← All breaches
Live tracker · updated daily

Threat-actor trackers

The ransomware and extortion crews behind the breaches we cover — who they are, how active they've been, and every incident we've attributed to them. Each tracker grows automatically as our daily breach ingest picks up new claims.

Groups tracked18
Incidents attributed89
Most activeDeadlock
Latest activity · May 5, 2026Ahorramas Supermarket Chain — May 2026

How these trackers work

Our breach ingest monitors public reporting and ransomware leak sites daily. When an incident is claimed by or attributed to a named group, it's added to that group's tracker automatically. "Claimed by" is not proof — extortion crews sometimes exaggerate or recycle old data — so every entry links to the full write-up with sources.

If an organization you use appears here

Treat your data as circulating. Stolen records get scraped into the same broker-and-dump ecosystem that doxxers and identity thieves search. The fastest way to know your real exposure is a free breach scan — it checks your email against 15.4B+ leaked records in about 15 seconds, including data tied to the groups above.

Close the chain attack

Both halves of the chain, cleaned once.

A breach put your credentials in 15.4B+ leaked records. Hackers chain that data to your address on 800+ broker sites. GalaxyWarden closes both halves — see what’s exposed first, then pick the protection that fits.

Run the free scan — see what leaked →
15 seconds · 15.4B+ records checked · no account, no card
W Choose your protection level COMPARE PLANS →
One-time purge, ongoing monitoring with weekly re-scans and breach alerts, or family-wide coverage — compare every plan and pick what fits.