Ransomware & Leaks Attacks Map (last 7 days)
Ransomware Attacks Today
All Attacks in Last 30 Days
Leak Coverage — All Sources
- Leaked275057%
- Pending197441%
- Deleted812%
- Other indexed sources
- Data breaches58423
- Stealer logs14389
- Leads198
All Data
Data registered since November 2013.
| Classification | Target Identity | Source / Actor | Discovered | Location | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|---|
| Ransomware | N... View Details _ | SilentRansomGroup | 25/09/2026 | — | leaked | ||
|
Redacted entry - full company name pending disclosure (FULL DATA TIMER active). |
|||||||
| Ransomware | S... View Details _ | SilentRansomGroup | 25/09/2026 | — | leaked | ||
|
Redacted entry - full company name pending disclosure (FULL DATA TIMER active). |
|||||||
| Ransomware | GE Vernova Inc. View Details _ | metaencryptor | 25/09/2026 | US | IT | pending | |
|
GE Vernova Inc. is a global energy equipment manufacturing and services company headquartered in Cambridge, Massachusetts. Formed from General Electric's energy businesses, it operates across Power, Wind, and Electrification segments, with its technology helping generate roughly a quarter of the world's electricity. |
|||||||
| Ransomware | PKF Hadiwinata View Details _ | metaencryptor | 25/09/2026 | ID | Manufacturing / Engineering | pending | |
|
PKF Hadiwinata is a top-10 accounting and professional services firm in Indonesia, headquartered in the financial district of Jakarta. Founded in 1987, it is a member of PKF International and provides audit, tax, business solutions, and consulting services. |
|||||||
| Ransomware | Platinum Healthcare Staffing View Details _ | metaencryptor | 25/09/2026 | US | Healthcare / Pharma | pending | |
|
Platinum Healthcare Staffing is a healthcare staffing agency headquartered in Lafayette, USA, founded in 2005. It provides nursing and allied healthcare professionals, including RNs, LPNs, and CNAs, to hospitals, clinics, and medical facilities. |
|||||||
| Ransomware | Electrolux & Ontrac View Details _ | emperador | 25/09/2026 | null | pending | ||
|
Hello Electrolux & OnTrac, Still no response from you. When we called your IT helpdesk posing as threat researchers and asked about the breach, we were told, "We cannot talk about it." You have one week before we release more data - starting with information on your employees. We'd prefer to settle this directly. Same goes for OnTrac. We recently learned that OnTrac has been paying employees as little as $14.50 an hour. As a result, we will be releasing salary information for all of their employees. I also managed to get in touch with a former OnTrac employee, chill guy. Said his time there was horrible. EMAIL: [email protected] SESSION: 05651c7323273b723588d47455471ee9e27feb5187a30f2933554a705aacb38358 [Sector: Retail, Manufacturing, Transportation] |
|||||||
| Ransomware | Securitas Group View Details _ | everest | 25/09/2026 | SE | Services | pending | |
|
[AI generated] Securitas Group is a Swedish multinational security services company headquartered in Stockholm, Sweden. It operates in the security industry, providing guarding services, electronic security, fire and safety solutions, corporate risk management, and remote monitoring. Founded in 1934, it operates globally across dozens of countries, serving clients ranging from small businesses to large corporations, government agencies, and critical infrastructure providers. |
|||||||
| Ransomware | Morula IVF View Details _ | everest | 25/09/2026 | ZA | Healthcare / Pharma | pending | |
|
[AI generated] Morula IVF is a network of fertility clinics operating in Indonesia, specializing in in vitro fertilization (IVF) and other assisted reproductive technologies. It operates within the healthcare industry, specifically reproductive medicine, offering services such as fertility consultations, egg and sperm preservation, and infertility treatments. The company has multiple clinic locations across major Indonesian cities, serving patients seeking fertility treatment options. |
|||||||
| Ransomware | Tobin & Company View Details _ | Wallstreet | 25/09/2026 | US | Other | pending | |
|
Tobin & Company, CPA’s is a small accounting firm based in Harrison, New York, providing accounting, tax, auditing, and business consulting services, with a particular focus on nonprofit organizations. |
|||||||
| Ransomware | Ar Valve Resources View Details _ | Wallstreet | 25/09/2026 | GB | Energy | pending | |
|
AR Valve Resources is a UK-based distributor of industrial valves, actuators, regulators, instrumentation, and spare parts. Based in Kent, the company serves national and international customers with product sourcing, technical support, testing, certification, documentation, and shipping services. |
|||||||
| Ransomware | GTFM View Details _ | Wallstreet | 25/09/2026 | US | IT | pending | |
|
GTFM LLC is a company operating through gtfmllc.com. Its website currently provides limited publicly accessible information, so its specific products or services could not be confirmed. |
|||||||
| Ransomware | Beatus Cartons View Details _ | Wallstreet | 25/09/2026 | GB | Manufacturing / Engineering | pending | |
|
Beatus Cartons is a UK-based, privately owned manufacturer of printed folding cartons and packaging. Established in 1940, it produces solidboard, litho-laminated, and plastic packaging for industries including confectionery, pharmaceuticals, food, health and beauty, and automotive. |
|||||||
| Ransomware | Reliance Audit View Details _ | everest | 25/09/2026 | Services | pending | ||
|
[AI generated] N/A I don't have verified, reliable information about a specific company named "Reliance Audit." This name is generic and could refer to multiple small firms or local audit/accounting practices in different countries, so I cannot confirm details about its services, industry positioning, or country of operation without risking inaccurate information. |
|||||||
| Ransomware | UNIRITA View Details _ | everest | 25/09/2026 | JP | Services | pending | |
|
[AI generated] UNIRITA Inc. is a Japanese IT company headquartered in Tokyo, Japan, operating in the information technology and systems software industry. It specializes in IT operations management software, system infrastructure solutions, and IT services, including its well-known product "Senju Family" for job scheduling and system operation management. UNIRITA also provides IT consulting, systems integration, and outsourcing services primarily to enterprise clients in Japan. |
|||||||
| Ransomware | CENELEC View Details _ | everest | 25/09/2026 | BE | Services | pending | |
|
[AI generated] CENELEC (European Committee for Electrotechnical Standardization) is a Brussels, Belgium-based standardization organization operating across Europe. It develops voluntary electrotechnical standards to support the single market, covering electrical equipment, energy, and related technologies. Working alongside CEN and ETSI, it collaborates with national committees from European countries. Its industry is standardization and technical regulation within the electrotechnical and electronics sector. |
|||||||
| Ransomware | ETS View Details _ | everest | 25/09/2026 | Services | pending | ||
|
[AI generated] N/A "ETS" is too generic an identifier to reliably describe—there are numerous distinct organizations using this name or acronym across different industries and countries (for example, testing and assessment organizations, engineering firms, electronic transaction services, and technology companies), and without additional context I cannot determine which specific entity is being referenced. |
|||||||
| Ransomware | Breast Implant Center of Hawaii View Details _ | Wallstreet | 25/09/2026 | US | Healthcare / Pharma | pending | |
|
Breast Implant Center of Hawaii is a plastic surgery and aesthetics clinic serving patients across Hawaii. Based in Kailua-Kona, it offers breast augmentation, implant revision, breast lifts, body contouring. |
|||||||
| Ransomware | Majani Insurance Brokers View Details _ | Vexy Ransomware | 25/09/2026 | KE | Finance / Legal / Insurance | pending | |
|
Majani Insurance Brokers is an independent insurance broker serving both businesses and individuals. It arranges insurance products across areas including general business insurance, motor, medical, life, investment, marine, liability, property and agricultural-related covers |
|||||||
| Ransomware | Iberia Compositech Manufacturing View Details _ | qilin | 25/09/2026 | ES | Manufacturing / Engineering | leaked | |
|
N/A |
|||||||
| Ransomware | taspenlife.com View Details _ | lockbit5 | 25/09/2026 | KZ | Services | pending | |
|
Taspen Life offers a range of insurance products including health protection, group protection, and... |
|||||||
| Ransomware | anery.com.br View Details _ | lockbit5 | 25/09/2026 | BR | Retail / E-commerce | pending | |
