Rx Management
April 8, 2026
•[ ransomware, data leak, healthcare ]
INC Ransom listed Australian pharmacy management firm Rx Management on its leak site on April 8, 2026 and threatened to publish more than 180 GB of allegedly stolen data; the data types and full extent were not publicly verified.
Synergy France
April 8, 2026
•[ ransomware, data leak, cyberattack ]
The Gentlemen ransomware group claimed responsibility for a cyberattack against Synergy France on April 8, 2026 and threatened to publish sensitive data unless the company contacted the group. ComputerWeekly later described The Gentlemen as an emerging ransomware player responsible for a large volume of attacks in 2026.
ChipSoft
April 7, 2026
•[ ransomware, healthcare, data breach ]
Embargo ransomware hit ChipSoft on April 7, 2026, disrupting its website and digital healthcare services, causing hospitals to disconnect or take ChipSoft-connected systems offline, and stealing medical personal data from several Dutch healthcare institutions; ChipSoft later said the stolen data had been destroyed.
Undisclosed Australian organization
April 7, 2026
•[ ransomware, Medusa ransomware, data exfiltration ]
Microsoft reported that Storm-1175, a financially motivated cybercrime actor linked to Medusa ransomware, heavily impacted organizations in Australia, the United Kingdom, and the United States by exploiting vulnerable web-facing systems, exfiltrating data, and deploying ransomware. This row represents the undisclosed Australian victim component of the country-level coding approach.
Undisclosed United Kingdom organization
April 7, 2026
•[ ransomware, data exfiltration, cybercrime ]
Microsoft reported that Storm-1175, a financially motivated cybercrime actor linked to Medusa ransomware, heavily impacted organizations in Australia, the United Kingdom, and the United States by exploiting vulnerable web-facing systems, exfiltrating data, and deploying ransomware. This row represents the undisclosed United Kingdom victim component of the country-level coding approach.
Undisclosed United States organization
April 7, 2026
•[ ransomware, cybercrime, data exfiltration ]
Microsoft reported that Storm-1175, a financially motivated cybercrime actor linked to Medusa ransomware, heavily impacted organizations in Australia, the United Kingdom, and the United States by exploiting vulnerable web-facing systems, exfiltrating data, and deploying ransomware. This row represents the undisclosed United States victim component of the country-level coding approach.
ChipSoft
April 7, 2026
•[ ransomware, data breach, healthcare ]
ChipSoft was hit by a ransomware attack on April 7, 2026, causing hosted patient-facing and provider-facing digital services to be disconnected or taken offline while the company investigated and restored systems. ChipSoft later confirmed that personal and medical patient data from some Dutch healthcare customers had been stolen and said the stolen data was destroyed and not published.
Winona County
April 6, 2026
•[ ransomware, data leak, government ]
Winona County, Minnesota experienced a ransomware attack that began April 6, 2026 and was discovered April 7. Officials took affected systems offline, declared a local emergency, requested Minnesota National Guard assistance, and notified the FBI. Later reporting confirmed cybercriminals released information taken from the county network; emergency services and 911 remained operational, while vital statistics and DMV systems were among those impacted.
Equity Life Indonesia
April 4, 2026
•[ ransomware, data theft, data encryption ]
The Gentlemen ransomware group claimed responsibility for an attack against Equity Life Indonesia on April 4, 2026, threatening to publish stolen data unless contacted. Independent ransomware trackers listed Equity Life Indonesia under The Gentlemen, and CYFIRMA reported the campaign objective as data theft, data encryption, and financial gain, but public sources did not confirm the exact data volume, affected record count, or operational disruption.
Amtrak
April 3, 2026
•[ data leak, ransomware, ShinyHunters ]
In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak. The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. The exposed data contained over 2M unique email addresses along with names, physical addresses and customer support records.
Coral Bay Nickel Corporation
April 2, 2026
•[ ransomware, server encryption, cyberattack ]
Coral Bay Nickel suffered ransomware encryption of two servers, but production systems remained unaffected and operations continued.
Świętokrzyskie Rehabilitation Center
March 31, 2026
•[ ransomware, encryption, personal data ]
witokrzyskie Rehabilitation Center reported a ransomware attack that encrypted personal-data files and may have exposed data.
Parque Eólico Toabré
March 31, 2026
•[ cyberattack, data leak, ransomware ]
Everest claimed responsibility for a cyberattack against Parque Elico Toabr on March 31, 2026 and threatened to release sensitive data. La Estrella de Panam later listed Parque Elico Toabr among Panamanian technology incidents dated May 9, 2026, and other dark-web monitoring reported an alleged 175GB database leak. Public reporting did not confirm encryption, data destruction, operational disruption, or compromise of wind-farm control systems.
Statistics South Africa
March 29, 2026
•[ cyber breach, data theft, ransomware ]
Stats SA said a cyber breach affected one HR database used for online job applications, while XP95 claimed it stole 453,362 files totaling 154 GB and demanded ransom.
Jackson County Sheriff's Office
March 27, 2026
•[ ransomware, cyberattack, operational disruption ]
A ransomware attack crippled the Jackson County Sheriff's Office in Indiana, taking computers, Wi-Fi, and reporting systems offline and forcing staff to use temporary manual workarounds.
Goodwill of Greater Grand Rapids
March 27, 2026
•[ ransomware, extortion, data theft ]
Goodwill of Greater Grand Rapids said an attack disrupted part of its network environment and affected store operations, forcing locations across its West Michigan service area to operate on a cash-only basis, while outside reporting tied the incident to an Interlock ransomware extortion claim alleging theft of 80 GB of data.
ZenBusiness
March 27, 2026
•[ data breach, extortion, ransomware ]
In March 2026, the hacker and extortion group "ShinyHunters" claimed to have obtained a substantial corpus of data from ZenBusiness, a business formation and compliance platform. The group claimed the data had been exfiltrated from platforms including Snowflake, Mixpanel and Salesforce, and threatened to publish it if a ransom was not paid. The following month, after claiming payment had not been made, ShinyHunters publicly released the data. The collection amounted to many terabytes across thousands of files that appeared to originate from multiple systems and business functions, including leads, support records and other CRM-related data. The data contained approximately 5M unique email addresses, often accompanied by name and phone number depending on the source file.
The Left Party
March 26, 2026
•[ ransomware, data leak, employee data ]
Die Linke said its federal headquarters IT systems were hit by a ransomware attack on March 26, 2026, causing partial disruption, while outside reporting tied the incident to Qilin and a claim of stolen internal and employee data.
Omax Autos
March 26, 2026
•[ ransomware, cyber security incident, IT infrastructure ]
Omax Autos said its IT department initially suspected a cyber security incident on March 26, 2026, which was later confirmed as a ransomware attack on the company's IT infrastructure; the company said core systems and operations were not impacted.
ARC Dialysis LLC
March 25, 2026
•[ ransomware, data leak, Personally Identifiable Information (PII) ]
PEAR claimed responsibility for a cyberattack against ARC Dialysis LLC, an independent U.S. dialysis provider, with ransomware-monitoring sources listing an estimated attack date of March 25, 2026 and discovery on April 7, 2026. DataBreach later indexed 310,566 rows allegedly tied to the breach, including Social Security numbers, dates of birth, emails, phone numbers, names, and street addresses. Public sources did not confirm file encryption, operational disruption, or a precise intrusion vector.