Ransomware & Leaks Attacks Map (last 7 days)
Ransomware Attacks Today
All Attacks in Last 30 Days
All Data
Data registered since November 2013.
| Classification | Target Identity | Source / Actor | Discovered | Location | Business Category | Intel Link |
|---|---|---|---|---|---|---|
| Ransomware | DECK APP TECHNOLOGIES PTE. LTD View Details _ | unsafe | 10/08/2026 | IN | IT | |
|
Deck.in is an Indian company operating in the IT sector, providing various services. The company is based in India and offers its services to clients. Deck.in was listed as a ransomware victim associated with unsafe |
||||||
| Ransomware | PharmaEssentia View Details _ | thegentlemen | 10/08/2026 | TW | Healthcare / Pharma | |
|
PharmaEssentia is a Taiwan-based company operating in the healthcare and pharmaceutical sector, offering various products and services. The company is involved in the development and manufacturing of pharmaceuticals. PharmaEssentia was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | CONTAC Ingenieros View Details _ | thegentlemen | 10/08/2026 | CL | IT | |
|
contac.cl is an IT company based in Chile, providing various IT services. As an entity in the IT sector, contac.cl operates in the technology industry, catering to clients in Chile. contac.cl was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | RAK Construction View Details _ | thegentlemen | 10/08/2026 | IN | Construction / Real Estate | |
|
Rak Construction is a construction and real estate company based in India, offering various services in the sector. The company operates in the Indian market, providing construction and real estate solutions. Rakconstruction.in was listed as a ransomware victim associated with thegentlemen. |
||||||
| Ransomware | Lancesoft India View Details _ | thegentlemen | 10/08/2026 | IN | IT | |
|
Lancesoft.in is an Indian IT company, operating in the information technology sector. The company is based in India and provides various IT services. Lancesoft.in was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | AIMS Group View Details _ | thegentlemen | 10/08/2026 | GB | IT | |
|
Aimsgroup.com is an IT company based in the United Kingdom, providing various IT services. The company operates in the IT sector, offering services to clients in GB. Aimsgroup.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | AnMed View Details _ | thegentlemen | 10/08/2026 | US | Healthcare / Medicine | |
|
AnMed Health is a healthcare organization based in the United States, providing medical services to patients. The organization operates in the healthcare sector, offering various medical treatments and care. AnMed Health was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | NTU Alumni Club View Details _ | thegentlemen | 10/08/2026 | SG | NGOs / Associations | |
|
ntualumni.org.sg is a website of the Nanyang Technological University Alumni Association in Singapore, providing services and resources to its members. As an association, it aims to foster a sense of community among its alumni. ntualumni.org.sg was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Canopy Support Services View Details _ | thegentlemen | 10/08/2026 | CA | Healthcare / Medicine | |
|
canopysupport.ca is a Canadian entity operating in the healthcare and medicine sector, providing support services. Located in Canada, the company offers various services to healthcare providers. canopysupport.ca was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Mikel Coffee View Details _ | thegentlemen | 10/08/2026 | MX | Retail / E-commerce | |
|
Mikelcoffee.com is an e-commerce company based in Mexico, operating in the retail sector. The company likely offers various products for sale online, catering to customers in Mexico and possibly other countries. Mikelcoffee.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Hong Kong Baptist University View Details _ | thegentlemen | 10/08/2026 | HK | Education | |
|
Hong Kong Baptist University, located in Hong Kong, is a public university that offers a range of academic programs. The university is part of the education sector in Hong Kong, providing various undergraduate and postgraduate degree programs. It was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Eva Care View Details _ | thegentlemen | 10/08/2026 | GB | Healthcare / Pharma | |
|
Evacare.com operates in the healthcare and pharmaceutical sector, providing services in the United Kingdom. As a healthcare entity, evacare.com is likely involved in medical care and pharmaceutical services. Evacare.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Premier Pigs View Details _ | thegentlemen | 10/08/2026 | GB | Agriculture / Food | |
|
Premierpigs.com operates in the agriculture and food sector in the United Kingdom, providing services related to pig farming. As a company in this sector, premierpigs.com is involved in activities such as pig breeding, farming, and possibly related food production. Premierpigs.com was listed as a ransomware victim associated with thegentlemen |
||||||
| Ransomware | Zion Contracting View Details _ | thegentlemen | 10/08/2026 | US | Construction / Real Estate | |
|
Zion Contracting is a construction and real estate company based in the United States, offering various services within the sector. The company operates within the construction and real estate industry, providing services to clients in the US. Zion Contracting was listed as a ransomware victim associated with thegentlemen. |
||||||
