ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen30▲6156401401activeno public figure
2qilin21▲7115359359activeno public figure
3krybit13▲12479696activeno public figure
4storm4▼36445656activeno public figure
5akira9▲3418383activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
6direwolf3▼8416262activeno public figure
7inc ransom6▲239109109activeno public figure
8coinbase cartel0=375656activeno public figure
9lockbit55▼2275353activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10audit team11▲2232525activeno public figure
11safepay10=226767activeno public figure
12leakeddata0▼4203838activeno public figure
13orova0=194444activeno public figure
14zawoo0=191919activeno public figure
15emperador4▼1172121activeno public figure
16kazu0▼17171717activeno public figure
17vexy4▼5151515activeno public figure
18shinyhunters1▼2143131activeno public figure
19panzer7▲4142525activeno public figure
20black nevas1▼12141414activeno public figure
21dragonforce3▲1127171activeno public figure
22chaos4▲2123434activeno public figure
23everest0▼4123434activeno public figure
24pear1=122323activeno public figure
25rhysida3▲1121414activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Leak-site victims31 records · full details

VictimGroup / typeDiscoveredDetails
Kimberly-Clark
tracker page ↗
shinyhuntersfilter this group · 3d agoThis is a final warning to reach out by 16 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
State of Florida DMV
tracker page ↗
shinyhuntersfilter this group · 9d agoContact us, you know how. or we will release the files. View download button below for proof (samples). Deadline : 9 11 2026
Medela.com
tracker page ↗
shinyhuntersfilter this group · 10d agoThis is a final warning to reach out by 08 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Note to mr. databroker1 NEXUS DL Service
tracker page ↗
shinyhuntersfilter this group · 12d agoWe've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think you will appreciate the numbers we have to offer you in return for the data you possess. What we are willing to offer you can be considered a payment as large as what you would get paid in a ransom. Reply to the DMs we are sending you on forum or simply contact [email protected]
Neogen Corporation
tracker page ↗
shinyhuntersfilter this group · 18d agoThis is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
McKesson Corporation
tracker page ↗
shinyhuntersfilter this group · 19d agoHundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Elekta AB
tracker page ↗
shinyhuntersfilter this group · 19d agoThis is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Jack Henry & Associates
tracker page ↗
shinyhuntersfilter this group · 19d agoThis is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
CyrusOne, LLC.
tracker page ↗
shinyhuntersfilter this group · 24d agoUpdate 23 Aug: We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records along with: Sharepoint: (369.6 GB Compressed / 645 GB Uncompressed) 288,729 Files, 60,513 Folders - More than 182,000 rows of Customer data Extracted from the "Contacts" Salesforce Object. - Over 8,300 Rows of Employee PII (Full Name, Email, Job Title, Phone Number, ect.) - Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs - Extensive physical key inventory logs, verification photos, and contractor Green Badge audits - Large collection of data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics - Full CERM (Critical Environment Reliability Management) process library - Physical and information security policy suite plus governance materials - Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages - Credential and access-control artifacts (including PasswordList.xlsx, Okta SSC Access lists, active badge reports, and multiple Data Center Access Control forms)This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
ReliaQuest, LLC
tracker page ↗
shinyhuntersfilter this group · 25d agoThis time the post is about you, not us. Let Mandiant report and advise on us accurately, go away. DISCLAIMER: This information is being provided "as is" for informational purposes only. We do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this post. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favour by us.
NovoCure Limited
tracker page ↗
shinyhuntersfilter this group · 25d agoThis is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
BOK Financial
tracker page ↗
shinyhuntersfilter this group · 25d agoThis is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Cyrus******
tracker page ↗
shinyhuntersfilter this group · 27d agoThis is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Logitech/ Streamlabs
tracker page ↗
shinyhuntersfilter this group · 29d agoThis is a final warning to reach out by 21 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Brinks Home
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026Over 4.9 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Alcon, Inc.
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026Over 25 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Lumenis Ltd.
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026Over 1.1 million records containing some PII of customers/employees and 177GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Questel SAS
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Metabase
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026:P
Sharecare, Inc.
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to negotiate for you, that is on you. We will be publishing companies data who are negotiating with us, without a warning if negotiators continue to take us as misinformed individuals and BS us. Over 3.4 million Salesforce records containing some PII and 28GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
NOTICE OF WARNING
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026We are currently experiencing an influx of volume. More leaks are on their way. Kindly be informed, it is in your best interests to not stall and waste our time. Just pay and get it over with. We are on short temper and patience. We are the ones with the leverage, not you. Don't be naive. If you aren't with the program, go away. Your data will be published immediately and accordingly. SH
Carhartt, Inc.
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026Our demand for this Company was $3.3 million. The Company reached out. However, The Company did not try to negotiate. If The Company attempted to negotiate with us The Company would've ended up saving a good chunk of money. Instead they decided to do (see blow); this is also because The Company hired a very unskilled and incompetent negotiator. If The Company hired competency to negotiate for them, this post would've never been published. [21:24:22] carhartt: After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions. We appreciate your patience throughout this process. There is millions of customers of data involved here. As we always say, these companies don't care. Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Cook Medical LLC
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026Customer data, employee data, and other internal corporate data was compromised. The Company engaged with us but made several paltry offers, did not want to pay what we asked for and decided they are okay with the data leak to happen instead of increasing their offer by a little, then we'd likely have accepted and this post would not have gone up. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Baxter International, Inc.
tracker page ↗
shinyhuntersfilter this group · Aug 18, 2026Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
BH Security, LLC. (brinkshome.com)
tracker page ↗
shinyhuntersfilter this group · Jul 27, 2026Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
RingCentral, Inc.
tracker page ↗
shinyhuntersfilter this group · Jul 27, 2026Over XX of data was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Ernst & Young
tracker page ↗
shinyhuntersfilter this group · Jul 27, 2026Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files. This is a final warning to reach out by 31 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
[cdn] Notification
tracker page ↗
shinyhuntersfilter this group · Jul 25, 2026All CDN mirrors are currently experiencing a service disruption. All files are fully backed up and no data has been lost. At this time we do not have an estimated time of resolution.We are working to restore service promptly and will share updates as they become available.
Abbott owned Exact Sciences Corporation
tracker page ↗
shinyhuntersfilter this group · Jul 15, 2026You wouldn't want us to describe what was exfiltrated from you publicly. This is a final warning to reach out by 18 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Fluke Corporation
tracker page ↗
shinyhuntersfilter this group · Jul 6, 2026Over 21 million Salesforce records containing some PII were compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.
Ingram Content Group, Inc.
tracker page ↗
shinyhuntersfilter this group · Jul 6, 2026The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care.

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.