This view includes organisations named on ransomware leak sites. Those are the groups’ claims, not confirmed breaches — the organisations have not confirmed them and no filing or verified record supports them.
Claimed by black nevas · unconfirmedRansomware claim2026-09-09
Speed Group named on black nevas's leak site
Speed Group (speedgroupe.com / speedfrance.fr) is a global leader in the manufacture of synthetic monofilament lines. The company was founded in France over 40 years ago. Today, Speed Group operates four manufacturing plants located in France, the USA, Chile, and South Africa. It specializes in the extrusion of high-quality monofilaments—particularly trimmer lines—and ranks among the world's leading players in this sector. The company also produces technical monofilaments for other industries. Since 2004, it has been part of the Italian Emak Group (Tecomec). Speed Group is renowned for its high product quality, rigorous production controls, and excellent service.Cyber Attack on Speed Group (speedgroupe.com)World leader in monofilament lines manufacturing — Speed Group — has been hit by a cyber attack. Hackers breached the company’s systems and stole confidential data.More than 1 terabytes of information were exfiltrated, including technical documentation, customer databases and production data from factories in France, USA, Chile, and South Africa.The company has not issued an official statement yet. #SpeedGroup #CyberAttack #DataBreach
Records not disclosedRansomLook
Claimed by black nevas · unconfirmedRansomware claim2026-09-09
L'azurde named on black nevas's leak site
L'azurdeL'azurde Company for Jewelry is a prominent Middle Eastern jewelry manufacturer and retailer, headquartered in Riyadh, Saudi Arabia.Founded in the 1980s, it designs, manufactures, and sells gold, diamond, and gemstone jewelry across the Kingdom, Egypt, the UAE, Kuwait, Oman, and Qatar.Core InformationBrands: Operates under several lines including L'azurde, Instyle, Miss L', and Waves.Business Segments: Focuses on both wholesale distribution to independent jewelers and direct-to-consumer retail.Public Listing: Listed on the Saudi Stock Exchange (Tadawul) under the symbol 4011.Accessibility: Offers both online shopping and a vast physical footprint of stores across the region.
Records not disclosedRansomLook
Claimed by black nevas · unconfirmedRansomware claim2026-09-09
Arkın Group / Arkın Casino, The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach named on black nevas's leak site
Arkın Group is a Turkish Cypriot company group primarily operating in Northern Cyprus (TRNC). It was founded by Erbil Arkin, who serves as Chairman. The group has around 25–30 years of experience, employs over 3,000 people, and maintains international offices.Main ActivitiesThe group began in the hospitality sector and expanded over time:The Arkın Colony Hotel (Kyrenia/Girne) — the group’s first hotel, marking its entry into hospitality.Arkın Palm Beach Hotel (Famagusta/Gazimağusa) — a hotel with an associated casino that contributed significantly to North Cyprus tourism.The Arkın Iskele Hotel (Iskele, opened in 2022) — a modern property featuring approximately 1 km of beach, restaurants, entertainment facilities, and a casino.Casinos operate alongside the group’s hotels (including Arkın Casino facilities).Beyond hospitality and gaming, the group is involved in:Yachting and boat building (Arkin Pruva Yachts, including eco-friendly models);Education — ARUCAD (Arkın University of Creative Arts and Design), opened in 2017 as a specialized university focused on art, design, and communication;Marina management — in 2024 the group assumed management of the luxury Karpaz Gate Marina resort on the Karpaz Peninsula.Arkın Group focuses on tourism, hotels, casinos, yachting, and related sectors. It also has business ventures in Europe, South America, and the Middle East.