| Breaches | ULP-@LegioN_LeakeR_pLifxs.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_ppOdKW.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_QkCBNQ.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_QSlqBY.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_RNOhLe.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_solAPy.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_TeGTzU.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_tufItn.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_tXJqcT.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | ULP-@LegioN_LeakeR_uXjHzL.txt View Details _ | F1bases | 10/08/2026 | — | ||
|
🔥🔥🔥🔥🔥🔥🔥🔥 💎 Buy VIP channel👑 @Hajit00n - @LegioN_LeakeRs |
||||||
| Breaches | chunk_743.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_741.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_740.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_754.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_752.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_750.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_751.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_749.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_75.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_748.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_747.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_746.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_744.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_742.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | chunk_745.csv View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | 435634634.xlsx View Details _ | Базы Директоров / ЛПР / | 10/08/2026 | — | ||
| Breaches | Dubsmash @BreachedData.7z.001 View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | Dubsmash @BreachedData.7z.002 View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | Dubsmash @BreachedData.7z.003 View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | Dubsmash @BreachedData.7z.004 View Details _ | Database World ROC | 10/08/2026 | — | ||
| Breaches | Joyalukkas.7z View Details _ | Database World ROC | 10/08/2026 | — | ||
|
https://www.joyalukkas.com/ae/ |
||||||
| Ransomware | MIE Solutions View Details _ | play | 09/08/2026 | GB | Manufacturing / Engineering | |
|
United States |
||||||
| Ransomware | Rilpa Enterprises View Details _ | play | 09/08/2026 | IT | ||
|
Canada |
||||||
| Ransomware | Marconi Industrial Services View Details _ | play | 09/08/2026 | IT | Manufacturing / Engineering | |
|
Italy |
||||||
| Ransomware | Synergy Interactive View Details _ | qilin | 09/08/2026 | US | IT | |
|
N/A |
||||||
| Ransomware | Energetic Development Corp View Details _ | qilin | 09/08/2026 | TW | Manufacturing / Engineering | |
|
N/A |
||||||
| Ransomware | Panda Logistics Taichung Branch View Details _ | qilin | 09/08/2026 | TW | IT | |
|
N/A |
||||||
| Ransomware | East Field Corporation View Details _ | qilin | 09/08/2026 | JP | Manufacturing / Engineering | |
|
N/A |
||||||
| Ransomware | Chun Tai Sing Chemical Industry View Details _ | qilin | 09/08/2026 | HK | Other | |
|
N/A |
||||||
| Ransomware | pm-energy Die Solarexperten View Details _ | qilin | 09/08/2026 | DE | Energy | |
|
N/A |
||||||
| Ransomware | Constellation HomeBuilder Systems View Details _ | unsafe | 09/08/2026 | US | Construction / Real Estate | |
|
Revenue: $138.1M |
||||||
| Ransomware | Harplast SRL View Details _ | qilin | 09/08/2026 | RO | Manufacturing / Engineering | |
|
N/A |
||||||
| Ransomware | Price Shoes View Details _ | qilin | 09/08/2026 | MX | Retail / E-commerce | |
|
N/A |
||||||
| Ransomware | Naval Interior Team View Details _ | qilin | 09/08/2026 | FI | IT | |
|
N/A |
||||||
| Ransomware | Phithan Phanich View Details _ | qilin | 09/08/2026 | TH | Retail / E-commerce | |
|
N/A |
||||||
| Ransomware | Grupo Diestra View Details _ | qilin | 09/08/2026 | PE | Transportation / Travel / Logistics | |
|
N/A |
||||||
| Ransomware | Université Libre de Bruxelles View Details _ | qilin | 09/08/2026 | BE | Education | |
|
N/A |
||||||
| Ransomware | Ali** ********** View Details _ | shinyhunters | 09/08/2026 | Retail / E-commerce | ||
|
August 7, 2026 3:00 PM ET: Over 11.5 million records across Salesforce, ServiceNow, and Entra containing some PII of customers and employees and 3.1TB+ of internal corporate data was compromised. This is a final warning to reach out by 10 August 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 08 August 2026 | Warning: FINAL WARNING PAY OR LEAK |
||||||
| Ransomware | Lucidmotors View Details _ | Sovcali | 09/08/2026 | US | Manufacturing / Engineering | |
|
Lucid Motors & eShocan Engineering Archive in Our Possession. The complete engineering archive of Lucid Motors and eShocan is now available: 5.078 terabytes of CATIA and STEP models, FEA and NVH analyses, multi-gigabyte CFD simulations of the LiDAR washing system, topology optimization studies, static and modal results for the Gravity and Midsize enclosures, BOMs, and internal progress reports. |
||||||
| Ransomware | Service d'usinage 9002 View Details _ | qilin | 09/08/2026 | CA | Manufacturing / Engineering | |
|
N/A |
||||||
| Ransomware | studiotibaldi.it View Details _ | krybit | 09/08/2026 | IT | IT | |
|
Studio Associato Tibaldi is an Italian professional firm based in Rome, founded over 40 years ago, specializing in condo... |
||||||
| Ransomware | Siam Oil Product View Details _ | Panzer | 09/08/2026 | TH | Energy | |
|
