Incidents
Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups
Leak-site victims · 7d
232
Leak-site victims · 30d
1K
Active groups · 30d
778 new
Most active · 7d
storm
Breaches added · 30d
9
Accounts exposed · 30d
36.8MHIBP
Ransomware & extortion groups · activityleak-site posts · 90-day window · click a group for its profile
| # | Group | 7d | trend | 30d | 90d | all-time* | Last post | Status | Estimated earnings (public reporting) |
|---|---|---|---|---|---|---|---|---|---|
| 1 | the gentlemen | 32 | ▲9 | 157 | 413 | 413 | active | no public figure | |
| 2 | qilin | 18 | ▲2 | 115 | 359 | 359 | active | no public figure | |
| 3 | krybit | 13 | ▲11 | 47 | 96 | 96 | active | no public figure | |
| 4 | direwolf | 5 | ▼6 | 45 | 62 | 62 | active | no public figure | |
| 5 | storm | 44 | ▲44 | 44 | 56 | 56 | active | no public figure | |
| 6 | akira | 7 | ▼1 | 38 | 82 | 82 | active | Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. | |
| 7 | coinbase cartel | 0 | = | 37 | 56 | 56 | active | no public figure | |
| 8 | inc ransom | 3 | ▼6 | 36 | 106 | 106 | active | no public figure | |
| 9 | lockbit5 | 5 | ▼1 | 27 | 86 | 86 | active | Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… | |
| 10 | shinyhunters | 1 | ▼2 | 24 | 34 | 34 | active | no public figure | |
| 11 | safepay | 14 | ▲8 | 22 | 67 | 67 | active | no public figure | |
| 12 | leakeddata | 0 | ▼7 | 20 | 38 | 38 | active | no public figure | |
| 13 | orova | 0 | = | 19 | 44 | 44 | active | no public figure | |
| 14 | zawoo | 0 | = | 19 | 19 | 19 | active | no public figure | |
| 15 | audit team | 10 | ▲6 | 18 | 19 | 19 | active | no public figure | |
| 16 | panzer | 6 | ▲3 | 17 | 24 | 24 | active | no public figure | |
| 17 | kazu | 0 | ▼17 | 17 | 17 | 17 | active | no public figure | |
| 18 | emperador | 6 | ▲5 | 16 | 19 | 19 | active | no public figure | |
| 19 | play | 4 | ▲4 | 14 | 44 | 44 | active | no public figure | |
| 20 | vexy | 4 | ▼6 | 14 | 14 | 14 | active | no public figure | |
| 21 | black nevas | 13 | ▲13 | 13 | 13 | 13 | active | no public figure | |
| 22 | chaos | 5 | ▲4 | 12 | 34 | 34 | active | no public figure | |
| 23 | everest | 0 | ▼4 | 12 | 34 | 34 | active | no public figure | |
| 24 | pear | 1 | ▼1 | 12 | 27 | 27 | active | no public figure | |
| 25 | rhysida | 3 | ▲1 | 12 | 15 | 15 | active | no public figure |
*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.
Incidents34 records · full details
| Victim | Group / type | Discovered | Details |
|---|---|---|---|
Kimberly-Clark tracker page ↗ | shinyhuntersfilter this group | · 2d ago | This is a final warning to reach out by 16 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
State of Florida DMV tracker page ↗ | shinyhuntersfilter this group | · 8d ago | Contact us, you know how. or we will release the files. View download button below for proof (samples). Deadline : 9 11 2026 |
Medela.com tracker page ↗ | shinyhuntersfilter this group | · 8d ago | This is a final warning to reach out by 08 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Note to mr. databroker1 NEXUS DL Service tracker page ↗ | shinyhuntersfilter this group | · 11d ago | We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think you will appreciate the numbers we have to offer you in return for the data you possess. What we are willing to offer you can be considered a payment as large as what you would get paid in a ransom. Reply to the DMs we are sending you on forum or simply contact [email protected] |
Neogen Corporation tracker page ↗ | shinyhuntersfilter this group | · 16d ago | This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
McKesson Corporation tracker page ↗ | shinyhuntersfilter this group | · 17d ago | Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Elekta AB tracker page ↗ | shinyhuntersfilter this group | · 17d ago | This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Jack Henry & Associates tracker page ↗ | shinyhuntersfilter this group | · 17d ago | This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
CyrusOne, LLC. tracker page ↗ | shinyhuntersfilter this group | · 22d ago | Update 23 Aug: We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records along with: Sharepoint: (369.6 GB Compressed / 645 GB Uncompressed) 288,729 Files, 60,513 Folders - More than 182,000 rows of Customer data Extracted from the "Contacts" Salesforce Object. - Over 8,300 Rows of Employee PII (Full Name, Email, Job Title, Phone Number, ect.) - Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs - Extensive physical key inventory logs, verification photos, and contractor Green Badge audits - Large collection of data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics - Full CERM (Critical Environment Reliability Management) process library - Physical and information security policy suite plus governance materials - Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages - Credential and access-control artifacts (including PasswordList.xlsx, Okta SSC Access lists, active badge reports, and multiple Data Center Access Control forms)This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
ReliaQuest, LLC tracker page ↗ | shinyhuntersfilter this group | · 23d ago | This time the post is about you, not us. Let Mandiant report and advise on us accurately, go away. DISCLAIMER: This information is being provided "as is" for informational purposes only. We do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this post. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favour by us. |
NovoCure Limited tracker page ↗ | shinyhuntersfilter this group | · 24d ago | This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
BOK Financial tracker page ↗ | shinyhuntersfilter this group | · 24d ago | This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Cyrus****** tracker page ↗ | shinyhuntersfilter this group | · 26d ago | This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Logitech/ Streamlabs tracker page ↗ | shinyhuntersfilter this group | · 28d ago | This is a final warning to reach out by 21 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Brinks Home tracker page ↗ | shinyhuntersfilter this group | · 28d ago | Over 4.9 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
