On January 21, 2026, the ransomware group sinobi added OnSight to its leak site, claiming that internal files had been exfiltrated from the London-based production facilities company that supplies high-end cameras, editing systems, and 3D post-production services to the film and broadcast industry.
Watch OnSight
Get alerted the next time OnSight files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about OnSight’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates sinobi claims to have stolen internal documents during a ransomware attack on OnSight. The company, located at Shepperton Studios and with a post-production team in Soho, has not yet disclosed the exact volume or nature of the files. No specific victim count has been released, and it remains unclear which categories of data—such as client contracts, employee records, or financial information—were taken. The leak site entry itself serves as the primary public evidence of the breach at this stage.
Why This Matters for You and Your Family
When a company like OnSight suffers a breach, the information exposed can include personal details of employees, contractors, freelancers, and even clients in the creative industries. Internal files often contain names, addresses, dates of birth, contact information, and sometimes copies of identification documents. If you or anyone in your family has worked with film, television, or broadcast production companies, your information could be among the records now in attackers’ hands. Once stolen data appears on dark-web leak sites, it circulates quickly among identity thieves, fraudsters, and doxxers who sell or repurpose it for months or years afterward.
The Doxxing and Identity-Chain Implications
Credential leaks and internal documents rarely stay isolated. A single exposed work email or phone number can be linked to personal accounts across social media, streaming services, and online shopping sites. Attackers use these connections to build an identity chain that reveals where you live, the names of family members, and even the usernames your children use on gaming platforms. This chain makes targeted harassment, SIM-swapping, and account takeovers far easier. Gaming accounts are especially vulnerable because kids often reuse passwords or email addresses tied to a parent’s work domain, turning one corporate breach into a household exposure.