Incidents
Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups
Leak-site victims · 7d
232
Leak-site victims · 30d
1K
Active groups · 30d
778 new
Most active · 7d
storm
Breaches added · 30d
9
Accounts exposed · 30d
36.8MHIBP
Ransomware & extortion groups · activityleak-site posts · 90-day window · click a group for its profile
| # | Group | 7d | trend | 30d | 90d | all-time* | Last post | Status | Estimated earnings (public reporting) |
|---|---|---|---|---|---|---|---|---|---|
| 1 | the gentlemen | 32 | ▲9 | 157 | 413 | 413 | active | no public figure | |
| 2 | qilin | 18 | ▲2 | 115 | 359 | 359 | active | no public figure | |
| 3 | krybit | 13 | ▲11 | 47 | 96 | 96 | active | no public figure | |
| 4 | direwolf | 5 | ▼6 | 45 | 62 | 62 | active | no public figure | |
| 5 | storm | 44 | ▲44 | 44 | 56 | 56 | active | no public figure | |
| 6 | akira | 7 | ▼1 | 38 | 82 | 82 | active | Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. | |
| 7 | coinbase cartel | 0 | = | 37 | 56 | 56 | active | no public figure | |
| 8 | inc ransom | 3 | ▼6 | 36 | 106 | 106 | active | no public figure | |
| 9 | lockbit5 | 5 | ▼1 | 27 | 86 | 86 | active | Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… | |
| 10 | shinyhunters | 1 | ▼2 | 24 | 34 | 34 | active | no public figure | |
| 11 | safepay | 14 | ▲8 | 22 | 72 | 72 | active | no public figure | |
| 12 | leakeddata | 0 | ▼7 | 20 | 38 | 38 | active | no public figure | |
| 13 | orova | 0 | = | 19 | 44 | 44 | active | no public figure | |
| 14 | zawoo | 0 | = | 19 | 19 | 19 | active | no public figure | |
| 15 | audit team | 10 | ▲6 | 18 | 19 | 19 | active | no public figure | |
| 16 | panzer | 6 | ▲3 | 17 | 24 | 24 | active | no public figure | |
| 17 | kazu | 0 | ▼17 | 17 | 17 | 17 | active | no public figure | |
| 18 | emperador | 6 | ▲5 | 16 | 19 | 19 | active | no public figure | |
| 19 | play | 4 | ▲4 | 14 | 44 | 44 | active | no public figure | |
| 20 | vexy | 4 | ▼6 | 14 | 14 | 14 | active | no public figure | |
| 21 | black nevas | 13 | ▲13 | 13 | 13 | 13 | active | no public figure | |
| 22 | chaos | 5 | ▲4 | 12 | 34 | 34 | active | no public figure | |
| 23 | everest | 0 | ▼4 | 12 | 34 | 34 | active | no public figure | |
| 24 | pear | 1 | ▼1 | 12 | 27 | 27 | active | no public figure | |
| 25 | rhysida | 3 | ▲1 | 12 | 15 | 15 | active | no public figure |
*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.
Breaches2 records · full details
| Victim | Breach date | Added to HIBP | Accounts | Data exposed | Description |
|---|---|---|---|---|---|
chess.com breach | 2026-08-03 | · 2d ago | 4.7M | Email addresses, Geographic locations, Names, Usernames | In August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches. |
mckesson.com breachsensitive | 2026-08-21 | · 5d ago | 6.4M | Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses | In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity". |
Breach & ransomware newsAll →
Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.