Siam Oil Product Co., Ltd. is a Thailand-based petroleum and industrial-products distributor, operating for 20+ years with registered capital of THB 200 million and 700+ employees; it supplies fuel oil, diesel, asphalt, base oils, automotive/industrial lubricants, petrochemicals such as HDPE/LDPE/LLDPE, plastic additives, and industrial products, and also operates a coffee-shop franchise business. Its headquarters is at RS Tower, Ratchadaphisek Road, Din Daeng, Bangkok, Thailand. |
||||||
| Breaches | TruistBank_BF.7z View Details _ | Database World ROC | 09/08/2026 | — | ||
|
In October 2023, the Truist Bank, a leading U.S. commercial bank were breached in an cyberattack and in June 2024, the data was published on BreachForums by @ShinyHunters .The exposed data included over 79k employees unique emails (Work emails) and account balances, dates of birth, job titles, names, partial credit card data and phone numbers. The ShinyHunters themselves commented about this leak - "There is nothing less true than the promises of CrowdShart and in the case of truist the truest words to be said on this subject are when #l0ckb1tch3z! troops taking point on zscaler its #G4M30V3R for them." |
||||||
| Breaches | shouldve_paid_the_ransom_icsecurity.com_shinyhunters.7z.001 View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_icsecurity.com_shinyhunters.7z.002 View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_icsecurity.com_shinyhunters.7z.003 View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | microsoft.7z View Details _ | Database World ROC | 09/08/2026 | — | ||
|
8M~ records containing: significant PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions. Size: 130GB |
||||||
| Breaches | your_negotiators_fault_alert360_shinyhunters_.7z.001 View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | your_negotiators_fault_alert360_shinyhunters_.7z.002 View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | your_negotiators_fault_alert360_shinyhunters_.7z.003 View Details _ | Database World ROC | 09/08/2026 | — | ||
|
Alert 360 Opco Inc. Over 2.5M records containing PII and other internal corporate data have been compromised. 10GB+ (compressed) |
||||||
| Breaches | shouldve_paid_the_ransom_pathstone.com_shinyhunters_.7z.001 View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_pathstone.com_shinyhunters_.7z.002 View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_pathstone.com_shinyhunters_.7z.003 View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_pathstone.com_shinyhunters_.7z.004 View Details _ | Database World ROC | 09/08/2026 | — | ||
|
Salesforce records were compromised and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care about their clients nor investors. 15GB (compressed) |
||||||
| Breaches | BouyguesTelecom_BF.7z View Details _ | Database World ROC | 09/08/2026 | — | ||
|
In August 2025, the French telecommunications company Bouygues Telecom detected a cyber attack against their services. The incident resulted in a data breach that exposed almost 6.4M customer records, including 5.7M unique email addresses. The breach also exposed names, physical addresses, phone numbers, dates of birth and IBANs (International Bank Account Numbers). Bouygues Telecom advised that all affected customers had been notified about the incident. |
||||||
| Breaches | Bank of America.txt View Details _ | Database World ROC | 09/08/2026 | — | ||
| Breaches | JAPANPHONE1.7z View Details _ | Database World ROC | 09/08/2026 | JP | — | |
|
1 Million Database Phone Number Japan with Provider Records: ~1.1M |
||||||
| Breaches | sermilweb.eb.mil.br_brazil.7z View Details _ | Database World ROC | 09/08/2026 | BR | — | |
|
Data from the Brazilian Army's SERMIL military conscription portal (sermilweb.eb.mil.br), ~50 million records leaked in October 2025. Fields include full name, full home address, date of birth, CPF, gender, education, father's and mother's names, phone number, email, country and place of birth, army rank and blood type. |
||||||
| Breaches | ColisPrivé_BF.7z View Details _ | Database World ROC | 09/08/2026 | — | ||
|
Colis Privé, a French shipping and delivery company, had its customer data scraped in November 2025 and subsequently leaked, exposing over 22 million customer records (a reply cites 22,564,381 records, noting duplicate entries for the same people). The data contained more than 12 million unique email addresses along with names, parcel numbers, phone numbers, and physical addresses. |
||||||
| Breaches | MonLogicielMédical_BF.7z View Details _ | Database World ROC | 09/08/2026 | — | ||
|
Mon Logiciel Médical, a SaaS-based medical software platform tied to Ameli (France's national health insurance system), had patient data scraped around 2025. Over 19 million patient rows were obtained, including more than 150 thousand unique email addresses, dates of birth, genders, names, phone numbers, and physical addresses. |
||||||
| Breaches | EasyCash_BF.7z View Details _ | Database World ROC | 09/08/2026 | — | ||
|
Easy Cash (France) Easy Cash, a French second-hand goods retailer, suffered a data breach in April 2025 that exposed over 14.6 million rows covering roughly 4.8 million clients. Replies note the file actually contains only around 5,000-5,500 unique email addresses, alongside clients, dates of birth and names. |
||||||
| Breaches | RevoraForums_BF.7z View Details _ | Database World ROC | 09/08/2026 | — | ||
|
Revora (forums.revora.net), a gaming forum, suffered a data breach that was publicly exposed in February 2025, affecting over 1.2 million users. Exposed data included email addresses, IP addresses, usernames, and passwords stored as vBulletin hashes |