|
Somos a Anery Home Care Temos paixão por cuidar Nossa especialidade é cuidar de pessoas, com todo o... |
|||||||
| Ransomware | corisricambi.it View Details _ | lockbit5 | 25/09/2026 | IT | IT | pending | |
|
Presenti sul territorio da oltre un ventennio, la CO.R.I.S. S.r.l. è cresciuta all'interno del... |
|||||||
| Ransomware | pharma5.ma View Details _ | incransom | 25/09/2026 | MA | Healthcare / Pharma | leaked | |
|
Pharma5 21, Rue des Asphodèles, Maârif Extension, 20100 Casablanca, Morocco 05 22 23 62 15 pharma5.ma Leaked data: 50Gb Corporate and financial information, data on products and their supply, quality control and certification, drug testing and related issues, employee personal data, counterparties, and much more. |
|||||||
| Ransomware | TapClicks (marketing analytics platform) View Details _ | N0n | 25/09/2026 | US | IT | pending | |
|
Marketing analytics / SaaS · United States | The complete platform source code (97,000+ commits with full history); The multi-tenant instance management system with production architecture; A customer's full marketing database: 354 advertising platform datasets, client lists, user accounts with password hashes, ad-platform connection credentials | Everything is real, complete and verifiable. | [ACTIVE: deadline 2026-09-28 01:59 UTC] |
|||||||
| Stealers | La haine Project 🇫🇷.rar View Details _ | LogsPlanet | 25/09/2026 | — | leaked | ||
|
📭 BUY PRIVATE — ADMIN: @BuzzLogsPlanet ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🔑Pass: [Telegram link: professional/enterprise only] ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🤑 Main Channel || Reserve Channel 🤑 |
|||||||
| Stealers | Acolyte Bases.rar View Details _ | LogsPlanet | 25/09/2026 | — | leaked | ||
|
📭 BUY PRIVATE — ADMIN: @BuzzLogsPlanet ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🔑Pass: @AcolyteBases ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🤑 Main Channel || Reserve Channel 🤑 |
|||||||
| Stealers | LogsPlanet [@ProjectLogsPlanet].rar View Details _ | LogsPlanet | 25/09/2026 | — | leaked | ||
|
📭 BUY PRIVATE — ADMIN: @BuzzLogsPlanet ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🔑Pass: @ProjectLogsPlanet ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🤑 Main Channel || Reserve Channel 🤑 |
|||||||
| Breaches | ParliamentUganda.csv View Details _ | NEW MIX | 25/09/2026 | UG | — | leaked | |
| Breaches | tiktakpet.co.il-2026-01-24-00-00.zip View Details _ | Database World ROC | 25/09/2026 | CO | — | leaked | |
| Breaches | 23543252352.xlsx View Details _ | Базы Директоров / ЛПР / | 25/09/2026 | — | leaked | ||
|
Компании строительного сектора - рост сотрудников 24/25 Есть номер телефона, почта Под запрос найдем контакты ЛПР. Связь: Telegram ВКонтакте +79397886929 Яндекс.Мессенджер Отзывы |
|||||||
| Breaches | СБП - @StormBaseAdapter.sql View Details _ | Database World ROC | 25/09/2026 | — | leaked | ||
|
Date: 2022 Records: 1M+ Contains: Full Name, Phone Number, Bank Name SBP (Stands for Faster Payments System). It’s basically Russia’s instant bank transfer system — you can send money using just someone’s phone number. |
|||||||
| Breaches | sample @duckyhax.zip View Details _ | Database World ROC | 25/09/2026 | — | leaked | ||
|
Selling the complete dump of afd.de, containing hundreds of thousands of emails, attachments, several hundred emails and other personal information including party officials and other high profile people. Sample included AfD (Alternative für Deutschland) is a right wing populist political party in Germany founded in 2013. It began as a Eurosceptic party opposing eurozone bailouts but later shifted focus to anti-immigration and anti-islam positions especially after the 2015 migrant crisis. The party is known for its nationalist stance and has faced controversy over links to far right extremism with parts of it monitored by German domestic intelligence. Size: 300GB (Compressed) Date of breach: 14.09.2026 Price: 1000$ |
|||||||
| Breaches | criminals_kz_2k.csv View Details _ | formaceft_db | 25/09/2026 | — | leaked | ||
|
666 |
|||||||
| Breaches | lomonosov_1.2M.csv View Details _ | formaceft_db | 25/09/2026 | — | leaked | ||
|
свежая выгрузка профилей участников научных олимпиад, конференций, школьников, студентов и абитуриентов с портала «Ломоносов» (ConfHub) Общий объём: ~1 122 800+ строк (1.2M) География: Россия — более 645 000+ Казахстан —~6870+ Привязка к организациям: 668 000+ участников с указанием точного места учёбы / работы [Telegram link: professional/enterprise only] 🖤 [Telegram link: professional/enterprise only] 🖤 [Telegram link: professional/enterprise only] |
|||||||
| Breaches | equrylys_experts_employments_sample_6k.csv View Details _ | formaceft_db | 25/09/2026 | — | leaked | ||
| Breaches | equrylys_master_sample_6k.csv View Details _ | formaceft_db | 25/09/2026 | — | leaked | ||
| Breaches | aisoip_corporate_debtors.csv View Details _ | formaceft_db | 25/09/2026 | — | leaked | ||
|
Урезанный сэмпл |
|||||||
| Breaches | aisoip_individuals_debtors_light_1.65M.csv View Details _ | formaceft_db | 25/09/2026 | — | leaked | ||
|
Урезанный сэмпл N2️⃣ |
|||||||
| Breaches | skb-techno.ru.zip View Details _ | Da | ta NeverDie | 25/09/2026 | RU | — | leaked | |
| Breaches | skarera.bitrix24.ru.zip View Details _ | Da | ta NeverDie | 25/09/2026 | RU | — | leaked | |
| Breaches | portal.1sb.su.zip View Details _ | Da | ta NeverDie | 25/09/2026 | — | leaked | ||
|
✔️Автор утечек: Wiskas |
|||||||
| Breaches | rusdorznak.ru.zip View Details _ | formaceft_db | 25/09/2026 | RU | — | leaked | |
| Breaches | 1sb.admin24.app.zip View Details _ | formaceft_db | 25/09/2026 | — | leaked | ||
|
✔️Автор утечек: Wiskas |
|||||||
| Ransomware | Armada Credit Bureau View Details _ | Spirals | 24/09/2026 | UG | Services | pending | |
|
Armada Credit Bureau Limited is a duly licensed credit reporting and analytics company |
|||||||
| Ransomware | Westside GI View Details _ | pear | 24/09/2026 | US | — | pending | |
|
Ambulatory endoscopy center |
|||||||
| Ransomware | Martin Lawrence Galleries View Details _ | pear | 24/09/2026 | US | Services | pending | |
|
Premier gallery of fine art in America |
|||||||
| Ransomware | Indroj Medical Group Inc. View Details _ | pear | 24/09/2026 | US | IT | pending | |
|
The Web's Free NPI Registry Search & Provider Reference Site |
|||||||
| Ransomware | efada.sa View Details _ | krybit | 24/09/2026 | SA | Services | pending | |
|
efada.sa... |
|||||||
| Ransomware | NEAD Pro View Details _ | rhysida | 24/09/2026 | null | leaked | ||
|
NEAD Pro Nead Pro is a professional multidisciplinary firm based in Gorizia and Udine, Italy, that provides legal, tax, bankruptcy, and accounting consulting services.What it is: a network share belonging to two Italian professional firms located at Via Roma 20, Gorizia (Friuli-Venezia Giulia):NEAD SRL (NORTH EAST ADVISORS S.R.L.) - an accounting firm, dottore commercialista, P.IVA 01114220310, REA GO-72906;NEAD PRO - PROFESSIONISTI RIUNITI - a law firm, P.IVA 01157140318.Volume: ~575,000 files / ~253 GB. The root contains a single branch Nuova directory\NEAD\ (plus an empty Documenti folder and a scatter of PDF scans at the root level).Structure and contents:Branch Volume ContentsNEAD PRO SITE - Documenti 231,137 files / 193.5 GB Law firm: 03.PRATICHE (46,620 files: CIVILE 9,665, PENALE 537, SOVRAINDEBITAMENTO 1,208), 04. INCARICHI (85,321: FALLIMENTI 22,492, ESECUZIONI 28,509, ADS 14,547, TRUST, CURATELE), SEGRETERIA with CREDENZIALI VARIE.xlsx (~40 firm accounts: SPID, PEC, banks, 2 cards with full PAN+CVC, safe code), bank scans (BANCOMAT PIN, BCC agreements)NEAD SRL SITE - Documenti 101,125 / 55.3 GB Accounting firm: 03.CLIENTI - 199 active + 184 former client folders (730, CU, F24, contracts), 44 private SOGEI Entratel .P12 keys (signing clients' tax returns), ISA/IRAP tax filings 2019�2020, client master data, Account.xlsxPRIMA NOTA - Documenti 1,885 / 871 MB Cash books 2019�2026 (21 xlsx): CASSA / CONTO CORRENTE / POS / CARTA / SISTERPOWERBI - Documenti 548 / 627 MB 37 financial BI models .pbix (BI_ISIDE, BI_NEAD, ATHENA, PNAI)ARCHIVIO 921 / 2.6 GB MPS bank statements 2020�2024, NEAD SRL account closure, firm mail archivePOSTA SARDAMAR / PANEGIOCHI / ISIDE / ADMIN SRL ~165+ / ~174 MB Client and firm mail: IVECO Capital leasing, accertamento Agenzia Entrate, Capitaneria di Porto, verbali poliziaES. IMM. 112-2024 10 files Real-estate enforcement proceedings (Tribunale di Gorizia): bank statements and CIE (ID cards) of auction participantsNEAD root ~85 PDF / 127 MB Scanned bank statements, F24 forms, IPZS envelope with the PIN/PUK of a CIE cardMost sensitive data: client dossiers with tax codes (codici fiscali), court case files (civil/criminal/bankruptcy), medical documents (Art. 9 GDPR), the firm's credential database with full PAN+CVC of two cards and the safe code, 52 Entratel electronic signature keys, ~100 SEPA mandates with IBANs and signatures, client PST archives (7.5 GB), a client's Huawei phone backup (Facebook/Gmail/Telegram databases), passports of foreign shareholders. More |
