On July 14, 2026, NowVertical (operating as COREBI) appeared on the leak site of the arcusmedia ransomware group with an extortion deadline of July 21, 2026. The listing states that internal files were exfiltrated during a ransomware attack on the global data and AI company. The leak-site posting does not specify the volume or exact categories of data taken, nor does it list individual victims, leaving affected customers and partners uncertain about their personal exposure.
Watch COREBI(NowVertical)
Get alerted the next time COREBI(NowVertical) files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about COREBI(NowVertical)’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The arcusmedia leak site, mirrored on ransomware.live, explicitly names NowVertical and claims successful data exfiltration following a ransomware deployment. The disclosure indicates that the company’s internal files were taken and will be published if the victim does not meet the group’s demands by the stated deadline. No sample data has been released publicly at the time of the listing, and the notification does not quantify how many customer records or employee records may be involved. Public reporting on arcusmedia’s prior postings shows the group typically posts proof-of-compromise screenshots or file-tree listings before escalating to full data dumps.
Why This Matters for You and Your Family
When a data and AI company like NowVertical is breached, the information it holds often includes details supplied by customers, partners, and vendors. Even though the exact data types remain undisclosed, internal files from such organizations frequently contain contracts, contact databases, financial records, or processed customer datasets. If your personal or family information was ever shared with NowVertical or one of its clients, those details could now sit in an attacker’s archive. The uncertainty itself creates risk: you cannot easily assess exposure without knowing what was taken, which is why proactive checks are essential for ordinary people whose data travels through multiple vendors.
Credential material or contact information exposed in these incidents routinely surfaces in subsequent fraud attempts, phishing campaigns, or identity-theft schemes targeting households.