||||||
| Ransomware | Daily Trust View Details _ | Panzer | 08/08/2026 | NG | Communication / Marketing | |
|
Daily Trust is a Nigerian news organization that provides breaking news, investigative stories, and various features across multiple sectors including business, politics, sports, and entertainment. The company offers content through print, online platforms, and media outlets like Trust TV and Trust Radio. Its services cater primarily to the Nigerian public, with a focus on providing comprehensive coverage of local and international news. Daily Trust aims to inform and engage its audience through a diverse range of storytelling and analysis. |
||||||
| Ransomware | Impact Centre Chrétien View Details _ | qilin | 08/08/2026 | FR | NGOs / Associations | |
|
N/A |
||||||
| Ransomware | Louisville Bar Association View Details _ | incransom | 08/08/2026 | US | NGOs / Associations | |
|
The Louisville Bar Association (LBA) provides a range of services including membership benefits, legal job placement, continuing legal education (CLE), and public service initiatives. It aims to support legal professionals at all stages of their careers while promoting diversity and community engagement within the legal field. The LBA also offers resources for individuals seeking legal representation and hosts various events and awards to recognize outstanding contributions in the legal community. Their intended clients include legal professionals, law firms, and individuals in need of legal assistance in the Louisville area. |
||||||
| Ransomware | Clausing View Details _ | qilin | 08/08/2026 | DE | Construction / Real Estate | |
|
N/A |
||||||
| Ransomware | CLLS Co Ltd View Details _ | qilin | 08/08/2026 | SG | Education | |
|
N/A |
||||||
| Ransomware | Ingersoll Rand View Details _ | everest | 08/08/2026 | US | Manufacturing / Engineering | |
|
[AI generated] Ingersoll Rand is an American industrial manufacturing company headquartered in Davidson, North Carolina. It designs and produces a wide range of industrial equipment including air compressors, power tools, fluid management systems, and HVAC solutions. The company serves diverse sectors such as manufacturing, construction, and energy. Formerly part of a larger conglomerate, it operates globally across multiple countries and markets. |
||||||
| Ransomware | Omnicell View Details _ | everest | 08/08/2026 | US | Healthcare / Pharma | |
|
[AI generated] Omnicell is a United States-based healthcare technology company founded in 1992 and headquartered in Austin, Texas. It specializes in medication management solutions, providing automated pharmacy systems, dispensing cabinets, and software platforms to hospitals, pharmacies, and healthcare facilities. Its products aim to improve medication safety, reduce errors, and streamline pharmacy workflows across the healthcare industry. |
||||||
| Ransomware | United Group of Companies View Details _ | Storm | 08/08/2026 | US | Other | |
|
Since 1972, The United Group of Companies, Inc. has specialized in all phases of real estate: development, financing, construction, and management. Their specialties include independent senior living, student apartment communities, multi-family (including affordable) housing, commercial properties, and mixed-use neighborhoods. The United Group of Companies is headquartered out of Troy, New York. The company headquarters is located in 300 Jordan Road, Troy, NY 12180, United States. 201-500 Employees |
||||||
| Ransomware | Sawyer Savings Bank View Details _ | Storm | 08/08/2026 | US | Finance / Legal / Insurance | |
|
Sawyer Savings Bank is a community-focused financial institution with over 150 years of experience, offering a range of personal and business banking services. Their products include personal checking, savings accounts, business loans, and digital banking solutions designed to enhance customer convenience and security. The bank is dedicated to supporting local communities through various initiatives, including scholarships and volunteerism. Their target clients include individuals seeking personal banking solutions and businesses looking for comprehensive banking support. The company headquarters is located in 87 Market Street, Saugerties, NY 12477, United States.11-50 Employees |
||||||
| Stealers | ТG - @WichLoveFromR.rar View Details _ | [Cloud] Wich Love From R | 08/08/2026 | — | ||
|
Subscribe to not lose us: CLICK 🔤🔤🔤🔤 🔤🔤🔤🔤🔤 pаss: t.me/WichLoveFromR Рrivate 🟡 Dоwnlоаd раck 🟡 Аdmin |
||||||
| Breaches | users.7z View Details _ | Database World ROC | 08/08/2026 | — | ||
|
jamendo.com scrape Date: 2026 Records: ~6,5M |
||||||
| Breaches | shouldve-paid-the-ransom-SYSCO-SHINYHUNTERS.zip View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Sysco Corporation Over 61 million Salesforce records across several tables, some containing customer data/PII, employee data, and other internal corporate data was compromised. |
||||||
| Breaches | moody.edu.tar.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | moody.edu.tar.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
moody.edu Over 23 gigabytes of Moody Bible Institute data (1,300+ files, tens of millions of records) was compromised across enrollment, donor relations, payroll, and communications systems (MBI, EDC/Salesforce leads, PeopleSoft PS_COMMUNICATION, Horizon SIS, WHPD donor database, and Cadence admissions), including 46 million communication records, 2.2 million enrollment lead records, 108,000 biodemographic master files with addresses and birthdates, 3.3 gigabytes of donor gift data, employee payroll XML with home addresses and earnings, 1,100+ admissions outreach files, and student housing assignment records. |
