Incidents
Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups
Leak-site victims · 7d
232
Leak-site victims · 30d
1K
Active groups · 30d
778 new
Most active · 7d
storm
Breaches added · 30d
9
Accounts exposed · 30d
36.8MHIBP
Ransomware & extortion groups · activityleak-site posts · 90-day window · click a group for its profile
| # | Group | 7d | trend | 30d | 90d | all-time* | Last post | Status | Estimated earnings (public reporting) |
|---|---|---|---|---|---|---|---|---|---|
| 1 | the gentlemen | 32 | ▲9 | 157 | 413 | 413 | active | no public figure | |
| 2 | qilin | 18 | ▲2 | 115 | 359 | 359 | active | no public figure | |
| 3 | krybit | 13 | ▲11 | 47 | 96 | 96 | active | no public figure | |
| 4 | direwolf | 5 | ▼6 | 45 | 62 | 62 | active | no public figure | |
| 5 | storm | 44 | ▲44 | 44 | 56 | 56 | active | no public figure | |
| 6 | akira | 7 | ▼1 | 38 | 82 | 82 | active | Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. | |
| 7 | coinbase cartel | 0 | = | 37 | 56 | 56 | active | no public figure | |
| 8 | inc ransom | 3 | ▼6 | 36 | 106 | 106 | active | no public figure | |
| 9 | lockbit5 | 5 | ▼1 | 27 | 86 | 86 | active | Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… | |
| 10 | shinyhunters | 1 | ▼2 | 24 | 34 | 34 | active | no public figure | |
| 11 | safepay | 14 | ▲8 | 22 | 72 | 72 | active | no public figure | |
| 12 | leakeddata | 0 | ▼7 | 20 | 38 | 38 | active | no public figure | |
| 13 | orova | 0 | = | 19 | 44 | 44 | active | no public figure | |
| 14 | zawoo | 0 | = | 19 | 19 | 19 | active | no public figure | |
| 15 | audit team | 10 | ▲6 | 18 | 19 | 19 | active | no public figure | |
| 16 | panzer | 6 | ▲3 | 17 | 24 | 24 | active | no public figure | |
| 17 | kazu | 0 | ▼17 | 17 | 17 | 17 | active | no public figure | |
| 18 | emperador | 6 | ▲5 | 16 | 19 | 19 | active | no public figure | |
| 19 | play | 4 | ▲4 | 14 | 44 | 44 | active | no public figure | |
| 20 | vexy | 4 | ▼6 | 14 | 14 | 14 | active | no public figure | |
| 21 | black nevas | 13 | ▲13 | 13 | 13 | 13 | active | no public figure | |
| 22 | chaos | 5 | ▲4 | 12 | 34 | 34 | active | no public figure | |
| 23 | everest | 0 | ▼4 | 12 | 34 | 34 | active | no public figure | |
| 24 | pear | 1 | ▼1 | 12 | 27 | 27 | active | no public figure | |
| 25 | rhysida | 3 | ▲1 | 12 | 15 | 15 | active | no public figure |
*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.
Breaches9 records · full details
| Victim | Breach date | Added to HIBP | Accounts | Data exposed | Description |
|---|---|---|---|---|---|
chess.com breach | 2026-08-03 | · 2d ago | 4.7M | Email addresses, Geographic locations, Names, Usernames | In August 2026, millions of records allegedly sourced from Chess.com were posted online . The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches. |
mckesson.com breachsensitive | 2026-08-21 | · 5d ago | 6.4M | Dates of birth, Email addresses, Employers, Genders, Names, Personal health data, Phone numbers, Physical addresses | In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity". |
magairports.com breach | 2026-08-27 | · 13d ago | 8.8M | Browser user agent details, Email addresses, Geographic locations, IP addresses, Names, Phone numbers, Purchases, Vehicle registration plates | In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services . The incident was later claimed by the FulcrumSec hacking group , who subsequently published email addresses and phone numbers relating to 8.8M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice , MAG advised that "at no point has passenger safety or aviation security been compromised". |
questel.com breach | 2026-08-01 | · 14d ago | 1.2M | Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets | In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers. |
carhartt.com breach | 2026-08-13 | · 21d ago | 12.9M | Email addresses, Names, Phone numbers, Physical addresses | In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach. |
nius.de breachsensitive | 2025-07-13 | · 23d ago | 6.1K | Bank account numbers, Email addresses, Names, Partial credit card data, Physical addresses, Purchases | In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly . The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry). |
golfcanada.ca breach | 2026-05-14 | · 24d ago | 569K | Dates of birth, Email addresses, Genders, Geographic locations, Names, Usernames | In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). It remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability. |
ozhairandbeauty.com breach | 2026-08-15 | · 27d ago | 2M | Email addresses, Geographic locations, Names, Phone numbers, Purchases | In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack . The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases. |
fanlore.org breach | 2026-08-06 | · 27d ago | 145K | Email addresses, Names, Passwords, Usernames | In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates . The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP. |
Breach & ransomware newsAll →
Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.