ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen32▲9157413413activeno public figure
2qilin18▲2115359359activeno public figure
3krybit13▲11479696activeno public figure
4direwolf5▼6456262activeno public figure
5storm44▲44445656activeno public figure
6akira7▼1388282activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
7coinbase cartel0=375656activeno public figure
8inc ransom3▼636106106activeno public figure
9lockbit55▼1278686activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10shinyhunters1▼2243434activeno public figure
11safepay14▲8227272activeno public figure
12leakeddata0▼7203838activeno public figure
13orova0=194444activeno public figure
14zawoo0=191919activeno public figure
15audit team10▲6181919activeno public figure
16panzer6▲3172424activeno public figure
17kazu0▼17171717activeno public figure
18emperador6▲5161919activeno public figure
19play4▲4144444activeno public figure
20vexy4▼6141414activeno public figure
21black nevas13▲13131313activeno public figure
22chaos5▲4123434activeno public figure
23everest0▼4123434activeno public figure
24pear1▼1122727activeno public figure
25rhysida3▲1121515activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Incidents24 records · full details

VictimGroup / typeDiscoveredDetails
Kimberly-Clark
tracker page ↗
shinyhuntersfilter this group · 2d agoThis is a final warning to reach out by 16 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
State of Florida DMV
tracker page ↗
shinyhuntersfilter this group · 8d agoContact us, you know how. or we will release the files. View download button below for proof (samples). Deadline : 9 11 2026
Medela.com
tracker page ↗
shinyhuntersfilter this group · 8d agoThis is a final warning to reach out by 08 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Note to mr. databroker1 NEXUS DL Service
tracker page ↗
shinyhuntersfilter this group · 11d agoWe've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think you will appreciate the numbers we have to offer you in return for the data you possess. What we are willing to offer you can be considered a payment as large as what you would get paid in a ransom. Reply to the DMs we are sending you on forum or simply contact [email protected]
Neogen Corporation
tracker page ↗
shinyhuntersfilter this group · 16d agoThis is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
McKesson Corporation
tracker page ↗
shinyhuntersfilter this group · 17d agoHundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Elekta AB
tracker page ↗
shinyhuntersfilter this group · 17d agoThis is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Jack Henry & Associates
tracker page ↗
shinyhuntersfilter this group · 17d agoThis is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
CyrusOne, LLC.
tracker page ↗
shinyhuntersfilter this group · 22d agoUpdate 23 Aug: We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records along with: Sharepoint: (369.6 GB Compressed / 645 GB Uncompressed) 288,729 Files, 60,513 Folders - More than 182,000 rows of Customer data Extracted from the "Contacts" Salesforce Object. - Over 8,300 Rows of Employee PII (Full Name, Email, Job Title, Phone Number, ect.) - Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs - Extensive physical key inventory logs, verification photos, and contractor Green Badge audits - Large collection of data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics - Full CERM (Critical Environment Reliability Management) process library - Physical and information security policy suite plus governance materials - Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages - Credential and access-control artifacts (including PasswordList.xlsx, Okta SSC Access lists, active badge reports, and multiple Data Center Access Control forms)This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
ReliaQuest, LLC
tracker page ↗
shinyhuntersfilter this group · 23d agoThis time the post is about you, not us. Let Mandiant report and advise on us accurately, go away. DISCLAIMER: This information is being provided "as is" for informational purposes only. We do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this post. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favour by us.
NovoCure Limited
tracker page ↗
shinyhuntersfilter this group · 24d agoThis is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
BOK Financial
tracker page ↗
shinyhuntersfilter this group · 24d agoThis is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Cyrus******
tracker page ↗
shinyhuntersfilter this group · 26d agoThis is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Logitech/ Streamlabs
tracker page ↗
shinyhuntersfilter this group · 28d agoThis is a final warning to reach out by 21 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Brinks Home
tracker page ↗
shinyhuntersfilter this group · 28d agoOver 4.9 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Alcon, Inc.
tracker page ↗
shinyhuntersfilter this group · 28d agoOver 25 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Lumenis Ltd.
tracker page ↗
shinyhuntersfilter this group · 28d agoOver 1.1 million records containing some PII of customers/employees and 177GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Questel SAS
tracker page ↗
shinyhuntersfilter this group · 28d agoOver 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Metabase
tracker page ↗
shinyhuntersfilter this group · 28d ago:P
Sharecare, Inc.
tracker page ↗
shinyhuntersfilter this group · 28d agoThis Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to negotiate for you, that is on you. We will be publishing companies data who are negotiating with us, without a warning if negotiators continue to take us as misinformed individuals and BS us. Over 3.4 million Salesforce records containing some PII and 28GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
NOTICE OF WARNING
tracker page ↗
shinyhuntersfilter this group · 28d agoWe are currently experiencing an influx of volume. More leaks are on their way. Kindly be informed, it is in your best interests to not stall and waste our time. Just pay and get it over with. We are on short temper and patience. We are the ones with the leverage, not you. Don't be naive. If you aren't with the program, go away. Your data will be published immediately and accordingly. SH
Carhartt, Inc.
tracker page ↗
shinyhuntersfilter this group · 28d agoOur demand for this Company was $3.3 million. The Company reached out. However, The Company did not try to negotiate. If The Company attempted to negotiate with us The Company would've ended up saving a good chunk of money. Instead they decided to do (see blow); this is also because The Company hired a very unskilled and incompetent negotiator. If The Company hired competency to negotiate for them, this post would've never been published. [21:24:22] carhartt: After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions. We appreciate your patience throughout this process. There is millions of customers of data involved here. As we always say, these companies don't care. Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Cook Medical LLC
tracker page ↗
shinyhuntersfilter this group · 28d agoCustomer data, employee data, and other internal corporate data was compromised. The Company engaged with us but made several paltry offers, did not want to pay what we asked for and decided they are okay with the data leak to happen instead of increasing their offer by a little, then we'd likely have accepted and this post would not have gone up. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Baxter International, Inc.
tracker page ↗
shinyhuntersfilter this group · 28d agoOver 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.