||||||
| Breaches | marcusmillichap.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | marcusmillichap.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Marcus & Millichap, Inc. Lesk In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group. Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, along with names, phone numbers and employment-related information including employer, job title and physical company address. In their disclosure notice, Marcus & Millichap advised that data which may have been accessed appeared limited to "company forms, templates, marketing materials, and general contact information". |
||||||
| Breaches | shouldve_paid_the_ransom_UDEMY_SHINYHUNTERS.zip View Details _ | Database World ROC | 08/08/2026 | — | ||
|
In April 2026, online training company Udemy was the victim of a “pay or leak” extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical addresses, phone numbers, employer information and instructor payout methods including PayPal, cheque and bank transfer. |
||||||
| Breaches | shouldve_paid-the_ransom_aura-shinyhunters_.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid-the_ransom_aura-shinyhunters_.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid-the_ransom_aura-shinyhunters_.7z.003 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid-the_ransom_aura-shinyhunters_.7z.004 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Name: Aura Date: March 2026 Records: ~900k Description: In March 2026, the online safety service Aura disclosed a data breach that exposed 900k unique email addresses. The data was primarily associated with a marketing tool from a previously acquired company, with fewer than 20k active Aura customers affected. Exposed data included names, phone numbers, physical and IP addresses, and customer service notes. Aura advised that no Social Security numbers, passwords or financial information were compromised. |
||||||
| Breaches | DEFCON.sql View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Name: Fluke Date: July 2026 Records: ~800k Description: In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present. |
||||||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.003 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.004 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.005 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.006 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.007 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.008 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.009 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.010 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.011 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.012 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.013 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.014 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.015 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.016 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.017 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.018 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.019 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.020 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.021 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.022 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.023 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.024 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.025 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.026 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_fluke_shinyhunters.7z.027 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | watiqa.ma).7z View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Watiqa.ma – Moroccan Government Civil Documents Platform Date: May 2026 Format: csv Records: 695,402 |
||||||
| Breaches | crunchyroll.json View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Name: Crunchyroll [Fake] Date: March 2026 Records: ~6.8M Description: In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users. The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the contents of the support tickets" were exposed. A subset of 1.2M email addresses from an alleged 2M record dataset being sold was later provided to HIBP. |
||||||
| Breaches | lbp-tm.fr.jsonl View Details _ | Database World ROC | 08/08/2026 | FR | — | |
|
Name: LBP-TM.FR Date: January 2026 Records: 3,691,395 Sample: {"Civilite":"MME","Nom":"D ADDETTA","Prenom":"CORALIE","Adresse1":"8 RUE BLANQUI","Adresse2":"","Numero1":"","Numero2":"0668605356","Numero3":"0664991521","Mail":"[email protected]","Code_Postal":"13530","Ville":"Trets","Code_INSEE":"13110","Pays":"1","Prenom_Enfant":"Leo","Jour_Naissance_Enfant":"06","Mois_Naissance_Enfant":"09","Annee_Naissance_enfant":"2010"} |
||||||
| Breaches | trasmitenota.br.7z View Details _ | Database World ROC | 08/08/2026 | BR | — | |
|
app3.transmitenota.com.br Date: May 01, 2026 Records: 20,151,364 Format: SQL |
||||||
| Breaches | criminals_db.csv View Details _ | ⚡️𝙎𝙏𝙊𝙍𝙈 Чат | База Данных | 08/08/2026 | — | ||