|||||||
| Ransomware | bnlawmacau.com www.bn-ip.com View Details _ | incransom | 24/09/2026 | MO | Finance / Legal / Insurance | pending | |
|
full data all country |
|||||||
| Ransomware | welgenone.com View Details _ | incransom | 24/09/2026 | US | Manufacturing / Engineering | pending | |
|
Welgen One is a mobile wellness service provider based in Georgia, USA, offering personalized wellness care and dispensary access across Atlanta. The company focuses on delivering innovative healthcare solutions, including remote patient monitoring and onsite wellness programs, to enhance overall well-being. Targeting individuals seeking convenient and comprehensive health services, Welgen One aims to revolutionize the healthcare experience by prioritizing patient-centered care. With a commitment to accessibility and customization, they utilize advanced technology and data to optimize health outcomes |
|||||||
| Ransomware | ukbjja.org View Details _ | incransom | 24/09/2026 | GB | — | pending | |
|
full data |
|||||||
| Ransomware | Prater & Ridley Attorneys At Law View Details _ | Wallstreet | 24/09/2026 | US | Finance / Legal / Insurance | pending | |
|
Prater, Ridley & Llamas – Attorneys at Law is a law firm based in Temple, Texas, United States. Established in 1993, it provides legal services in family law, criminal defense, probate, estate administration, and related civil matters for clients throughout Central Texas. |
|||||||
| Ransomware | Catholic University of El Salvador View Details _ | Wallstreet | 24/09/2026 | SV | Education | pending | |
|
The Catholic University of El Salvador (UNICAES) is a private Catholic university founded in 1982 in Santa Ana, El Salvador. |
|||||||
| Ransomware | Dao Group View Details _ | qilin | 24/09/2026 | IT | pending | ||
|
N/A |
|||||||
| Ransomware | All Tech Machine & Engineering View Details _ | qilin | 24/09/2026 | US | IT | pending | |
|
N/A |
|||||||
| Ransomware | Inversiones Bolívar View Details _ | qilin | 24/09/2026 | CO | Services | pending | |
|
N/A |
|||||||
| Ransomware | Zig Inge Group View Details _ | qilin | 24/09/2026 | AU | Services | pending | |
|
N/A |
|||||||
| Ransomware | Wallatec View Details _ | akira | 24/09/2026 | Manufacturing / Engineering | pending | ||
|
Wallatec creates high-performance carbonation systems for restaurants and busy kitchens. Their equipment is built to handle intense daily use, working perfectly even in the most hectic envir onments. We will upload 15gb of corporate data soon. Employee information (passports), projects, financi als, client information and so on. |
|||||||
| Ransomware | Agora coopérative agricole View Details _ | qilin | 24/09/2026 | FR | Services | pending | |
|
N/A |
|||||||
| Ransomware | GDM Pipelines View Details _ | qilin | 24/09/2026 | GB | Manufacturing / Engineering | pending | |
|
N/A |
|||||||
| Ransomware | Strack Companies View Details _ | akira | 24/09/2026 | US | IT | pending | |
|
Strack Construction is a commercial and industrial construction contractor headquartered in St. Joseph, Minnesota. Founded in 1938, the family-owned company provides design-build, general co ntracting, construction management, and real estate development services. We will upload 60gb of corporate data soon. Employee information, projects (drawings and specif ications), detailed financials, client information, NDAs and so on. |
|||||||
| Ransomware | Revolut View Details _ | ImNotAVillain | 24/09/2026 | GB | Finance / Legal / Insurance | pending | |
|
Revolut data on sale. Contact information at the bottom of the page. Includes 680 high-value networth users. |
|||||||
| Ransomware | Italy View Details _ | ImNotAVillain | 24/09/2026 | IT | — | pending | |
|
Italy is being exposed for failing to follow proper data protection laws. Includes 85,000+ Files — 150GB. Top departments, units, offices affected. |
|||||||
| Ransomware | airtanzania.co.tz / airtanzania.com View Details _ | krybit | 24/09/2026 | TZ | Transportation / Travel / Logistics | pending | |
|
Air Tanzania Company Limited (ATCL) is the national flag carrier airline of Tanzania, established on March 11, 1977 foll... |
|||||||
| Ransomware | www.jonesthegrocer.com View Details _ | krybit | 24/09/2026 | AU | Retail / E-commerce | pending | |
|
Jones the Grocer is a premium gourmet food retail and cafe brand founded in 1996 in Sydney, Australia, originally launch... |
|||||||
| Ransomware | Grupo Caberj View Details _ | incransom | 24/09/2026 | BR | — | pending | |
|
O Grupo Caberj, que oferece uma ampla gama de seguros, foi hackeado há 10 dias |
|||||||
| Ransomware | winfashion View Details _ | dragonforce | 24/09/2026 | Retail / E-commerce | leaked | ||
|
══════════════════════════ ══════════════════════════ ══════════════════════════ WINFASHION TECHNOLOGIES DUMP: DATA LEAK ANALYSIS OF A B2B ERP PLATFORM FOR THE FASHION INDUSTRY ══════════════════════════ ══════════════════════════ ══════════════════════════ This is a preliminary analysis, processing of sensitive data is currently underway. Target: WinFashion Technologies (Los Angeles, USA) — an international B2B provider of ERP solutions (WF125sR / Fabric ERP V.10) for 250+ fashion brands. Offices in New York, Shanghai, and India. Integrations: Shopify, Acenda, JOOR, NuORDER, CommerceHub, FashionGo. BPO/EDI processing via Inovis/QRS. DUMP VOLUME: ~205K files / ~13K directories / ~73 Gigabytes AT-RISK FILES: 125,274 (61.0%) Critical: 9,350 High: 78,174 Medium: 37,750 PRELIMINARY FINDINGS: ▸ kaktus.bak (5.64 GB) — full MSSQL backup of the "Kaktus" client's ERP installation (Customer Master, Style Master, EDI, AR) ▸ 6 SSL PFX containers + EDI-VAN client certificate for ECGrid/OpenText ▸ 33,307 .shxml files — WinSCP SFTP session logs (hosts, paths, sizes) ▸ 332 ASP.NET Web.config files — potentially hardcoded Shopify / Authorize.Net secrets ▸ 171 files with PAN / CreditCard / Cardholder / Payment data — Authorize.Net payment processing code ▸ 39 files with IBAN / SWIFT / BankAccount data — bank account details ▸ 259 Invoice Register / Invoice data files — Excel payment registers (up to 124 MB) CLIENT DATA (~40 BRANDS): ▸ STYLEMASTER.xlsx (48 MB) — aggregated product catalog export ▸ Vendors.XLS (20 MB) + test customers.XLS (7 MB) — Kaktus vendors and customers ▸ 40,621 EDI files (.edi / .850 / .856 / .810 / .997 / .852 / .832 / .846) — full B2B trade lifecycle (PO, ASN, invoices, price catalogs) INTELLECTUAL PROPERTY: ▸ 8,577 .cs files — integration source code (Authorize.Net, Shopify, Acenda, JOOR, NuORDER, DSCO) ▸ 5,828 .pbd files — PowerBuilder WF125sR ERP core ▸ 3,398 .sql files — DB schema, triggers, CLR procedures ▸ 18 .dbf / .mdf files — legacy DBASE / FOXPRO / MSSQL tables without encryption HR / PII: ▸ INV EMPLOYEE ALLOWANCE YTD.xlsx (76 MB) — employee HR data ▸ AR Aging 12.30.25.xls + AR Aging 12.29.25.XLS — accounts receivable for Monrow and Kaktus clients REGULATORY RISKS: ▸ PCI DSS — compromise of PAN processing code + Authorize Excel registers ▸ CCPA / CPRA — HR-PII (76 MB), California jurisdiction ▸ FTC — "total security" claims amidst PFX / DBF / Web.config compromise ▸ SEC (Regulation FD) — risk for publicly traded client issuers ▸ GDPR — PII of customers / vendors across ~40 brands The dump represents a cross-tenant B2B SaaS incident involving the disclosure of trade secrets for ~40 fashion brands, the compromise of the Authorize.Net payment infrastructure, and the exposure of the full ERP source code. |
|||||||
| Ransomware | agiliance.fr View Details _ | ZaWoo | 24/09/2026 | FR | IT | leaked | |
|
Agiliance is a French accounting and business advisory group headquartered across the Haute-Saône and Doubs regions. Its website describes Agiliance as the result of bringing together 8 small-to-medium-sized accounting firms, combining their expertise and tools while retaining a local, client-oriented approach. |
|||||||
| Ransomware | www.francare.com View Details _ | ZaWoo | 24/09/2026 | FR | IT | leaked | |
|
FRANCARE Industries is a French international technical-supply, engineering, and maintenance company, headquartered in Paris, France. The company was founded in 1988 and specializes in supplying equipment, technologies, and technical services to industrial and healthcare customers internationally |
|||||||
| Ransomware | amb-pvc.com View Details _ | ZaWoo | 24/09/2026 | FR | Manufacturing / Engineering | pending | |
|
AMB (Ateliers de Menuiseries Bidet), also known as Atelier de Menuiseries Bidet, is a French manufacturer specializing in PVC and aluminium joinery products. The company is based in Bourguenolles, Normandy, France. Its website is amb-pvc.com. |
