Full stored descriptionNAI Earle Furman, a Business & Professional Services sector organization, was claimed by secp0 on September 22, 2026.
State now. Changed: +25 tier promotions, 0 known-exploited vulnerability additions, 9 leak-site claims, and 1 confirmed breach since yesterday.
Breaches and leak-site claims
Compare confirmed breaches with clearly labelled, unverified leak-site claims, each linked to its named source.
Confirmed breaches and unverified leak-site claims in one labeled feed. Confirmed breaches come from the California Attorney General breach portal, the Department of Health and Human Services Office for Civil Rights (HHS OCR, including its 42 CFR Part 2 substance-use records), Securities and Exchange Commission (SEC) 8-K cyber-incident filings, and the Have I Been Pwned breach directory. Leak-site claims come from RansomLook and, as a failover, ransomware.live. Claims are always labeled and never presented as fact.
Why now: 15 leak-site claims were first observed in the last 24 hours.
Claims tracked since 2024-04-19. The 24-hour figure is a rolling window; month and year are calendar periods (UTC), so on the first days of a month the 24-hour count can exceed the month-to-date count.
Of 13,394 confirmed breaches, 5,402 show "Not reported" for individuals affected because the portal published no count: all 5,401 California Attorney General rows plus 1 other government-source row. The gap is the source's, not omission on our part.
What changed
This page does not publish a page-specific change count. Open the daily comparison for newly confirmed breaches and newly observed leak-site claims.
Details
The labels separate confirmed incidents from claims, and the filters below narrow the source-linked records.
Ordered by the source-provided record date when present, even when its meaning is unknown; otherwise, by when this tracker first saw the record. Every displayed date states which event it represents.
Full stored descriptionSealcon, a cable management provider in the electrical components sector based in Colorado, United States, was claimed by termite on September 22, 2026.
Full stored descriptionFinSoft, a retail software vendor and IT services provider in Uzbekistan, was claimed by N0n on September 22, 2026.
Full stored descriptionTruAmerica Multifamily, a real estate investment and asset management firm operating in the United States, was claimed by termite on September 22, 2026.
Full stored descriptiontheLender, a wholesale mortgage company in the United States, was claimed by termite on September 22, 2026.
Full stored descriptionplay alleged access to Metallco of Norway on September 21, 2026.
Full stored descriptionHurley, based in the United States, was claimed by play on September 21, 2026.
Full stored descriptionAstemo, Ltd., an automotive parts supplier, was claimed by metaencryptor on September 21, 2026.
Full stored descriptionHogan Lovells Cadwalader was claimed by SilentRansomGroup on September 21, 2026.
Full stored descriptionkyyba.com was claimed by unsafe on September 21, 2026.
Full stored descriptionNightspire claimed Spo**** Schools on September 21, 2026.
Full stored descriptionSumma Gold, a gold mining organization, was claimed by the Anubis group on September 21, 2026.
Full stored descriptionAllied Supply Co., a Manufacturing sector organization, was claimed by Global Secret Group on September 21, 2026.
Full stored descriptionKjla, a broadcasting organization in the United States, was listed by Global Secret Group on September 21, 2026.
Full stored descriptionTelrad Networks was claimed by qilin on September 21, 2026.
Full stored descriptionU.S. Electrical Services and Wiedenbach Brown, an Energy & Utilities sector organization, was claimed by moneymessage on September 21, 2026.
Full stored descriptionHudson MD Group, LLC, a U.S.-based multispecialty medical group in the healthcare sector, was claimed by metaencryptor on September 21, 2026.
Full stored descriptionBruker Corporation, a scientific technology company in the United States, was claimed by metaencryptor on September 21, 2026.
Full stored descriptionFlex Ltd, a technology manufacturing and supply-chain company, was claimed by metaencryptor on September 21, 2026.
Full stored descriptionHyVision System. Inc, a Technology sector organization, was claimed by metaencryptor on September 21, 2026.
Full stored descriptionVisual Intelligence, Inc., a managed services organization, was claimed as compromised by metaencryptor on September 21, 2026.
Full stored descriptionPrestige Management, a real estate management organization based in New York, was claimed as compromised by akira on September 21, 2026.
Full stored descriptionGrupolider, an Agriculture sector organization, was claimed by thegentlemen on September 21, 2026.
Full stored descriptionThe Money Store, a Financial Services sector organization, was claimed by Storm on September 21, 2026.