| Breaches | criminals_db_fix.csv View Details _ | ⚡️𝙎𝙏𝙊𝙍𝙈 Чат | База Данных | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_ADT_SHINYHUNTERS_.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Name: ADT Size: 10.7 GB Records: 10M+ Description: This dataset is part of a leak concerning the Council of Europe, published by the ShinyHunters group on 18 June 2026 after ransom negotiations failed, following exploitation of an Oracle PeopleSoft zero-day (CVE-2026-35273). The full leak totals roughly 295GB across ~430,000 files and reportedly includes about 409,000 pay slips for over 10,000 current and former employees (2011-2026), CVs, internal HR documents, and banking and tax information. The compromised data content is particularly sensitive: • 409,000 pay slips from over 10,000 current and former employees, covering the period 2011-2026 • 14,000 CVs and 3,700 internal HR documents • Banking information including statements and account numbers • Tax and social security data • Medical records and absence/sickness reports • Performance evaluations and payroll exports • Names, IDs, addresses, phone numbers, and dates of birth of employees |
||||||
| Breaches | shouldve_paid_the_ransom_ADT_SHINYHUNTERS_.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_ADT_SHINYHUNTERS_.7z.003 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_bakerdist.7z View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Baker Distributing Company A leak from Baker Distributing Company, attributed to the ShinyHunters group and dated 4 June 2026. It reportedly comprises over 260,000 Salesforce CRM records along with corporate data taken from various SharePoint sites |
||||||
| Breaches | shouldve-paid-the-ransom-matchgroup-shinyhunters.7z View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
Nexstar.tv Over 1 million Salesforce records and other internal corporate data containing PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. 27GB+ (compressed) 1M+ Records File Size: 26.5 GB |
||||||
| Breaches | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.003 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.004 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.005 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.006 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.007 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | glendale.edu.tar.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
glendale.edu In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information". |
||||||
| Breaches | glendale.edu.tar.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | glendale.edu.tar.7z.003 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | glendale.edu.tar.7z.004 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | glendale.edu.tar.7z.005 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | glendale.edu.tar.7z.006 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | glendale.edu.tar.7z.007 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | glendale.edu.tar.7z.008 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | glendale.edu.tar.7z.009 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | 7Eleven-THEFALLEN.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | 7Eleven-THEFALLEN.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | 7Eleven-THEFALLEN.7z.003 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | 7Eleven-THEFALLEN.7z.004 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
7-Eleven, Inc. Over 600k Salesforce records containing PII and other internal corporate data have been compromised. Size: 10.4GB+ (compressed) Breach date: Apr 22 ,2026 |
||||||
| Breaches | ameriprise_sharepoint_.7z.001 View Details _ | Database World ROC | 08/08/2026 | — | ||
|
In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general, Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures". |
||||||
| Breaches | ameriprise_sharepoint_.7z.002 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.003 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.004 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.005 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.006 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.007 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.008 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.009 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.010 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.011 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.012 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.013 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.014 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.015 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.016 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.017 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.018 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.019 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.020 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.021 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.022 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.023 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.024 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.025 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.026 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.027 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.028 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.029 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.030 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.031 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.032 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.033 View Details _ | Database World ROC | 08/08/2026 | — | ||
| Breaches | ameriprise_sharepoint_.7z.034 View Details _ | Database World ROC | 08/08/2026 | — | ||