Alcon, Inc. tracker page ↗ | shinyhuntersfilter this group | · 28d ago | Over 25 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
Lumenis Ltd. tracker page ↗ | shinyhuntersfilter this group | · 28d ago | Over 1.1 million records containing some PII of customers/employees and 177GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
Questel SAS tracker page ↗ | shinyhuntersfilter this group | · 28d ago | Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
Metabase tracker page ↗ | shinyhuntersfilter this group | · 28d ago | :P |
Sharecare, Inc. tracker page ↗ | shinyhuntersfilter this group | · 28d ago | This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to negotiate for you, that is on you. We will be publishing companies data who are negotiating with us, without a warning if negotiators continue to take us as misinformed individuals and BS us. Over 3.4 million Salesforce records containing some PII and 28GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
NOTICE OF WARNING tracker page ↗ | shinyhuntersfilter this group | · 28d ago | We are currently experiencing an influx of volume. More leaks are on their way. Kindly be informed, it is in your best interests to not stall and waste our time. Just pay and get it over with. We are on short temper and patience. We are the ones with the leverage, not you. Don't be naive. If you aren't with the program, go away. Your data will be published immediately and accordingly. SH |
Carhartt, Inc. tracker page ↗ | shinyhuntersfilter this group | · 28d ago | Our demand for this Company was $3.3 million. The Company reached out. However, The Company did not try to negotiate. If The Company attempted to negotiate with us The Company would've ended up saving a good chunk of money. Instead they decided to do (see blow); this is also because The Company hired a very unskilled and incompetent negotiator. If The Company hired competency to negotiate for them, this post would've never been published. [21:24:22] carhartt: After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions. We appreciate your patience throughout this process. There is millions of customers of data involved here. As we always say, these companies don't care. Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
Cook Medical LLC tracker page ↗ | shinyhuntersfilter this group | · 28d ago | Customer data, employee data, and other internal corporate data was compromised. The Company engaged with us but made several paltry offers, did not want to pay what we asked for and decided they are okay with the data leak to happen instead of increasing their offer by a little, then we'd likely have accepted and this post would not have gone up. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
Baxter International, Inc. tracker page ↗ | shinyhuntersfilter this group | · 28d ago | Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
BH Security, LLC. (brinkshome.com) tracker page ↗ | shinyhuntersfilter this group | · Jul 27, 2026 | Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
RingCentral, Inc. tracker page ↗ | shinyhuntersfilter this group | · Jul 27, 2026 | Over XX of data was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Ernst & Young tracker page ↗ | shinyhuntersfilter this group | · Jul 27, 2026 | Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files. This is a final warning to reach out by 31 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
[cdn] Notification tracker page ↗ | shinyhuntersfilter this group | · Jul 25, 2026 | All CDN mirrors are currently experiencing a service disruption. All files are fully backed up and no data has been lost. At this time we do not have an estimated time of resolution.We are working to restore service promptly and will share updates as they become available. |
Abbott owned Exact Sciences Corporation tracker page ↗ | shinyhuntersfilter this group | · Jul 15, 2026 | You wouldn't want us to describe what was exfiltrated from you publicly. This is a final warning to reach out by 18 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Fluke Corporation tracker page ↗ | shinyhuntersfilter this group | · Jul 6, 2026 | Over 21 million Salesforce records containing some PII were compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
Ingram Content Group, Inc. tracker page ↗ | shinyhuntersfilter this group | · Jul 6, 2026 | The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
icsecurity.com tracker page ↗ | shinyhuntersfilter this group | · Jun 19, 2026 | Over 2.7 million records and other internal corporate data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Amazon owned OneMedical.com tracker page ↗ | shinyhuntersfilter this group | · Jun 18, 2026 | Over 8.8TB of data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
NAIC.org tracker page ↗ | shinyhuntersfilter this group | · Jun 18, 2026 | Over 3.1 terabytes of National Association of Insurance Commissioners data (105,000+ files) was compromised across the INSData statistical platform, Vision credit rating feeds, SERFF, OPTINS, UCAA, EDP, RDC, and state insurance department reporting systems (NAIC, all fifty state insurance departments, and thousands of licensed insurers), including 2.1 million insurer regulatory filing PDFs, 40,000 quarterly statistical CSVs with federal EINs and company data, 45,000+ licensed rating agency files from Moody's, Fitch, S&P, Kroll, DBRS, and AM Best with CUSIP and ISIN identifiers, statutory annual and quarterly financial statements, premium and loss statistics, and HR Ratings master data. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
Breach & ransomware newsAll →
Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.