Full stored descriptionTrueCore Behavioral Solutions, a behavioral health services provider in the United States, was claimed by Storm on September 21, 2026.
Full stored descriptionManroc Developments, a mining contractor based in Canada, was claimed by Storm on September 21, 2026.
Full stored descriptionDoommageddon claimed responsibility for a breach at Charlottesville Police Department on September 21, 2026.
Full stored descriptionGomomentum.com, a telecommunications company, was claimed to be compromised by EndZone on September 21, 2026.
Full stored descriptionIKEGAMI TSUSHINKI COMPANY LIMITED was claimed by qilin on September 21, 2026.
Full stored descriptionsiinqeebank.com, a Financial Services sector organization, was claimed by lockbit5 on September 21, 2026.
Full stored descriptionNewman Tractor, a heavy equipment sector organization in the United States, was claimed by threeam on September 21, 2026.
Full stored descriptionSecond House, a privately held real estate company headquartered in Barcelona, Spain, was claimed by incransom on September 21, 2026.
Full stored descriptionBonita Orthodontics, a dental care organization in the United States, was claimed by incransom on September 21, 2026.
Full stored descriptionReported to the California Attorney General under the state data breach notification law.
Full stored descriptionReported to the California Attorney General under the state data breach notification law.
Full stored descriptionReported to the California Attorney General under the state data breach notification law.
Full stored descriptionAlabama Woman's Health Care, a Healthcare sector organization, was claimed by emperador on September 20, 2026.
Full stored descriptionst***co was claimed by AuditTeam on September 20, 2026. No further details were available from the leak-site post.
Full stored descriptionSiddhi Green Excellence Pvt. Ltd, an Energy & Utilities sector organization, was claimed by Orova on September 20, 2026.
Full stored descriptionAhluwalia Contracts (India) Limited, a civil construction and contracting company operating in India, became subject to a claim by krybit on September 20, 2026.
Full stored descriptionEuramex Management Group, a real estate organization in the United States, was claimed by Orova on September 20, 2026.
Full stored descriptionZorlu Holding was claimed as compromised by qilin on September 20, 2026.
Full stored descriptionShopDunk was claimed by qilin on September 20, 2026.
Full stored descriptionKMLS was listed by qilin on September 20, 2026.
Full stored descriptionTouring Club Suisse was claimed by qilin on September 20, 2026.
Full stored descriptionStudio Notarile Associato Salvatore Costantino E Anna Favarato, a Business & Professional Services sector organization, was claimed by emperador on September 20, 2026.
Full stored descriptionGreat Bay Bio was claimed by nightspire on September 20, 2026.
Full stored descriptionTOWILL, a Technology sector organization, was claimed by bravox on September 20, 2026.
Full stored descriptionFanatics (global sports commerce platform), a Retail sector organization, was claimed by N0n on September 20, 2026.
Full stored descriptionSchneider's Computing & Websites Ltd., a Canadian organization, was claimed on September 19, 2026 by arcusmedia.
Per-incident affected-count reconciliation across government breach sources is not currently possible. The Maine Attorney General portal has been offline since 2026-06-12, and the California Attorney General publishes no affected-persons count. Where one incident is reported to more than one source it is cross-linked, and every count shown is only the number that source itself reported.
A "No longer listed" badge means the victim was present on the leak site and is now absent from the claiming group's current listing, confirmed across two consecutive checks. It is an observation only. It is not a confirmation that the organization paid, negotiated, or resolved the incident, and a group that takes down its own site can cause it. Removal is tracked for RansomLook claims, the only source that publishes a full per-group listing. A claim from another source carries no badge because its removal is not tracked, which is not evidence the victim is still listed.
Browse every record in stable static pages, for search engines and no-JavaScript access to the full corpus.
Leak-site claim data:RansomLook(CC BY 4.0), withransomware.liveas a failover, credited voluntarily (it carries no attribution obligation). Claims are unverified until the affected organization confirms an incident. Confirmed breaches come from the California Attorney General breach portal, theHHS OCR Breach Portal(including its 42 CFR Part 2 records), theMaine Attorney Generalbreach portal (offline since 2026-06-12; no rows are currently in this index), Securities and Exchange Commission 8-K filings, andHave I Been Pwned(CC BY 4.0).
How this is computed
Confirmed incidents come from the named government and breach-directory sources. Leak-site entries remain unverified claims. Windows use the recorded disclosure or observation date, and missing dates remain explicit.
Method reviewed on .