Records not disclosedRansomLook
Claimed by black nevas · unconfirmedRansomware claim2026-09-09
Abans Group named on black nevas's leak site
The Abans Group is a globally diversified organization engaged in Investment Management, Trading, Broking, Gold Refining, Non-Banking Financial Services, Agricultural Trading, Software Development, and Real Estate Development.We are globally diversified organisation engaged in Financial Services, Gold Refining, Jewellery, Commodities Trading, Agricultural Trading and Warehousing, Pharmaceuticals Distribution, Software Development and Real Estate. The group is founded by young entrepreneur - Mr. Abhishek Bansal who leads a global team of over 300 people operating growing businesses from multiple locations including India, United Kingdom, Dubai, Shanghai, Hong kong, Mauritius and Singapore.Our Company represents the financial services arm of the Abans Group. We operate a diversified global financial services business, headquartered in India, providing NBFC services, multi-asset global institutional trading in equities,Since the inception of our Company in 2009-10, we have grown from being a commodities trading company into a diversified multi-asset and multi-national financial services company having varied financial services businesses which are mainly organised under:NBFC Business: We are a Non Banking Financial Company registered with RBI and having a Total Loan Book of ₹ 35,263 lakhs as on March 31, 2021.Our NBFC business is primarily focused on lending to private traders and other small and medium businesses involved in the commodities trading market.Agency Business: We are SEBI registered Stock and Commodity Exchange Brokers with memberships across all the major stock exchanges in India, including BSE, NSE, MSEI, MCX, NCDEX, ICEX and IIEL and further we have memberships in various international exchanges like DGCX (Dubai), LME (London), INE (Shanghai) and DCE (China). We are also a SEBI Registered Portfolio Management company as well as a SEBI Registered Category-I FPI and Category-III AIF. We offer various client-based institutional trading services, wealth man
Records not disclosedRansomLook
Claimed by black nevas · unconfirmedRansomware claim2026-09-09
Cash and carry - COSAEN GRUP named on black nevas's leak site
Cash and carry - COSAEN GRUPProfessionals in the food sectorюCosaen Grup SA has wholesale and retail warehouses offering a wide range of food and beverage products, as well as fresh and dry goods.[link removed] stock: 983158 filedata size: 243GBList of files, to confirm that we have all the files, you can request several files from the list and we will provide them to you.[link removed] ask all our partners, friends and clients to contact us to discuss the acquisition of this data. You know the contacts. For new members, please wait in the Contacts tab.Advertising:We are always ready to cooperate in any form, do you need specific data? We will try to provide it to you as soon as possible, we will receive and download your competitors' data, provide a list of what you are interested in. We are also ready to cooperate with law firms and data leak victims. We will provide all the information you need about the company that was negligent and provided access to data to its clients.
Records not disclosedRansomLook
Claimed by black nevas · unconfirmedRansomware claim2026-09-09
PROMOSFERA S.r.l. named on black nevas's leak site
passports, employee and client documents, databases of promotional participants - hundreds of thousands of emails + full names, tens of thousands of emails + full names + phone numbersinternal company documentation[link removed] ask all our partners, friends and clients to contact us to discuss the acquisition of this data. You know the contacts. For new members, please wait in the Contacts tab.Advertising:We are always ready to cooperate in any form, do you need specific data? We will try to provide it to you as soon as possible, we will receive and download your competitors' data, provide a list of what you are interested in. We are also ready to cooperate with law firms and data leak victims. We will provide all the information you need about the company that was negligent and provided access to data to its clients.
Records not disclosedRansomLook
ConfirmedData breach2026-02-05
In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack . As part of the incident, Betterment customers received fraudulent crypto-related messages promising high returns if funds were sent to an attacker-controlled cryptocurrency wallet. The breach exposed 1.4M unique email addresses, along with names and geographic location data. A subset of records also included dates of birth, phone numbers, and physical addresses. In its disclosure notice , Betterment stated that the incident did not provide attackers with access to customer accounts and did not expose passwords or other login credentials.
ConfirmedData breach2026-06-15
In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as well as names, physical addresses and phone numbers, among other data.
