Full stored descriptionAlter Consultores Legales was claimed by qilin on August 28, 2026.
Breaches and leak-site claims
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Claims tracked since 2024-04-19.
Of 13,275 confirmed breaches, 5,362 come from the California Attorney General portal, which publishes no individuals-affected count. Those rows, and any other government-source row whose portal did not publish a count, read "Not reported" here (5,363 in all): the source's own gap, not omission on our part.
Filter to "Removed from leak site" to surface victims a ransomware group has taken off its own leak site. A removal can signal that the incident was resolved or the ransom paid, but a group can also remove a victim after a fake or withdrawn claim, or by taking down its own site, so it is an observation only, never a guarantee or confirmation of payment.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Full stored descriptionCore Materials was claimed by chaos on August 28, 2026.
Full stored descriptionMacAllister was claimed on August 28, 2026 by threat actor chaos.
Full stored descriptionValley Health Team, a healthcare organization, was claimed by the rhysida group on August 28, 2026.
Full stored descriptionAtcomm, a Technology sector organization, was claimed by global on August 28, 2026.
Full stored descriptionAlumax, an aluminum distribution company for the construction industry, was claimed by akira on August 28, 2026.
Full stored descriptionBerlin, Germany, a government organization, was claimed as compromised by rhysida on August 28, 2026.
Full stored descriptionBEPeterson, a metal fabrication company, was claimed by akira on August 28, 2026.
Full stored descriptionJRT Mechanical, a mechanical contracting firm in the Pacific Northwest, was claimed by akira on August 28, 2026.
Full stored descriptionProCare was claimed to be compromised by moneymessage on August 28, 2026.
Full stored descriptionqilin claimed DigiGround on August 28, 2026.
Full stored descriptionTramigo, a Transportation & Logistics sector organization, was claimed by qilin on August 28, 2026.
Full stored descriptionCosmocolor SA de CV was claimed on August 28, 2026 by qilin.
Full stored descriptionHanwha Renewables, an Energy & Utilities sector organization, was claimed by emperador on August 28, 2026.
Full stored descriptionamzur.com was claimed by unsafe on August 28, 2026.
Full stored descriptionDirectorate-General for Education in Portugal was claimed by Panzer on August 28, 2026.
Full stored descriptionInfinnium was claimed by qilin on August 28, 2026.
Full stored descriptionQilin claimed Whitehouse on August 28, 2026.
Full stored descriptionBayview Real Estate was claimed to be compromised by ShadowByt3$ on August 28, 2026.
Full stored descriptionThe Tennessee Medical Association was claimed by lockbit5 on August 28, 2026.
Full stored descriptionCaduceus Medical Group, operating in the healthcare sector, had data claimed in a leak-site post by anubis on August 28, 2026.
Full stored descriptionEclipse claimed the compromise of ETNA Software, a financial technology sector organization, on August 27, 2026.
Full stored descriptionSingleton Reynolds, a law firm headquartered in Vancouver, British Columbia, was claimed by chaos on August 27, 2026.
Full stored descriptionSilentRansomGroup claimed an organization with a redacted name on August 27, 2026.
Full stored descriptionGlobalport Terminals was claimed by qilin on August 27, 2026.
Full stored descriptionAgrimac, an agricultural dealership in Australia, claimed by Storm on August 27, 2026.
Full stored descriptionOur Hospice Of South Central Indiana, a healthcare organization in Indiana, was claimed by Storm on August 27, 2026.
Full stored descriptionBenchmark Civil Engineering Services, Inc., a civil engineering firm in Allentown, Pennsylvania, was claimed by incransom on August 27, 2026.
Full stored descriptionFP Management BV, a trust office sector organization in Netherlands, was claimed by lockbit5 on August 27, 2026.
Full stored descriptionAn organization with initials G... T... was claimed by SilentRansomGroup on August 27, 2026.
Full stored descriptionKling Automaten was claimed by qilin on August 27, 2026.
Full stored descriptionDotlines was claimed on August 27, 2026 by qilin.
Full stored descriptionIpro.com (revealdata.com) customer database and full database backup claimed by emperador on August 27, 2026.
Full stored descriptionRohloff Group, a Manufacturing sector organization, was claimed by incransom on August 27, 2026.
Full stored descriptionCetylite, Inc., a dental and medical products organization, was claimed by akira on August 27, 2026.
Full stored descriptionCGP MEP, a building services consultancy in the United Kingdom, was claimed as compromised by akira on August 27, 2026.
Full stored descriptionSeabrook Island, a Hospitality sector organization, was claimed by akira on August 27, 2026.
Full stored descriptionRuby Seven Studios Inc., a gaming organization, was claimed by incransom on August 27, 2026.
Full stored descriptionGPS Grothkopp und Partner was claimed by qilin on August 27, 2026.
Full stored descriptionThe Heart Center of Memphis was claimed on August 27, 2026 by lockbit5.
Full stored descriptionDeCe COMPUTERS s.r.o. was claimed to be breached by lockbit5 on August 27, 2026.
Full stored descriptiontakt.be was claimed by lockbit5 on August 27, 2026.
Full stored descriptionqilin claimed Providence Investments on August 27, 2026.
Full stored descriptionQilin claimed LGG Advisors on August 27, 2026.
Full stored descriptionOpen Sports was claimed by qilin on August 27, 2026.
Full stored descriptionPI***al, a Financial Services sector organization, was claimed by AuditTeam on August 27, 2026. No further details were available from the leak-site post.
Full stored descriptionQilin claimed DAB Investments on August 27, 2026.
Full stored descriptionDisplaydata was claimed on August 27, 2026 by the group qilin.
Full stored descriptionSCA Logistik & Fulfillment GmbH, a logistics and e-commerce fulfillment provider in Germany, was claimed to be compromised by aurora on August 27, 2026.
Full stored descriptionCapitol Mechanics, operating in the Finance and Transportation sectors, was claimed by emperador on August 27, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal, Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).