Tessco Technologies
April 30, 2026
•[ ransomware, data exfiltration, data leak ]
On April 30, 2026, the ransomware group PayoutsKing claimed to have exfiltrated and encrypted 615GB of data from Tessco Technologies, a U.S. wireless communications products distributor, including contact information for over 100,000 individuals and Salesforce records for more than 500,000 customers.
Marutake Co., Ltd.
April 28, 2026
•[ ransomware, unauthorized access, system outage ]
Marutake Co., Ltd., a Japanese pharmaceutical and medical-supplies wholesaler, confirmed that a system outage was caused by ransomware resulting from unauthorized external access. As of its May 8, 2026 third notice, some servers remained impaired, some normal operations were difficult, and full restoration was expected to take considerable time, though the company was using alternative measures to maintain stable supply. Public Japanese security reporting linked the confirmed incident to a The Gentlemen leak-site claim, but Marutake stated that external leakage of personal information had not been confirmed.
Gelatissimo
April 27, 2026
•[ data leak, ransomware, financial data ]
DragonForce listed Australian gelato franchiser Gelatissimo on its leak site around April 27, 2026 and claimed to have stolen more than 350 GB of data, with other reporting specifying 352.24 GB. The claimed data included sensitive employee data, financial details, operational information, and executive contact details, and the group threatened publication unless the company responded; reviewed reporting did not confirm encryption or operational disruption.
Generation Life Limited
April 27, 2026
•[ cyber incident, unauthorized access, third-party service provider ]
Generation Life disclosed a contained cyber incident on April 27, 2026 involving an unauthorized party gaining access to part of its system through a third-party service provider. The company said the incident was quickly contained, core investment systems remained secure, services continued operating normally, and there was no evidence of unauthorized transactions. Qilin later claimed responsibility and alleged access to some Generation Life data, but public reporting did not confirm the scope, data types, encryption, or operational disruption.
Kent District Library
April 24, 2026
•[ ransomware, cyberattack, service disruption ]
Kent District Library closed all branches after a ransomware attack disrupted computer systems and network-dependent services.
i.e.Smart Systems
April 23, 2026
•[ ransomware, data-extortion, data leak ]
The Gentlemen ransomware group publicly claimed responsibility for a data-extortion attack against i.e.Smart Systems, a Houston-area technology integrator, on April 23, 2026 and threatened to leak sensitive data if the company did not engage in negotiations. Public reporting did not confirm encryption, deletion, operational disruption, or the specific data volume.
Mile Bluff Medical Center
April 21, 2026
•[ ransomware, data encryption, system disruption ]
Mile Bluff Medical Center experienced system disruptions after a security event that encrypted data, affecting phone and computer systems; clinical teams operated under downtime procedures while the organization investigated and engaged third-party partners.
Nordenta
April 20, 2026
•[ ransomware, data leak ]
The Danish dental supplier Nordenta was listed on the Kairos ransomware leak site around April 20, 2026, and Computerworld reported on April 22 that the company had been hit by ransomware. Kairos claimed to have stolen 1.68 TB of data and used the leak-site post to pressure company executives, but the specific data categories and operational impact were not confirmed in the reviewed sources.
Seiko USA
April 18, 2026
•[ defacement, ransomware, data theft ]
The Seiko USA websites Press Lounge section was defaced with a ransom message claiming attackers had accessed the companys Shopify backend and stolen its customer database; the claimed data theft was not confirmed.
Pricon Microelectronics, Inc.
April 17, 2026
•[ ransomware, data theft, LockBit 5.0 ]
Pricon Microelectronics suffered a ransomware attack affecting some servers; LockBit 5.0 later claimed data theft.
Adams County, Mississippi
April 17, 2026
•[ ransomware, government services, outdated systems ]
Adams County, Mississippi suffered a ransomware attack on April 17, 2026, after an outdated computer in the sanitation department allowed hackers to spread through the county network. The attack locked employees out of key services including court records, car tag payments, and public records processing; about 70% of systems were back online by the time of reporting, but full recovery was still underway.
Guesty
April 15, 2026
•[ ransomware, extortion, data theft ]
Vect claimed it stole 700GB of Guesty data and was negotiating with the company after a ransomware-related extortion listing.
Kemper
April 15, 2026
•[ ransomware, social engineering, extortion ]
In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.
Unimed
April 14, 2026
•[ unauthorized access, data theft, ransomware ]
Unknown attackers gained unauthorized access to parts of Unimed's IT infrastructure on April 14, 2026 and stole patient billing data processed for German hospitals and clinics. Affected institutions included university hospitals in Cologne, Freiburg, Heidelberg, Tbingen, Ulm, Dsseldorf, Mainz, Saarland, Oldenburg, Hannover, Gttingen, and others. Reporting indicated the attackers intended broader system encryption, but this was stopped; hospitals said their clinical systems and patient care were not affected.
Gastroenterology & Hepatology of CNY
April 14, 2026
•[ ransomware, data-extortion, healthcare ]
Exitium claimed responsibility for a ransomware and data-extortion attack against Gastroenterology & Hepatology of CNY on April 14, 2026, claiming it had encrypted systems and threatened to sell patient records if its demands were not met. DataBreach.com later indexed 196,959 rows associated with the leak, while other public reporting described Exitium's claim as involving approximately 167,303 patient records.
Spring Lake Park School District
April 12, 2026
•[ ransomware, system shutdown, cyberattack ]
Spring Lake Park Schools discovered on April 12, 2026 that an outside actor had accessed some district systems in a suspected ransomware incident; the district shut down systems defensively to prevent further access, causing class, childcare, community education, and after-school activity cancellations while recovery proceeded.
Autovista
April 11, 2026
•[ ransomware, service disruption, containment ]
Autovista reported a ransomware incident identified on April 11, 2026 that affected certain systems in Europe and Australia and caused service disruption for customers. The company implemented containment measures, worked with external forensic experts to validate systems before restoration, and later reported many products and services were partially or fully restored.
Athénée Royal d'Izel
April 9, 2026
•[ ransomware, encryption, service disruption ]
The local server of Athne Royal d'Izel was encrypted during a ransomware attack on the morning of April 9, 2026, affecting the online school platform for meal payments and attendance; quick isolation prevented personal data theft and restoration from backups was underway.
Saver
April 9, 2026
•[ ransomware, personal data, operational disruption ]
Saver was hit by ransomware on April 9, disrupting systems and phone lines while attackers accessed servers containing personal data.
City of Ardmore
April 8, 2026
•[ ransomware, phishing, data leak ]
On April 8, 2026, ransomware encrypted Ardmore police/internal servers after a phishing email; the incident was contained within hours, and information tied to criminal complaints and investigations, including names, addresses, and phone numbers, may have been exposed.