ToolsCVE trackerATT&CKLeak trackerCIDRDNSEmail securityHeadersTrackersTLSMy connectionCSP builderEmail headersJWTCert decoderPassphrasePassword checkHash & encodesecurity.txtDNSSEC & CAA

d4 · tools · leaks

Ransomware leak tracker.

Who ransomware groups are claiming to have breached, from two independent trackers of their leak sites. Unverified criminal claims, not confirmed breaches: an early signal to go and check, never a finding. Get alerts when something on your watch list is claimed. We do not record what you look up.

Tracking 2,073 claims across 108 groups, 237 of them in the last seven days.

Read this before you act on anything here

A listing means a criminal group has said it holds data from an organisation. It does not mean a breach happened, that the data is real, or that it is recent.

Where two independent trackers carried the same claim we mark it 2 sources. That means two crawlers saw the same post, not that anyone verified it.

We publish the claim only. We do not link to leak sites, mirror screenshots, or carry any pointer to stolen data. If you are listed here and believe it is wrong, or you want the entry removed, tell us and we will act on it.

None of this is our research. The crawling is done by RansomLook, Ransomfeed and ransomware.live, and we are grateful for it. Please go to them for the full picture.

Claims by endzone

Organisation namedGroup claimingClaimedWhereSources
Accela.com
accela.com
Revenue: $144.4 million Accela is a comprehensive cloud based software platform used by state and local governments to manage internal agency operations. We have successfully extracted over 50 GB of data from Accela. Data includes over 2 million lines of user...
endzone2026-09-18US, Government & Defense2 sources
AT&T
att.com
Revenue: $125.6 billion Initial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes/Call Forwarding (thanks a lot TORCH patch) - VPN + HVD (both external and internal MyDesktop) instances were access...
endzone2026-09-18US, Technology2 sources

Watch for your own name

Tell us what to watch for and we will email you when a group claims it. Weekly at most, only when something matches, and never the same claim twice. Double opt-in, one-click unsubscribe, and your watch list is deleted the moment you leave.

Set up an alert

Sources: RansomLook (CC BY 4.0, synced 2026-09-19 08:20 UTC), Ransomfeed (CC BY 4.0, synced 2026-09-19 08:20 UTC) and ransomware.live (PRO licence, synced 2026-09-19 08:20 UTC), each used under the licence shown and refreshed a few times a day. They crawl the groups' Tor leak sites; we never do, and we store no .onion address, magnet link or leak-site screenshot. Listings are the claims of criminals and are the sole responsibility of their authors; nothing here is verified, and nothing here is advice. This site stores no personal data about what you look up.