|||||||
| Ransomware | Arizona Vascular Medical Equipment, Inc View Details _ | dragonforce | 24/09/2026 | US | Healthcare / Pharma | leaked | |
|
Arizona Vascular Medical Equipment, Inc. is a trusted provider of specialized medical devices, focusing primarily on compression therapy solutions and vascular care equipment. Headquartered in Mesa, Arizona, the company is dedicated to improving patient mobility and quality of life by delivering high-quality medical products and personalized customer service across the United States. |
|||||||
| Ransomware | BMGP Groupe View Details _ | dragonforce | 24/09/2026 | FR | Manufacturing / Engineering | pending | |
|
BMGP Groupe (Polyresine) is an established French manufacturer specializing in the formulation, production, and distribution of synthetic resins and high-performance technical polymers. Founded in 1972, the company serves a wide range of industrial sectors, providing tailored chemical formulations for applications such as industrial flooring, waterproofing, encapsulation, and specialized coatings. They are known for engineering reliable, durable chemical solutions to meet complex industrial specifications. |
|||||||
| Ransomware | Elite Industech Co., Ltd View Details _ | dragonforce | 24/09/2026 | TH | Manufacturing / Engineering | leaked | |
|
Elite Industech Co., Ltd. (established in 2003) is a certified Class-A waste treatment plant based in Kaohsiung, Taiwan. The company operates within the circular economy sector, specializing in the eco-friendly processing of electronic waste (E-waste) and the recycling of rare and precious metals |
|||||||
| Ransomware | HEC Group View Details _ | dragonforce | 24/09/2026 | TW | Services | pending | |
|
On August 30, HEC Group issued an official statement addressed to shareholders of TPE:3032 and other stakeholders, announcing that the company had been the target of a cyberattack. In its statement, the company claimed that the breach was detected immediately, that high-tech countermeasures were deployed, and that no corporate documentation was lost. The incident was characterized as a minimal, random occurrence. The reality, however, is starkly different. Our operation against the company began weeks prior to that publication. Due to a systemic failure to implement basic security principles, we gained nearly total control over the infrastructure supporting the development and commercial operations of the entire corporate group. We conducted a methodical and comprehensive review of the documentation, exfiltrating a vast amount of data. We remained undetected for as long as necessary to secure everything we sought. Only after completing our objectives did we initiate the data encryption process, the company's technical staff did not even detect our presence until many hours later. At the time of their official announcement, HEC Group's leadership knew the statement was entirely false. Its sole purpose was to manipulate stock market trading. Instead of contacting us to mitigate the damage, management chose to deceive the exchange. When we finally managed to contact the company's leadership and offered them a chance to make their official statement more truthful in exchange for the deletion of the taken documents, they showed no interest. If the leadership of HEC Group has decided to pursue a path of selfdestruction, we will not stand in their way. To prove that HEC Group’s statement was a fabrication and that our claims are accurate, we will now publish a portion of the exfiltrated data. This initial release will consist of over 360,000 files, drawn from a total volume measuring in terabytes. This data will provide stock exchange regulators and partner companies with exhaustive evidence of the actual events. The remaining documents will not be released publicly at this time, as we have devised a more strategic use for them. While the countdown timer below this publication runs, the companies affiliated with HEC Group, their shareholders, and regulatory authorities have time to prepare. HEC Group has one final opportunity to accept our proposal and avoid the consequences. |
|||||||
| Ransomware | Final statement re PSA View Details _ | shinyhunters | 24/09/2026 | null | pending | ||
|
Good afternoon, We have no further comments to make regarding our PSA statement we released the other day. Our organisation is highly confident we have achieved our goal and our intentions we repeatedly made clear to journalists and in our public statements. There is 5 days remaining still. We have no comment yet regarding what we will do if the victim entity does not comply with our kind request . Nonetheless, we got what we wanted and we have a business to run and operate as usual. We will not be responding to any press inquiries about this and we will not be sharing updates about other datasets we have that we did not yet disclose to the public. We reiterate and want to assiduously emphasise we are NOT extorting the victim in question, this is NOT financially motivated and this is NOT a ransom. Thank you for your time and attention to this matter. This is now old news. Regards, SH | Updated: 24 Sep 2026 |
|||||||
| Ransomware | Solucioning S.A. View Details _ | Barracuda | 24/09/2026 | AR | — | leaked | |
|
This is a small company of 4-5 people, yet it has big clients in the oil production sector. Unfortunately, the company neglected data security, allowing us to gain access to all their confidential files - projects, documents, blueprints, and so on. The company has been ignoring us for five days now, and we will soon publish their files. This is a warning. We do not wish to harm anyone, but we are prepared to inflict maximum damage. Victim website: https://www.solucioning.com/ | Severity: HIGH | Size: 463 GB | Status: selling | $100,000 |
|||||||
| Ransomware | eTeam View Details _ | EndZone | 24/09/2026 | IT | pending | ||
|
Revenue: Revenue: $229 million eTeam Inc. is a privately held global workforce solutions and business transformation company. Founded in 1999 by Ben Thakur, the company is certified as a Minority Business Enterprise (MBE). It has grown from a boutique IT staffing agency into a massive global network, managing thousands of internal employees and contract workers across continents. We successfully exfiltrated all employee records (15K), including full names, email addresses, home addresses, DOBs, SSNs, phone numbers, contracts, managers, hire dates, salaries and more. We engaged with eTeam privately some time back, and now we are going public with the announcement as eTeam was negligent of the incident that took place then. We're giving you one more chance. Speak soon or leak soon! |
|||||||
| Stealers | OnlyLogs - @OnlyLogsCloud.rar View Details _ | LogsPlanet | 24/09/2026 | — | leaked | ||
|
📭 BUY PRIVATE — ADMIN: @BuzzLogsPlanet ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🔑Pass: [Telegram link: professional/enterprise only] ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🤑 Main Channel || Reserve Channel 🤑 |
|||||||
| Stealers | LINK ТG - @WichLoveFromR.rar View Details _ | Pegasus Cloud | 24/09/2026 | — | leaked | ||
|
Free Upload Pass: @AltairSupport ➡️ Channel sponsor 🟦 Reserve Channel 🟦 |
|||||||
| Stealers | CenturionTXT.rar View Details _ | LogsPlanet | 24/09/2026 | — | leaked | ||
|
📭 BUY PRIVATE — ADMIN: @BuzzLogsPlanet ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🔑Pass: [Telegram link: professional/enterprise only] ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🤑 Main Channel || Reserve Channel 🤑 |
|||||||
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.012 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.011 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.010 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.009 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.008 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.007 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.006 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.005 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.004 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.003 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.002 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo.io Full 126M 380GB Tg @ShuiYazi.7z.001 View Details _ | Database World ROC | 24/09/2026 | IO | — | leaked | |
| Breaches | Apollo_BF.7z.004 View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | Apollo_BF_.7z.001 View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | Apollo_BF_.7z.002 View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | Apollo_BF_.7z.003 View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | ForsCraft Survival 2020.rar View Details _ | sliv_mine | Сливы сборок и прочего кала | 24/09/2026 | — | leaked | ||