ConfirmedData breach2025-11-20
In November 2025, Beckett Collectibles experienced a data breach accompanied by website content defacement . The stolen data was later advertised for sale on a prominent hacking forum, with portions subsequently released publicly. The publicly circulating data initially included more than 500k email addresses reportedly belonging to North American customers, before a larger corpus of over 1M addresses was published the following month. The impacted data included names, usernames, phone numbers and physical addresses.
ConfirmedData breach2026-06-05
In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.
ConfirmedData breach2026-03-15
In March 2026, the Turkish restaurant chain Baydöner suffered a data breach which was subsequently published to a public hacking forum . The incident exposed over 1.2M unique email addresses along with names, phone numbers, cities of residence and plaintext passwords. A small number of records also included Turkish national ID number and date of birth. In their disclosure notice , Baydöner stated that payment and financial data was not affected.
ConfirmedData breach2026-06-07
In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site . In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HVAC contractor customer base. The exposed data was largely corporate contact and support information with limited sensitivity.
ConfirmedData breach2025-12-18
In March 2025, the French vehicle inspection company AUTOSUR suffered a data breach exposing over 10M customer records, though only 487k unique email addresses were present. The compromised data included names, phone numbers, physical addresses, and vehicle details such as make and model, VIN, and registration plate. AUTOSUR later issued a disclosure notice with further details.
ConfirmedData breach2026-03-18
In March 2026, the online safety service Aura disclosed a data breach that exposed 900k unique email addresses . The data was primarily associated with a marketing tool from a previously acquired company, with fewer than 20k active Aura customers affected. Exposed data included names, phone numbers, physical and IP addresses, and customer service notes. Aura advised that no Social Security numbers, passwords or financial information were compromised.
903,080 recordsAura →Have I Been Pwned ConfirmedData breach2026-05-30
In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.
ConfirmedData breach2026-02-10
In January 2026, a data breach impacting the French non-profit Association Nationale des Premiers Secours (ANPS) was posted to a hacking forum . The breach exposed 5.6k unique email addresses along with names, dates of birth and places of birth. ANPS self-submitted the data to HIBP and advised the incident was traced back to a legacy system and did not impact health data, financial information or passwords.
ConfirmedData breach2025-10-04
In August 2025, the "marketplace that connects artists to prospective clients" Artists&Clients, suffered a data breach and subsequent ransom demand of US$50k . The data was subsequently leaked publicly and included 95k unique email addresses alongside usernames, IP addresses and bcrypt password hashes.
ConfirmedData breach2026-02-16
In December 2025, a database of the Brazilian crowdfunding platform APOIA.se was posted to an online forum . In January 2026, the company confirmed it had suffered a data breach. The incident exposed 451k unique email addresses along with names and physical addresses.
ConfirmedData breach2025-09-21
In October 2021, the now defunct Arabic language Anime website Animeify suffered a data breach that was later redistributed as part of a larger corpus of data . The data included 808k unique email addresses along with names, usernames, genders and plain text passwords.
ConfirmedData breach2026-04-17
In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak . The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. They subsequently published the alleged data which contained over 2M unique email addresses along with names, physical addresses and customer support records.
2,147,679 recordsAmtrak →Have I Been Pwned ConfirmedData breach2026-05-26
In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general , Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".
ConfirmedData breach2026-06-26
In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.
ConfirmedData breach2026-05-01
In April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign , with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on all records, the data also included genders, physical addresses, phone numbers, nationalities, dates of birth, spouse names and VIP status codes.
215,563 recordsAman →Have I Been Pwned ConfirmedData breach2026-08-09
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.
218,395 recordsAlcon →Have I Been Pwned ConfirmedData breach2026-04-27
In April 2026, home security firm ADT confirmed a data breach by ShinyHunters , which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also advised that "in a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included" and that it had contacted all affected people.
5,488,888 recordsADT →Have I Been Pwned Filings come from SEC EDGAR and are filtered to 8-K submissions that declare Item 1.05, not merely mention it. Breach records come from Have I Been Pwned. Ransomware claims come from RansomLook, used under CC BY 4.0; we store metadata only and never leak links.