MCBS has linked a breach to 1.2 million affected individuals, while the PEAR ransomware group claimed to have taken 3 TB of information - a reminder that volume claims and verified exposure are not the same thing.
A new victim label and an unverified 18.7 GB data figure create immediate pressure, even while the technical facts remain incomplete.
A fresh victim entry tied to hydraulic-components.net shows how extortion crews use exact file and volume figures to amplify pressure, even when the alleged theft remains unconfirmed.
A victim entry names Zynex and attaches a data-loss figure, but the allegation remains unverified and the content of the data is not described.
A ransomware-linked victim listing tied to Thegentlemen has placed a Montreal imaging clinic in view, yet the supplied material does not prove intrusion, exfiltration, or patient-data exposure.
A public victim listing tied to Moneymessage names Indigo Energy, but the record does not confirm breach scope, data theft, or downstream impact.
A ransomware crew says it has confidential data tied to a Coca-Cola subsidiary, yet the public record still rests on an unverified extortion claim.
Craneware’s disclosure points to a classic exfiltration event: an unauthorized party got into part of its environment and took data tied to employees, customers, partners, and some US healthcare organizations.
MatheuZSecurity’s newly announced Furtex package puts raw io_uring and eBPF in the spotlight, showing how post-exploitation tooling can lean on legitimate Linux primitives to pursue stealthier process manipulation and data theft.
A breach involving a vendor-managed IT support platform shows how sensitive client tax data can travel through a trust boundary that many organizations do not fully see.
A ransomware listing tied to Paragon Store Fixtures points to a familiar extortion pressure point: sensitive business files that can hurt customers, partners, and deal pipelines at once.
A ransomware-style listing ties arambol.co.uk to M3rx and alleges a large file haul, yet the public evidence still stops at the post itself.
A Go-based backdoor, stolen credentials, and share-based transfer paths point to an espionage workflow built for patience, not noise.
A victim listing tied to Thegentlemen puts the Finnish advisory and accounting firm in view, yet the public record does not confirm breach scope, data theft, or operational disruption.
A new extortion listing tied to Aphena Pharma Solutions points to the value of finance records, even when the alleged breach details remain unverified.
Lidl’s customer data was taken from a separately stored database run by a third-party provider, underscoring how a breach can begin far from the public storefront.
Google removed ModHeader from the Chrome Web Store after a security review flagged dormant surveillance behavior and a hidden data exfiltration risk in a browser extension with roughly 900,000 users.
Bridgeport S.p.A. was named in a DeadLock victim publication, but the public record still does not confirm the intrusion path, the scale of any compromise, or whether data was actually taken.
Židlochovice has been named as a DeadLock victim, but the more important question is whether this is a real exfiltration case, a pressure tactic, or both.
A Deadlock victim post tied to WiBeats S.r.l. shows how modern ransomware pressure often centers on email archives, contracts, and permits rather than encryption alone.