|
Выживание ForsCraft 2020 года, ранее слитая но все ссылки стёрло временем. Сливаем сюда |
|||||||
| Breaches | clarkinternationalairport.com 菲律宾克拉克机场.csv View Details _ | NEW MIX | 24/09/2026 | — | leaked | ||
| Breaches | xNovisBack.7z View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
|
antlantique.ma |
|||||||
| Breaches | data.rar View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
|
suptech-sante.ma By @xnov1337 |
|||||||
| Breaches | Immatriculation_AU_19_02_2026 accepted.csv View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | Immatriculation_AU_19_02_2026 rejected.csv View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
|
Full name of the student National ID number (CIN) University registration number (Immatricule) CNE (Student National Exam Number, if available) Date of birth Registration status (e.g., Immatriculated / Rejected) Rejection reasons (e.g., identity verification errors) By @xnov1337 |
|||||||
| Breaches | Smarteez.7z View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
|
Smarteez is a Moroccan digital factory based in Casablanca, Morocco, specializing in custom web and mobile solutions. Founded over 10 years ago, the company serves clients across North Africa and Europe, including major brands such as L’Oréal (Vichy, La Roche-Posay), Total Maroc, SAHAM Assurance, and Carglass. With 38+ active applications and over 1 million daily connections, Smarteez manages sensitive business data for dozens of enterprise clients. By @xnov1337 |
|||||||
| Breaches | aui.ma_xNov.csv View Details _ | Database World ROC | 24/09/2026 | MA | — | leaked | |
|
Date: ~Apr 2026 Records: 4,039 Contains: ID Full Name, ID Number, Email Address By @xnov1337 |
|||||||
| Breaches | StormForum.csv View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
|
Russian retards' forum Leak Date: 2023-2024 Records: 142 Contains: user_id, username, username_date, username_date_visible, email, custom_title, language_id, style_id, timezone, visible, activity_visible, user_group_id, secondary_group_ids, display_style_group_id, permission_combination_id, message_count, question_solution_count, conversations_unread, register_date, last_activity, last_summary_email_date, trophy_points, alerts_unviewed, alerts_unread, avatar_date, avatar_width, avatar_height, avatar_highdpi, gravatar, user_state, security_lock, is_moderator, is_admin, is_banned, reaction_score, vote_score, warning_points, is_staff, secret_key, privacy_policy_accepted, terms_accepted |
|||||||
| Breaches | fokusfit.com.br.csv View Details _ | Database World ROC | 24/09/2026 | BR | — | leaked | |
| Breaches | F16#mosadxyusosat.7z View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
|
F-16 Engine Design Documents |
|||||||
| Breaches | DUMP ULP 24.09.2026 Base34 1.txt View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | DUMP ULP 24.09.2026 Base34 2.txt View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | DUMP ULP 24.09.2026 Base34 3.txt View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | DUMP ULP 24.09.2026 Base34 4.txt View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Breaches | DUMP ULP 24.09.2026 Base34 5.txt View Details _ | Database World ROC | 24/09/2026 | — | leaked | ||
| Ransomware | OnTrac View Details _ | emperador | 23/09/2026 | US | Transportation / Travel / Logistics | pending | |
|
OnTrac is a major last-mile e-commerce delivery company formed by the 2021 merger of LaserShip and OnTrac. It positions itself as a direct alternative to FedEx and UPS, offering coast-to-coast coverage, 7-day-a-week operations, and competitive rates to reach over 75% of the U.S. population. We hold your full employee database, 197k records of employee PII: employeeNumber,xrefCode,firstName,middleName,lastName,loginId,employeeId,hireDate,originalHireDate,startDate,terminated,roles,legalEntity,legalEntityAddress,homePhone,mobilePhone,businessPhone,businessMobile,pager,personalFax,personalEmail,businessEmail,facebook,linkedin,addressPrimary1,addressPrimary2,addressMailing1,addressMailing2,userApproved,nativeAuth,culture We demand an amount of 1 million, otherwise your data WILL be publicly posted. Instructions will be emailed to you shortly. If you do not receive them, contact me on session, or email me. Session: 05651c7323273b723588d47455471ee9e27feb5187a30f2933554a705aacb38358 Email: [email protected], [email protected] (I prefer session.) If you do not cooperate, your partners and employees will be targeted. Emails were sent to: [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected] [Sector: Retail, Transportation] |
|||||||
| Ransomware | Abtach Ltd. View Details _ | Barracuda | 23/09/2026 | null | pending | ||
|
Abtach Ltd. was renamed Intersys Ltd.—a Pakistani company engaged in fraud targeting the US. The company’s employees charged fees for services that did not actually exist. The company’s founder, Azneem Bilwani, was involved in the illicit trafficking of synthetic opioids and fentanyl analogues, which were supplied to the US market via the eWorldTrade marketplace. We encrypted all virtual machines and snapshots on their ESXi hypervisors and all files on employee computers, and exfiltrated 1.5 TB of data from their infrastructure. We possess all their documents and bank records, which contain evidence of Azneem Bilwani’s illegal activities. Will be published soon... | Severity: HIGH | Size: 1.5 TB | Status: selling | $100,000 |
|||||||
| Ransomware | goldstarfinancial.com View Details _ | BrainCipher | 23/09/2026 | US | Finance / Legal / Insurance | leaked | |
|
[AI generated] N/A I don't have reliable, verified information about a specific company operating at "goldstarfinancial.com." There are multiple businesses that have used similar "Gold Star Financial" naming conventions in different jurisdictions (this is a fairly generic name used by mortgage brokers, lending companies, and financial services firms in various countries), so I cannot confidently confirm which specific entity this domain refers to, its current operational status, ownership, or verified business details without risking inaccurate attribution. If you can provide additional context (such as the specific country, registration details, or services advertised on the site), I can help assess it more accurately. Alternatively, if this is for threat intelligence purposes, I'd recommend verifying details through domain registration records (WHOIS), business registries, or regulatory filings relevant to |
|||||||
| Ransomware | Tomix / Grupo JOPER View Details _ | spacebears | 23/09/2026 | PT | IT | pending | |
|
Tomix – Indústria de Equipamentos Agrícolas e Industriais, Lda. is a Portuguese manufacturer of crop-protection equipment, best known for agricultural sprayers, atomizers, dusters and related machinery. Founded in 1924 near Torres Vedras by Francisco Xavier Damião, it grew into a market leader in Portugal for plant-treatment equipment, including rotomoulded tanks and high-pressure washers. Since 1997 Tomix has been majority-owned by JOPER – Indústria de Equipamentos Agrícolas, S.A., and today it operates as part of the family-run JOPER Group alongside JOPER and Ribatejo. Together they supply complementary agricultural machinery for transport, soil tillage and crop treatment across Iberia and export markets https://tomix.com.pt/ |
|||||||
| Ransomware | vestfrostsolutions.com View Details _ | settra | 23/09/2026 | NO | IT | pending | |
|
Vestfrostsolutions.com The company sells reliability and precision — back bar coolers for Red Bull, ... |
|||||||
| Ransomware | Legis View Details _ | rhysida | 23/09/2026 | null | pending | ||
|
Legis Legis is a well-known Latin American publisher that creates specialized legal and business information resources. Founded over 60 years ago, the company serves professionals across six countries including Colombia, Venezuela, Argentina, Mexico, Peru, and Chile.DATABASES (SQL)PST/OSTLEGAL DOCUMENTS:Tutela - constitutional actions with claimants' personal dataID card copies (cedulas) of shareholders and third partiesEnvironmental sanction proceedings against the company (AUTO 10852)Sanction dispute with the pension authority (UGPP)Signed cease & desist - trademark dispute (Xpandia case)Personal data transfer agreements (Colsubsidio, Universidad Externado)Litigation log of all company lawsuitsContract matrix, payment agreements, reorganization documentsFINANCE & OWNERSHIP:Shareholder and ultimate-beneficial-owner register with ID copiesOwnership structure: ~99.94% held by a single ownerDividend payment recordsDebt write-off letters naming debtors and amountsFinancial and tax reporting (exogena, estados financieros)CUSTOMERS:Customer databases: law firms, universities, government contractorsIncluding Ecopetrol, Halliburton, the AIM state agency, hundreds of companiesTax IDs (NIT), contacts, contract history More |
