriptionSC PaderTeG Cabluri Electrice was claimed by qilin on August 25, 2026.
Breaches and leak-site claims
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Claims tracked since 2024-04-19.
Of 13,274 confirmed breaches, 5,361 come from the California Attorney General portal, which publishes no individuals-affected count. Those rows, and any other government-source row whose portal did not publish a count, read "Not reported" here (5,362 in all): the source's own gap, not omission on our part.
Filter to "Removed from leak site" to surface victims a ransomware group has taken off its own leak site. A removal can signal that the incident was resolved or the ransom paid, but a group can also remove a victim after a fake or withdrawn claim, or by taking down its own site, so it is an observation only, never a guarantee or confirmation of payment.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Full stored descriptiondirewolf claimed to have compromised National Kidney Registry, a healthcare organization based in the United States, on August 25, 2026.
Full stored descriptiondirewolf claims Studio Legale ESE, a legal services organization, on August 25, 2026.
Full stored descriptionTiseo Paving, a construction sector organization in the United States, was listed in a claim by Global Secret Group on August 25, 2026.
Full stored descriptionJohnson City Honda, an automobile dealer in the United States, was claimed by Global Secret Group on August 25, 2026.
Full stored descriptionLockheed Architectural Solutions, Inc., a manufacturing, construction, and building materials organization in the United States, was claimed by Global Secret Group on August 25, 2026.
Full stored descriptionSinar Mas Agribusiness and Food Golden Agri-Resources was claimed by ShadowByt3$ on August 25, 2026.
Full stored descriptionA-Plus Software Limited, a Technology sector organization, was claimed by ShadowByt3$ on August 25, 2026.
Full stored descriptionS******* was claimed by genesis on August 25, 2026.
Full stored descriptionWINTER Ingenieure, an engineering and construction services organization in Germany, was claimed by akira on August 25, 2026.
Full stored descriptionQilin claimed STRUCTURED SETTLEMENT CAPITAL LLC on August 25, 2026.
Full stored descriptionDavis & Ferber, a personal injury and malpractice law firm based in New York, was claimed by akira on August 25, 2026.
Full stored descriptionAGROLAND S.A. was claimed by qilin on August 25, 2026.
Full stored descriptionPump Engineering Company, an industrial pump distributor and supplier, was claimed to be compromised by Dark Project on August 25, 2026.
Full stored descriptionPCA Group Sdn. Bhd. was claimed on August 25, 2026 by majinahanashi.
Full stored descriptionDark Project claimed to have breached a dentist in New Britain, CT on August 25, 2026.
Full stored descriptionReported to the California Attorney General under the state data breach notification law.
Full stored descriptionConsultores de Seguros was claimed by qilin on August 24, 2026.
Full stored descriptionShaheen Law Group PLC, a family law firm in Richmond, Virginia, USA, was claimed by Deadlock on August 24, 2026.
Full stored descriptionFurniture Bargaining Council, a furniture and upholstery industry organization in South Africa, was named in a claim by Deadlock on August 24, 2026.
Full stored descriptionlagegepesca.it, an Agriculture sector organization, was claimed by safepay on August 24, 2026.
Full stored descriptionThe Liberty Group was claimed by Dark Project on August 24, 2026.
Full stored descriptionJones, Little & Co., CPAs, LLP, a professional accounting firm, was claimed to be compromised by Dark Project on August 24, 2026.
Full stored descriptionDesign-Aire Engineering, INC, a Manufacturing sector organization, was claimed by Dark Project on August 24, 2026.
Full stored descriptionFurnished Quarters, a Hospitality sector organization, was claimed by Dark Project on August 24, 2026.
Full stored descriptionFrato, an interior lifestyle organization, was claimed by dragonforce on August 24, 2026.
Full stored descriptionCriba, an Argentina-based construction company, was claimed compromised by dragonforce on August 24, 2026.
Full stored descriptionBrookview Financial, a financial services organization, had a breach claimed by dragonforce on August 24, 2026.
Full stored descriptionWozair, an HVAC products and services organization, was claimed by the dragonforce group on August 24, 2026.
Full stored descriptionBihl was claimed by akira on August 24, 2026.
Full stored descriptionBooba Project claimed access to Davroc, a furniture and home furnishings manufacturing organization, on August 24, 2026.
Full stored descriptionChernyy & Associates, a law practice, was claimed by Booba Project on August 24, 2026.
Full stored descriptionManagementPro Inc., a computer software company, was claimed by arcusmedia on August 24, 2026.
Full stored descriptionMark'Techno, a mechanical and sheet metal organization, was claimed by arcusmedia on August 24, 2026.
Full stored descriptionGovernment of Vojvodina was claimed as compromised by Panzer on August 24, 2026.
Full stored descriptionQilin claimed Coldfish Seafood on August 24, 2026.
Full stored descriptionSinarmas Cepsa Pte. Ltd., an oleochemicals organization, was claimed as compromised by blackwater on August 24, 2026.
Full stored descriptionCountry-Wide Insurance, operating in the insurance sector, was claimed to be compromised on August 24, 2026.
Full stored descriptionFederis Abogados, a law practice, was claimed as breached by Booba Project on August 24, 2026.
Full stored descriptionSenvibe, an education and environmental organization, was claimed to be compromised by Panzer on August 24, 2026.
Full stored descriptionA&E + SMA Design was claimed on August 24, 2026 by the qilin group.
Full stored descriptionSharp Motor Group, an automotive dealership group based in Australia, was claimed by Storm on August 24, 2026.
Full stored descriptionCity of Mitchell, a government entity in South Dakota, United States, had its data claimed by Storm on August 24, 2026.
Full stored descriptionResi, a United Kingdom-based online architectural and home renovation platform, was claimed by krybit on August 24, 2026.
Full stored descriptionReported to the California Attorney General under the state data breach notification law.
Full stored descriptionReported to the California Attorney General under the state data breach notification law.
Full stored descriptionWestwing Group SE, a home and living products e-commerce company in Germany, was claimed by coinbasecartel on August 23, 2026.
Full stored descriptionCyrusOne, LLC was claimed by shinyhunters on August 23, 2026.
Full stored descriptionS.E.M.P. s.r.l. was named in a claim posted on August 23, 2026.
Full stored descriptionGlobal Go was claimed by killsec on August 23, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).