ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen32▲9157413413activeno public figure
2qilin18▲2115359359activeno public figure
3krybit13▲11479696activeno public figure
4direwolf5▼6456262activeno public figure
5storm44▲44445656activeno public figure
6akira7▼1388282activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
7coinbase cartel0=375656activeno public figure
8inc ransom3▼636106106activeno public figure
9lockbit55▼1278686activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10shinyhunters1▼2243434activeno public figure
11safepay14▲8227272activeno public figure
12leakeddata0▼7203838activeno public figure
13orova0=194444activeno public figure
14zawoo0=191919activeno public figure
15audit team10▲6181919activeno public figure
16panzer6▲3172424activeno public figure
17kazu0▼17171717activeno public figure
18emperador6▲5161919activeno public figure
19play4▲4144444activeno public figure
20vexy4▼6141414activeno public figure
21black nevas13▲13131313activeno public figure
22chaos5▲4123434activeno public figure
23everest0▼4123434activeno public figure
24pear1▼1122727activeno public figure
25rhysida3▲1121515activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Breaches2 records · full details

VictimBreach dateAdded to HIBPAccountsData exposedDescription
chess.com
breach
2026-08-03 · 2d ago4.7MEmail addresses, Geographic locations, Names, UsernamesIn August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.
mckesson.com
breachsensitive
2026-08-21 · 5d ago6.4MDates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addressesIn August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.