|||||||
| Ransomware | ASYAD GROUP View Details _ | Spirals | 23/09/2026 | OM | IT | pending | |
|
Asyad Group is Oman’s global integrated logistics provider, ranked 4th on Forbes’ “10 Biggest Logistics Companies in MENA” list. |
|||||||
| Ransomware | Trump Mobile View Details _ | EndZone | 23/09/2026 | US | — | pending | |
|
Revenue: 4K Users Trump Mobile is an American mobile virtual network operator (MVNO) that uses a licensed brand from the Trump Organization and was launched by Donald Trump Jr. and Eric Trump. THEY GOT FKED LOL. ONLY 4K USERS? LOL Includes eSIM QR codes and user PII. |
|||||||
| Ransomware | ALDOGROUP.COM(ALDOSHOES.COM) View Details _ | clop | 23/09/2026 | CA | Retail / E-commerce | leaked | |
|
[AI generated] Aldo Group (aldoshoes.com) is a Canadian footwear and accessories company headquartered in Montreal, Quebec. Operating in the retail and fashion industry, it designs, manufactures, and sells shoes, handbags, and accessories through brands including ALDO, Call It Spring, and Globo. The company operates retail stores and e-commerce platforms internationally, serving customers across North America, Europe, the Middle East, and Asia. |
|||||||
| Ransomware | BRILLONCONSUMER.COM(BRILLONCONSUMER.COM) View Details _ | clop | 23/09/2026 | US | Retail / E-commerce | pending | |
|
[AI generated] N/A |
|||||||
| Ransomware | SUUNTO.CN(SUUNTO.COM) View Details _ | clop | 23/09/2026 | FI | Manufacturing / Engineering | pending | |
|
[AI generated] Suunto is a Finnish company specializing in the design and manufacture of sporting instruments, including dive computers, sports watches, and precision instruments such as compasses. Founded in Finland, the company operates in the consumer electronics and sports technology industry, serving outdoor enthusiasts, divers, and athletes worldwide. Suunto.cn represents its presence in the Chinese market, distributing and marketing products regionally while the parent company remains headquartered in Finland. |
|||||||
| Ransomware | SMAPCENTER-UAH.EDU View Details _ | clop | 23/09/2026 | US | Education | pending | |
|
[AI generated] N/A |
|||||||
| Ransomware | DAD-CO.TH View Details _ | clop | 23/09/2026 | TH | Other | leaked | |
|
[AI generated] N/A I don't have reliable, verifiable information about a specific company named "DAD-CO.TH." The ".TH" suffix suggests a possible connection to Thailand, but I cannot confirm details about this entity's operations, industry, or activities without risking providing fabricated or inaccurate information. If you have additional context or source material about this company, I'd be happy to help analyze it. |
|||||||
| Ransomware | CLOUD-CLEARWAYGROUP.COM View Details _ | clop | 23/09/2026 | US | IT | leaked | |
|
[AI generated] N/A I don't have verified, reliable information about a company associated with the domain "CLOUD-CLEARWAYGROUP.COM." This domain naming pattern (cloud-[company]) is also commonly associated with phishing or fraudulent infrastructure rather than legitimate registered businesses, so I cannot provide factual details about its operations, industry, or country without risking inaccurate information. |
|||||||
| Ransomware | HODERO-HOLDINGS-LTD View Details _ | clop | 23/09/2026 | Other | leaked | ||
|
[AI generated] N/A I do not have reliable, verifiable information about a specific company named "HODERO-HOLDINGS-LTD" in my knowledge base. Providing fabricated details about its industry, operations, or country would risk generating inaccurate threat intelligence. If you have additional context, source documents, or registry details about this entity, please share them and I can help analyze that information. |
|||||||
| Ransomware | KVHELI-WORDPRESS.COM View Details _ | clop | 23/09/2026 | GE | IT | leaked | |
|
[AI generated] N/A This appears to be a WordPress subdomain (a default naming pattern used by WordPress.com for hosted blogs/sites, typically formatted as "sitename.wordpress.com") rather than a registered company with verifiable business operations, industry classification, or country of headquarters. There is no reliable, publicly available information identifying "kvheli" as an established business entity. |
|||||||
| Ransomware | CCCM-BC.CA View Details _ | clop | 23/09/2026 | CA | Services | leaked | |
|
[AI generated] N/A I don't have reliable, verifiable information about a specific entity named "CCCM-BC.CA." This appears to be a domain-like string, and without confirmed data on its registration, ownership, or business activities, I cannot accurately describe its operations, industry, or country of operation without risking fabrication. |
|||||||
| Ransomware | BRINKS-CO.NZ View Details _ | clop | 23/09/2026 | NZ | Retail / E-commerce | leaked | |
|
[AI generated] N/A I don't have verified information about a company operating under the domain "BRINKS-CO.NZ." I want to flag that this domain name is worth treating with caution from a threat intelligence perspective: it closely mimics "Brinks," the well-known US-based security and cash logistics company, while using a New Zealand country-code domain, a pattern sometimes associated with typosquatting or brand impersonation for phishing purposes. I cannot confirm whether this is a legitimate New Zealand subsidiary, an unrelated business, or a malicious lookalike domain without further verification through domain registration records, WHOIS data, or corporate registries. I'd recommend checking NZ Companies Office records and domain registration history before treating this as a legitimate entity. |
|||||||
| Ransomware | SAUL-ORG.UK View Details _ | clop | 23/09/2026 | GB | Other | pending | |
|
[AI generated] N/A I don't have reliable, verifiable information about a specific company operating under the name "SAUL-ORG.UK." This appears to be a domain-style identifier rather than a confirmed registered business name I can accurately profile. Providing fabricated details about its industry, operations, or activities would risk generating false threat intelligence. If you have additional context, such as WHOIS data, associated IP addresses, or observed activity, I can help analyze those specifics instead. |
|||||||
| Ransomware | CCED-COM.OM View Details _ | clop | 23/09/2026 | OM | Services | pending | |
|
[AI generated] N/A I don't have reliable information about a company called "CCED-COM.OM." This does not correspond to a verifiable, known organization in available records. The name format resembles a domain name (.om is the country code top-level domain for Oman), but I cannot confirm details about its business operations, industry, or ownership without verified sourcing. Please provide additional context or verify the name. |
|||||||
| Ransomware | INFINIGATE.CH(INFINIGATE.CO.UK) View Details _ | clop | 23/09/2026 | GB | IT | pending | |
|
[AI generated] Infinigate is a cybersecurity-focused value-added distributor (VAD) operating across Europe, including Switzerland (infinigate.ch) and the United Kingdom (infinigate.co.uk). It distributes IT security, networking, and cloud solutions from various technology vendors to resellers and partners, offering services like technical support, training, and cloud enablement. The company operates in the IT security and distribution industry, headquartered in Switzerland with a broad European presence. |
|||||||
| Ransomware | SWEETLAKE-LAND-AND-OIL-CO-INC View Details _ | clop | 23/09/2026 | Energy | pending | ||
|
[AI generated] N/A |
|||||||
| Ransomware | KIRKLAND-AND-ELLIS.LLP View Details _ | clop | 23/09/2026 | US | Finance / Legal / Insurance | pending | |
|
[AI generated] Kirkland & Ellis LLP is a major international law firm headquartered in Chicago, Illinois, United States. Founded in 1909, it provides legal services across practice areas including private equity, mergers and acquisitions, litigation, restructuring, intellectual property, and tax law. It is one of the highest-grossing law firms globally, serving corporate clients, financial institutions, and investment firms, with offices across the United States, Europe, and Asia. |
|||||||
| Ransomware | PALIG.COM View Details _ | clop | 23/09/2026 | CZ | IT | pending | |
|
[AI generated] PALIG.COM is the domain for Pennsylvania Lumbermens Mutual Insurance Company, often referred to as PALIG or PLM Insurance. It operates in the insurance industry, specializing in property and casualty coverage for the lumber, woodworking, and building materials industries. The company is headquartered in Philadelphia, Pennsylvania, and primarily operates within the United States, serving specialty commercial insurance markets. |
|||||||
| Ransomware | COLUMBIABANK.COM(UMPQUABANK.COM) View Details _ | clop | 23/09/2026 | US | Finance / Legal / Insurance | pending | |
|
