The “pay or leak” breaches: every company named so far

Since April 2026 the same extortion campaign has been working through one company after another — copy the customer records, demand payment, publish the files when nobody pays. Here is the running list, and what it means if your details are in one of the sets.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

33 companies have had records published in this campaign so far, and the sets that public breach databases have indexed hold 72 million email addresses between them. What leaked is identity rather than logins: names, addresses, phone numbers, sometimes dates of birth or partial card details. So the risk is not somebody logging in as you — it is somebody contacting you with enough real detail to be believed. Check which of these sets hold your address, turn on two-factor authentication on your email, and treat any call or message about a breach, a refund or a settlement as unverified until you have called back on a number you already had.

Companies named so far

Newest first, by the date the published records reached public breach databases — which is usually weeks or months after the intrusion itself. Each page lists the exposed data categories for that company and lets you check whether your email is in it. The most recent addition is Alcon.

Alcon data breachEmail addresses · Names · Phone numbers · Physical addresses218,395 records · published August 2026Brinks Home data breachDates of birth · Email addresses · Names · Partial credit card data732,162 records · published August 2026Exact Sciences data breachNames · Email addresses · Phone numbers · Physical addresses10.9M email addresses · published August 2026Inter-Con Security data breachEmail addresses · Employers · Job titles · Names276,114 records · published August 2026Houston City College data breachAcademic records · Citizenship statuses · Dates of birth · Email addresses831,642 records · published July 2026Fluke data breachEmail addresses · Employers · Job titles · Names821,100 records · published July 2026Glendale Community College data breachAcademic records · Dates of birth · Email addresses · Genders793,925 records · published July 2026Moody Bible Institute data breachDates of birth · Email addresses · Genders · Marital statuses2 million records · published July 2026Sysco data breachCustomer feedback · Email addresses · Employers · Job titles3 million records · published June 2026American Tower data breachEmail addresses · Job titles · Names · Phone numbers216,601 records · published June 2026Madison Square Garden Sports data breachCustomer service records · Email addresses · Names · Phone numbers10 million records · published June 2026JCPenney data breachDates of birth · Email addresses · Government issued IDs · Job titles368,418 records · published June 2026Ralph Lauren data breachAge groups · Email addresses · Genders · Names139,903 records · published June 2026Infinite Campus data breachEmail addresses · Employers · Job titles · Names137,123 records · published June 2026Berkadia data breachEmail addresses · Employers · Names · Phone numbers305,216 records · published June 2026University of Nottingham data breachAcademic records · Citizenship statuses · Dates of birth · Disabilities454,635 records · published June 2026Baker Distributing data breachEmail addresses · Names · Phone numbers · Physical addresses102,935 records · published June 2026BCD Travel data breachEmail addresses · Employers · Job titles · Names396,313 records · published June 2026DentaQuest data breachDates of birth · Email addresses · Genders · Government issued IDs3 million records · published June 2026Kemper data breachEmail addresses · Names · Partial credit card data · Phone numbers269,299 records · published May 2026Spectrum data breachEmail addresses · Job titles · Names · Phone numbers5 million records · published May 2026Mytheresa data breachEmail addresses · Names · Partial credit card data · Phone numbers84,108 records · published May 2026Ameriprise data breachEmail addresses · Employers · Financial transactions · Job titles502,597 records · published May 20267-Eleven data breachDates of birth · Email addresses · Names · Phone numbers185,256 records · published May 2026Addi data breachAge groups · Credit scores · Device information · Email addresses35 million records · published May 2026Abrigo data breachEmail addresses · Employers · Job titles · Names711,099 records · published May 2026Canada Life data breachEmail addresses · Job titles · Names · Phone numbers237,810 records · published May 2026Cushman & Wakefield data breachEmail addresses · Job titles · Names · Phone numbers310,431 records · published May 2026Zara data breachEmail addresses · Geographic locations · Purchases · Support tickets197,376 records · published May 2026Vimeo data breachEmail addresses · Names119,167 records · published May 2026Aman data breachDates of birth · Email addresses · Genders · Language preferences215,563 records · published May 2026ADT data breachDates of birth · Email addresses · Names · Partial government issued IDs5 million records · published April 2026Udemy data breachEmail addresses · Employers · Job titles · Names1 million records · published April 2026

Record counts are unique email addresses in each published set, not headcounts of people — one person can appear in several sets, and in more than one row of the same set. The list is rebuilt from our breach catalogue, so it grows as new sets are indexed.

See what a caller could already put together about you

Leaked records get dangerous when they are matched with a current address and phone number. PersProtect finds where yours are published across 499 broker and people-search sites and files the removals for you. Start with a free scan.

Check my exposure — free →

1. What “pay or leak” means in practice

There is no encryption in this one and nothing stops working. The attackers get into a company’s systems, copy whatever customer or staff records they can reach, and leave. Then comes a private demand with a deadline, and when the deadline passes without payment the files go up publicly. From the outside you usually see nothing until that last step, which is why the first many people hear of it is a set of records appearing with their name in it. The practical difference from a ransomware attack is that the harm lands on the people in the files rather than on the company’s operations, and it arrives weeks after the break-in rather than the same day.

