Full stored descriptionRDA MOTORS S.P.A., an Italian automotive organization, was claimed by emperador on September 16, 2026.
State now. Changed: 0 tier promotions, +1 known-exploited vulnerability addition, 15 leak-site claims, and 0 confirmed breaches since yesterday.
Breaches and leak-site claims
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Why now: 18 leak-site claims were first observed in the last 24 hours.
Claims tracked since 2024-04-19. The 24-hour figure is a rolling window; month and year are calendar periods (UTC), so on the first days of a month the 24-hour count can exceed the month-to-date count.
Of 13,371 confirmed breaches, 5,389 show "Not reported" for individuals affected because the portal published no count: all 5,388 California Attorney General rows plus 1 other government-source row. The gap is the source's, not omission on our part.
What changed
This page does not publish a page-specific change count. Open the daily comparison for newly confirmed breaches and newly observed leak-site claims.
Details
The labels separate confirmed incidents from claims, and the filters below narrow the source-linked records.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Full stored descriptionOptimum First Mortgage (Pear's acting group's promotional blog), a Financial Services sector organization, was claimed by blacknevas on September 16, 2026.
Full stored descriptionemperador claimed on September 16, 2026 to have breached SEVENOAKS s.r.o., a technology sector organization based in Czech Republic.
Full stored descriptionLeisure Coast Kitchens, a kitchens and bathrooms company, was claimed by kairos on September 16, 2026.
Full stored descriptionReddrop Group was claimed to have been compromised by qilin on September 16, 2026.
Full stored descriptionIn The Company of Huskies was claimed by qilin on September 16, 2026.
Full stored descriptionOdyssey Charter School, Inc., a nonprofit education organization in Florida, was claimed by Wallstreet on September 16, 2026.
Full stored descriptionRoshd Sanat, an Iranian industrial company in the energy sector, was claimed by Wallstreet on September 16, 2026.
Full stored descriptionQilin claimed Thorndale Foundation on September 16, 2026.
Full stored descriptionThema Foundries was claimed by qilin on September 16, 2026.
Full stored descriptionBlossomland Accounting, an accounting services organization in the United States, was claimed by akira on September 16, 2026.
Full stored descriptionBee Maid Honey, an Agriculture sector organization, was claimed by akira on September 16, 2026.
Full stored descriptionManders, a contractor in the Washington Metropolitan Area, was claimed by akira on September 16, 2026.
Full stored descriptionThe Agricultural Research Development Agency (ARDA), a public organization in Thailand, was claimed by arcusmedia on September 16, 2026.
Full stored descriptionNielsen Design was claimed by Panzer on September 16, 2026.
Full stored descriptionAarsleff was named in a claim by qilin on September 16, 2026.
Full stored descriptionCommunity Property Management, a property management firm, was claimed to be compromised by dragonforce on September 16, 2026.
Full stored descriptionOwen Leigh Optometry, a Healthcare sector organization, was claimed by dragonforce on September 16, 2026.
Full stored descriptionVexy Ransomware claimed the compromise of Hashimoto Jimuki, a Japanese office equipment, IT equipment, services, office furniture, meeting and conferencing systems, and computer support provider on September 15, 2026.
Full stored descriptionMarlin HVAC, a mechanical services organization, was claimed by safepay on September 15, 2026.
Full stored descriptionNeumerkel GmbH was claimed by safepay on September 15, 2026.
Full stored descriptiontriniticaring.org, a senior services organization, was claimed on September 15, 2026 by the safepay group.
Full stored descriptionSafepay claimed laconcepcion.com.mx, a private healthcare provider, on September 15, 2026.
Full stored descriptionmeterex.com was claimed by safepay on September 15, 2026.
Full stored descriptionStoecklin-kuechen.ch, a carpentry and kitchen company based in Aesch near Basel, Switzerland, was claimed by safepay on September 15, 2026.
Full stored descriptionara-lyss.ch was claimed by safepay on September 15, 2026.
Full stored descriptiongob.pe, a Peruvian government organization, was claimed as compromised by safepay on September 15, 2026.
Full stored descriptionWiggins, Childs, Pantazis, Fisher, & Goldfarb LLC, a Business & Professional Services sector organization, was claimed by insomnia on September 15, 2026.
Full stored descriptionTaurus Ibérica was claimed by qilin on September 15, 2026.
Full stored descriptionPilot Precision, an industrial tools and machining equipment manufacturer, was claimed as compromised by akira on September 15, 2026.
Full stored descriptionLazyboyz, a motorcycle retail and service business in Norway, was claimed by akira on September 15, 2026.
Full stored descriptionQilin claimed Montana Civil Contractors on September 15, 2026.
Full stored descriptionSouthern California Telephone Company, a telecommunications sector organization, was claimed by akira on September 15, 2026.
Full stored descriptionResolve Law Group was claimed by qilin on September 15, 2026.
Full stored descriptionADM is claimed to have been compromised by the Qilin group on September 15, 2026.
Full stored descriptionSFA Engineering Corporation, a high-tech engineering sector organization based in South Korea, was claimed by metaencryptor on September 15, 2026.
Full stored descriptionNippon Steel Corporation, a Manufacturing sector organization, was claimed by metaencryptor on September 15, 2026.
Full stored descriptionAsada Sarapiqu, an organization focused on water supply services, claimed by arcusmedia on September 15, 2026.
Full stored descriptionIncrys was listed on the qilin leak site on September 15, 2026.
Full stored descriptionBravo Group was reported as compromised by qilin on September 15, 2026.
Full stored descriptionMcCarthy Tire Service, a Retail sector organization, was claimed by Storm on September 15, 2026.
Full stored descriptionPANTHERx Rare, a pharmacy sector organization in the United States, was claimed by Storm on September 15, 2026.
Full stored descriptionStorm claimed Insight Credit Union, a financial services organization in the United States, on September 15, 2026.
Full stored descriptionACA Pescara, a public housing agency in the Province of Pescara, Italy, was claimed by thegentlemen on September 15, 2026.
Full stored descriptionHattiesburg Eye Clinic, a Healthcare sector organization, was claimed by thegentlemen on September 15, 2026.
Full stored descriptionIndic, a Houston-based industrial electronics manufacturer's representative firm, was claimed by thegentlemen on September 15, 2026.
Full stored descriptionAurora Technologies, a materials fabrication and distribution company in the United States, was claimed by thegentlemen on September 15, 2026.
Full stored descriptionGöteborgsregionens Tekniska Gymnasium, a Swedish educational institution, was claimed by the thegentlemen group on September 15, 2026.
Full stored descriptionAlchin Long Group, an Australian hardware conglomerate, was claimed by thegentlemen on September 15, 2026.
Full stored descriptionGelarti, a food and beverage company operating in Peru, was claimed as compromised by thegentlemen on September 15, 2026.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal (offline since 2026-06-12; no rows are currently in this index), Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).
How this is computed
Confirmed incidents come from the named government and breach-directory sources. Leak-site entries remain unverified claims. Windows use the recorded disclosure or observation date, and missing dates remain explicit.
Method reviewed on .