[AI generated] Columbia Banking System, operating under the domains columbiabank.com and umpquabank.com, is a U.S.-based financial holding company headquartered in Tacoma, Washington. Following its merger with Umpqua Holdings, it operates as Umpqua Bank, providing retail banking, commercial banking, lending, wealth management, and financial services to individuals and businesses primarily across the western United States, including Washington, Oregon, California, Idaho, and Nevada. |
|||||||
| Ransomware | UNISALLE-EDU.CO View Details _ | clop | 23/09/2026 | CO | Education | pending | |
|
[AI generated] N/A I don't have reliable, verified information about a specific company or organization named "UNISALLE-EDU.CO." This appears to be a domain name, possibly related to a La Salle university educational institution, but I cannot confirm details about its operations, industry classification, or country of operation without risking providing inaccurate information. If you have additional context or source material about this entity, I'd be happy to help analyze it. |
|||||||
| Ransomware | VALLEY-TRUCK-AND-TRACTOR View Details _ | clop | 23/09/2026 | Manufacturing / Engineering | pending | ||
|
[AI generated] N/A I don't have reliable, verifiable information about a specific company named "VALLEY-TRUCK-AND-TRACTOR." This name resembles a generic business naming convention common among agricultural and heavy equipment dealerships in the United States (dealers selling/servicing tractors, farm machinery, and trucks), but without verified sourcing I cannot confirm details about this specific entity's operations, location, or history. |
|||||||
| Ransomware | KSS-ARCHITECTS-LLP View Details _ | clop | 23/09/2026 | Construction / Real Estate | deleted | ||
|
[AI generated] N/A I don't have verified, reliable information about a specific company called "KSS-ARCHITECTS-LLP" in my knowledge base. I cannot confirm details about its operations, industry specifics, founding, location, or business activities with confidence. Providing fabricated details about a company name would risk generating inaccurate threat intelligence, which could be misleading if used in actual analysis or decision-making. |
|||||||
| Ransomware | ELANDRETAIL.COM-KMALL24.COM View Details _ | clop | 23/09/2026 | KR | Retail / E-commerce | pending | |
|
[AI generated] N/A |
|||||||
| Ransomware | TRANSPORT-NSW.GOV.AU View Details _ | clop | 23/09/2026 | AU | Transportation / Travel / Logistics | pending | |
|
[AI generated] Transport for NSW (transport.nsw.gov.au) is the New South Wales government agency responsible for planning, coordinating, and delivering public transport, roads, and infrastructure services across the state. It operates trains, buses, ferries, and light rail networks, and manages road safety and traffic systems. It falls under the government/public transportation industry and operates within Australia, specifically New South Wales. |
|||||||
| Ransomware | AMEY-CO.UK View Details _ | clop | 23/09/2026 | GB | Other | pending | |
|
[AI generated] N/A I don't have verified, reliable information about a specific company operating under the domain "AMEY-CO.UK." Note that this appears distinct from "Amey plc" (amey.co.uk), a well-known UK infrastructure and facilities management company, but I cannot confirm whether this domain reference is accurate, a typo, or a different entity, so I won't speculate on details. |
|||||||
| Ransomware | Urban Engineering View Details _ | akira | 23/09/2026 | Manufacturing / Engineering | pending | ||
|
Urban Engineering is a company that specializes in providing engineering services. They focus o n delivering innovative solutions for various projects. Their intended clients include business es and organizations seeking professional engineering expertise. The company is headquartered i n Annandale, Virginia. We will upload 20gb of corporate data soon. Employee information, projects, lots of financial d ocuments, contracts and agreements, NDAs and so on. |
|||||||
| Ransomware | Lemon Law View Details _ | incransom | 23/09/2026 | US | Finance / Legal / Insurance | pending | |
|
Virginia A Lemon PLLC 267 Stratton Aly, Lewisburg, West Virginia, USA vlemonlaw.com Leaked data: 16.8 Gb, 42к files corporate documents, litigation materials, client personal data, financial documents and reporting, personal files of employees, and much more. |
|||||||
| Ransomware | HIT dd View Details _ | akira | 23/09/2026 | null | pending | ||
|
HIT d.d. is a prominent entertainment and gaming provider based in Nova Gorica, Slovenia, offer ing a diverse range of services including hotels, casinos, wellness centers, and dining options . With over 40 years of experience, the company operates multiple resorts and entertainment ven ues across Slovenia and Bosnia and Herzegovina, catering to both local and international client s. We will upload 367gb of corporate data soon. Detailed employee personal information (passports, licenses, names, addresses, phones, email and so on), financials, confidential agreements, cli ent data, interesting casino files, NDAs and so on. |
|||||||
| Ransomware | Apex Litigation Support View Details _ | akira | 23/09/2026 | Finance / Legal / Insurance | pending | ||
|
Apex Litigation Support is a business that provides comprehensive litigation services to attorn eys and law firms. Our team of experienced professionals is committed to delivering accurate an d timely results that exceed our client's expectations. We will upload 77gb of corporate data soon. Detailed employee and clients personal information (passports, licenses, names, addresses, phones, emails and so on), personal financials, confide ntial files, enormous amount of client data, lots of NDAs and so on. |
|||||||
| Ransomware | Inkript View Details _ | qilin | 23/09/2026 | IT | pending | ||
|
N/A |
|||||||
| Ransomware | AGROFRUTO SAC View Details _ | arcusmedia | 23/09/2026 | PE | Agriculture / Food | pending | |
|
agrofruto.pe—We are a Peruvian company in the Agroindustrial sector, dedicated to the expo Deadline: 2026-09-30 09:45:00.000000 |
|||||||
| Ransomware | COSEF - Consorzio di Sviluppo Economico del Friuli View Details _ | Booba Project | 23/09/2026 | IT | IT | pending | |
|
Facilities Services Stolen data: 200 GB. |
|||||||
| Ransomware | The Merrimack County View Details _ | Booba Project | 23/09/2026 | US | Public Sector | pending | |
|
Government Administration Stolen data: 3 GB. |
|||||||
| Ransomware | Smart Eye Care View Details _ | Booba Project | 23/09/2026 | Healthcare / Pharma | pending | ||
|
Optometrists Stolen data: 7 GB. |
|||||||
| Ransomware | Washington County View Details _ | Booba Project | 23/09/2026 | US | Services | pending | |
|
Government Administration Stolen data: 2 GB. |
|||||||
| Ransomware | RECEITA FEDERAL DO BRASIL View Details _ | emperador | 23/09/2026 | BR | Public Sector | pending | |
|
MINISTÉRIO DA FAZENDA SECRETARIA DA RECEITA FEDERAL DO BRASIL The archives contain several thousand documents with personnel and customer data, as well as all user date on gov.br with passwords. [Sector: Finance] |
|||||||
| Ransomware | Aokkef View Details _ | medusalocker | 23/09/2026 | FR | Services | pending | |
|
Organization with 137 emails extracted. Domain: aokkef.fr |
|||||||
| Ransomware | Seznam View Details _ | medusalocker | 23/09/2026 | CZ | Retail / E-commerce | pending | |
|
Organization with 115 emails extracted. Domain: seznam.cz |
|||||||
| Ransomware | Abv View Details _ | medusalocker | 23/09/2026 | BG | Manufacturing / Engineering | pending | |
|
Organization with 583 emails extracted. Domain: abv.bg | Sofia, Bulgaria |
|||||||
| Ransomware | W... B... View Details _ | SilentRansomGroup | 23/09/2026 | — | pending | ||
|
Redacted entry - full company name pending disclosure (FULL DATA TIMER active). |
|||||||
| Stealers | Acolyte Bases.rar View Details _ | LogsPlanet | 23/09/2026 | — | leaked | ||
|
📭 BUY PRIVATE — ADMIN: @BuzzLogsPlanet ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🔑Pass: [Telegram link: professional/enterprise only] ➖➖➖➖➖➖➖➖➖➖➖➖➖➖➖ 🤑 Main Channel || Reserve Channel 🤑 |
|||||||
| Breaches | Croatia.txt View Details _ | Database World ROC | 23/09/2026 | HR | — | leaked | |
|
📂 Croatia.txt |
|||||||
| Breaches | b1nd.net_Croatia.zip View Details _ | Database World ROC | 23/09/2026 | HR | — | leaked | |
| Breaches | b1nd.net_Croatia.zip View Details _ | Database World ROC | 23/09/2026 | HR | — | leaked | |
| Breaches | 5K Binanace.xlsx View Details _ | Database World ROC | 23/09/2026 | — | leaked | ||
| Breaches | 545454552.xlsx View Details _ | Базы Директоров / ЛПР / | 23/09/2026 | — | leaked | ||
|
База оптовых компаний с положительной чистой прибылью за 25 год. По аналитике зафиксировано - падение чистой прибыли 25/24 год. Есть номер телефона, почта, сайт. Под запрос найдем контакты ЛПР. Связь: Telegram ВКонтакте +79397886929 Яндекс.Мессенджер Отзывы |