2. The way in was usually a phone call

Across the notices these companies have published, the recurring entry point is not malware but a conversation. Someone rings a help desk or an employee, sounds like internal IT or a supplier, and talks the person on the other end through a sign-in or a password reset. Abbott described exactly that pattern after the intrusion into its Exact Sciences business: staff were phoned and talked out of single sign-on access. It matters to you for one reason. The same technique that got into these companies is the technique that will be aimed at you with the data that came out of them, and it works on attention rather than on software.

3. Why the same person turns up in several of these

Look down the list and there is no industry pattern: a fashion retailer, a cable company, an insurer, two colleges, a travel agency, an eye-care manufacturer. What they share is the kind of system they were storing contacts in, not the kind of business they run. So a single email address that has shopped, insured a car, enrolled a child and booked a work trip can sit in four of these sets at once. Each one on its own is a partial picture. Together they are a fairly complete one, and that is the realistic thing to plan around rather than any single company’s notice.

4. What is actually in the files

Identity, mostly. Names, email addresses, phone numbers and postal addresses run through nearly all of them, with dates of birth, purchase histories, partial card details or insurance information appearing in some. Passwords are rare, because these were not login databases. That changes what the exposure is worth: nobody can log in as you with this material, but anyone can sound like they already know you. A caller who has your address, the last four digits of your card and the name of the company you actually pay is past the point where most people start checking.

5. Assume the contact, not the login

The single rule that covers almost every follow-on approach: never continue a conversation that somebody else started. Hang up, close the email, and go back through a number or an address you already had — the one printed on your card, your statement or the company’s own site. Anyone genuine is fine with that. Beyond it, turn on two-factor authentication on your email and banking, because email is the account that resets all the others, and stop using the same password anywhere it still repeats. If a date of birth or a Social Security number was in the set that holds you, freeze your credit at all three bureaus as well.

6. Expect the second wave, aimed at victims

Every large published set is followed by people working it. The recurring scripts are a message about a settlement or compensation that asks you to confirm bank details, a fake claim site standing up within days of any real lawsuit, an offer of identity protection that collects exactly the data that leaked, and a call offering to “secure” your account that ends with a one-time code being read aloud. Some victims of these sets have also had extortion emails sent directly to them, quoting their own leaked details as proof. None of that needs a reply. Real claim processes run through a court-appointed administrator and are announced on the company’s own breach page — our guide to settlement claims covers how to tell one from a fake.

7. Shrink the half of your profile that is still in your control

None of the published records can be pulled back. What can be cut is the public layer that makes them workable — the people-search and data-broker sites listing your current address, phone number, age and relatives, which is what lets someone combine a stale record from one of these sets with a live phone number for you today. Removing that does not undo any breach and it does make the follow-up materially harder. Our data-broker opt-out guide has the free, site-by-site route, and what to do after a data breach covers the general order of operations.

Common questions

The “pay or leak” breaches, answered

I have never had an account with that company. Why is my email in its breach?

Several names on this list are not consumer brands at all. A property-management firm, a commercial-security contractor, a school records platform, a distributor of air-conditioning parts — none of them sell to you directly, and all of them end up holding your details because someone you did deal with passed them along. Your landlord, your employer, your child’s school district or a shop that installed something in your home is the link. There is no account to close in those cases and no password to change, which is why the response below is about the follow-up contact rather than about logins.

Did any of the companies pay?

A few have said publicly that they refused, most have said nothing either way, and there is no reliable way to tell from the outside. What the pattern shows is that the data ended up published for every company on this list, whether or not money changed hands. Treat a demand like this as a disclosure event from the first day rather than something a payment can undo — files that have been copied stay copied.

Can I check whether I am in one of these sets?

For most of them, yes: the published records have been indexed by the breach databases our free check runs against, so a single lookup tells you which of these names hold your address. The exception is anything with health data in it. Those sets are deliberately kept out of public email lookups so that nobody can type in a neighbour’s address and learn something medical about them, so no tool will confirm the Exact Sciences set for you — ours included.

Is this one group of people?

The name has been attached to different crews and different tactics for years, and security reporting has repeatedly described it as a label that gets picked up and reused rather than a fixed roster. For anyone whose data is in one of these sets, that argument does not change much. The method is consistent, the sets keep appearing, and the exposure is identical whoever is behind the keyboard.

Are the passwords in these sets?

Mostly not, and that is what people get wrong about this campaign. These are records lifted out of business systems — customer lists, contact databases, support and billing records — rather than login tables, so what comes out is name, email, phone number, postal address, sometimes a date of birth or the last four digits of a card. Changing your password is still worth doing where you had an account, but it is not the defence here. The material is the kind that makes a stranger sound like they already know you.

Will I get a letter about it?

Often yes, and often late. Notification duties depend on which state you live in and what category of data was involved, and a company working through a set of several hundred thousand records can take months to send anything. Some of the companies here published a notice on their own site and never wrote to individuals at all. If the set holding your address is already public, waiting for the post is the slowest way to find out.

Does a credit freeze help with this kind of breach?

It helps against one specific outcome — somebody opening an account in your name — and it is free at all three bureaus, so it is worth doing if a date of birth or a Social Security number was in the set. It does nothing about the more likely outcome here, which is contact: a caller or an email that quotes a real order, a real address or a real policy number to get you to hand over something new. Those two risks need different responses, and most people only cover the first one.

The files are out. Your live details do not have to be.

See which sites are publishing your address, phone and relatives right now — free, in about a minute.

Run a free exposure scan →