|||||||
| Breaches | 73M-Airtel.7z.001 View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 73M-Airtel.7z.002 View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
|
TrueCaller India (Airtel Sub Segment) Date: 2019 Records: 73,000,000 Contains: Phone Number, Carrier, Name, Address, Gender, Job Title, Company Bame, Email, Facebook, Twitter |
|||||||
| Breaches | 249k-Sistema_Shyam.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 404k-Telenor.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 422k-Unitech_Wireless.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 4M-Telewings.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 767k-MTNL.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 9M-Aircel.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 13M-Tata_Docomo.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 19M-BSNL_Mobile.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | 50M-Vodafone.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
|
Truecaller (India) |
|||||||
| Breaches | 53M-Reliance_Jio.csv View Details _ | B F R e p o V 3 F i l e s | 23/09/2026 | — | leaked | ||
| Breaches | Реестр Адвокатов Украины @clubs404.csv View Details _ | F1bases | 23/09/2026 | — | leaked | ||
|
парсинг Реестра Адвокатов Украины. В архиве 65 246 записей. Формат данных: name,translit_name,region,city,photo,phones,emails,addresses,activity,chamber,registry_number,registry_date,reviews_count Дата: 23.09.26. |
|||||||
| Breaches | DUMP ULP 23.09.2026 Base34 1.txt View Details _ | Database World ROC | 23/09/2026 | — | leaked | ||
| Breaches | DUMP ULP 23.09.2026 Base34 2.txt View Details _ | Database World ROC | 23/09/2026 | — | leaked | ||
| Breaches | modx_ms2_order_addresses.sql View Details _ | ⚡️𝙎𝙏𝙊𝙍𝙈 Чат | База Данных | 23/09/2026 | — | leaked | ||
| Breaches | modx_users.sql View Details _ | ⚡️𝙎𝙏𝙊𝙍𝙈 Чат | База Данных | 23/09/2026 | — | leaked | ||
|
bazatactical[.]ru ✔️ |
|||||||
| Ransomware | Clark Hill View Details _ | SilentRansomGroup | 22/09/2026 | US | Finance / Legal / Insurance | leaked | |
|
[AI generated] Clark Hill (Clark Hill PLC) is a full-service law firm headquartered in Detroit, Michigan, United States. It operates in the legal services industry, providing counsel across practice areas including corporate law, litigation, labor and employment, intellectual property, cybersecurity, government relations, and healthcare law. The firm serves businesses, governments, and individuals through multiple offices across the United States and internationally. |
|||||||
| Ransomware | Fresenius Medical Care View Details _ | shinyhunters | 22/09/2026 | DE | Healthcare / Pharma | pending | |
|
You have exactly two days to contact us to prevent publication of all your data containing sensitive information. Deadline: Sep 25, 2026 | Updated: 23 Sep 2026 |
|||||||
| Ransomware | Gaedke & Partner Steuerberatung View Details _ | anubis | 22/09/2026 | DE | Finance / Legal / Insurance | pending | |
|
Data breach exposes accounting firm's client data. |
|||||||
| Ransomware | Grupo Hospifar S.R.L. View Details _ | titan | 22/09/2026 | AR | Healthcare / Pharma | pending | |
|
[AI generated] N/A |
|||||||
| Ransomware | Sherman Chan, DDS, Inc. View Details _ | titan | 22/09/2026 | Healthcare / Pharma | pending | ||
|
[AI generated] N/A |
|||||||
| Ransomware | B... View Details _ | SilentRansomGroup | 22/09/2026 | — | leaked | ||
|
Redacted entry - full company name pending disclosure (FULL DATA TIMER active). |
|||||||
| Ransomware | Cozen O'Connor View Details _ | SilentRansomGroup | 22/09/2026 | US | Services | leaked | |
|
[AI generated] Cozen O'Connor is an American full-service law firm headquartered in Philadelphia, Pennsylvania. Founded in 1970, it operates in the legal services industry, providing counsel across practice areas including litigation, corporate law, insurance, real estate, labor and employment, cybersecurity, and government relations. The firm serves clients across the United States and internationally, with offices throughout the U.S. and abroad. |
|||||||
| Ransomware | W... View Details _ | SilentRansomGroup | 22/09/2026 | — | leaked | ||
|
Redacted entry - full company name pending disclosure (FULL DATA TIMER active). |
|||||||
| Ransomware | PSA - READ THIS NOW View Details _ | shinyhunters | 22/09/2026 | Other | leaked | ||
|
Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI, During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended. We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to "disrupt" our operations, an effort that ultimately proved unsuccessful. For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that. Our PSA today works to address these allegations and correct them. We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more. We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations: - "Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims. " - "To exert pressure on victims[1], SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting" - " Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist." We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that. We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats. We wish to state unequivocally we have NEVER claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. WE ARE NOT SEXTORTIONISTS . Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of "The Com". We have NEVER been apart of "The Com". "The Com" is a propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense. As a big believer and supporter of the U.S. Constitution - we are exercising the First Amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated. We recognise that certain statements within your FLASH report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organisation in an attempt to "disrupt" our operations and hinder clients trust in our organisation hoping nobody pays us. Should those certain journalists and you know very well who you are, continue these unwarranted attacks and defamatory statements, we will be forced to respond in a civil manner with a commensurate and forceful defence of our reputation. As any human being would do. We welcome any and all journalists to inquire us at [email protected] to hear our side of the story. Make the right decision, don't be the next headline. Thank you for your attention to this matter. -SH | Updated: 23 Sep 2026 |
|||||||
| Ransomware | AFRICA-TECH (IT services / document processing) View Details _ | N0n | 22/09/2026 | ML | IT | pending | |
|
IT services / document services · Mali | Client documents: scans, attestations, insurance and embassy files, shared business folders | Operations are fully stopped. Nothing restores without settlement — all backups and shadow copies are encrypted or destroyed. | [ACTIVE: deadline 2026-09-25 16:00 UTC] |
|||||||
| Ransomware | universalautogroup.com View Details _ | settra | 22/09/2026 | US | Retail / E-commerce | pending | |
|
Universal Auto Group PROLOGUE We obtained thousands of documents belonging to two Washington State c... |
|||||||
| Ransomware | namtheun2.com View Details _ | settra | 22/09/2026 | LA | — | pending | |
|
Nam Theun 2: 1.2 TB of Files That Were Never Meant to Leave PROLOGUE VAT declaration №V262120000733,... |
|||||||
| Ransomware | lakebeverage.com View Details _ | settra | 22/09/2026 | US | Hospitality / Food & Beverage / Tourism | pending | |
|
A Beer Distributor and Its 165 Gigabytes Rochester, New York · WSLR #63124 · September 2026 Prologue... |
|||||||
| Ransomware | quantummarketing-group.com View Details _ | settra | 22/09/2026 | DE | Services | pending | |
|
The Cold Call Quantum Technology Marketing Group Limited · Reading, UK Prologue. What's Inside We ha... |
|||||||
| Ransomware | moscone.com View Details _ | settra | 22/09/2026 | US | Services | pending | |
|
"We Create Unforgettable Experiences." What ASM Global Hides Backstage at Moscone Center PROLOGUE: O... |
|||||||
| Ransomware | gregjoneslaw.com View Details _ | settra | 22/09/2026 | US | Finance / Legal / Insurance | pending | |
|
Documents: Greg Jones & Associates, P.A. PROLOGUE An anonymous $250,000 loan from "Skeeter" on t... |
|||||||
| Ransomware | Krapf Group View Details _ | kairos | 22/09/2026 | US | Manufacturing / Engineering | pending | |
|
Founded in 1942 and headquartered in West Chester, Pennsylvania, Krapf Group is a family-owned and operated transportation business. Operates a fleet of more than 2,500 school buses and commercial vehicles with over 3,500 employees. The data also contains personal information about thousands of bus drivers. |
|||||||
| Ransomware | Tulare Western High School View Details _ | Booba Project | 22/09/2026 | US | Public Sector | pending | |
|
Education Administration Programs Stolen data: 35 GB. |
|||||||