The “pay or leak” breaches: every company named so far
Since April 2026 the same extortion campaign has been working through one company after another — copy the customer records, demand payment, publish the files when nobody pays. Here is the running list, and what it means if your details are in one of the sets.
33 companies have had records published in this campaign so far, and the sets that public breach databases have indexed hold 72 million email addresses between them. What leaked is identity rather than logins: names, addresses, phone numbers, sometimes dates of birth or partial card details. So the risk is not somebody logging in as you — it is somebody contacting you with enough real detail to be believed. Check which of these sets hold your address, turn on two-factor authentication on your email, and treat any call or message about a breach, a refund or a settlement as unverified until you have called back on a number you already had.
Companies named so far
Newest first, by the date the published records reached public breach databases — which is usually weeks or months after the intrusion itself. Each page lists the exposed data categories for that company and lets you check whether your email is in it. The most recent addition is Alcon.
Record counts are unique email addresses in each published set, not headcounts of people — one person can appear in several sets, and in more than one row of the same set. The list is rebuilt from our breach catalogue, so it grows as new sets are indexed.
See what a caller could already put together about you
Leaked records get dangerous when they are matched with a current address and phone number. PersProtect finds where yours are published across 499 broker and people-search sites and files the removals for you. Start with a free scan.
Check my exposure — free →1. What “pay or leak” means in practice
There is no encryption in this one and nothing stops working. The attackers get into a company’s systems, copy whatever customer or staff records they can reach, and leave. Then comes a private demand with a deadline, and when the deadline passes without payment the files go up publicly. From the outside you usually see nothing until that last step, which is why the first many people hear of it is a set of records appearing with their name in it. The practical difference from a ransomware attack is that the harm lands on the people in the files rather than on the company’s operations, and it arrives weeks after the break-in rather than the same day.
2. The way in was usually a phone call
Across the notices these companies have published, the recurring entry point is not malware but a conversation. Someone rings a help desk or an employee, sounds like internal IT or a supplier, and talks the person on the other end through a sign-in or a password reset. Abbott described exactly that pattern after the intrusion into its Exact Sciences business: staff were phoned and talked out of single sign-on access. It matters to you for one reason. The same technique that got into these companies is the technique that will be aimed at you with the data that came out of them, and it works on attention rather than on software.
3. Why the same person turns up in several of these
Look down the list and there is no industry pattern: a fashion retailer, a cable company, an insurer, two colleges, a travel agency, an eye-care manufacturer. What they share is the kind of system they were storing contacts in, not the kind of business they run. So a single email address that has shopped, insured a car, enrolled a child and booked a work trip can sit in four of these sets at once. Each one on its own is a partial picture. Together they are a fairly complete one, and that is the realistic thing to plan around rather than any single company’s notice.
4. What is actually in the files
Identity, mostly. Names, email addresses, phone numbers and postal addresses run through nearly all of them, with dates of birth, purchase histories, partial card details or insurance information appearing in some. Passwords are rare, because these were not login databases. That changes what the exposure is worth: nobody can log in as you with this material, but anyone can sound like they already know you. A caller who has your address, the last four digits of your card and the name of the company you actually pay is past the point where most people start checking.
5. Assume the contact, not the login
The single rule that covers almost every follow-on approach: never continue a conversation that somebody else started. Hang up, close the email, and go back through a number or an address you already had — the one printed on your card, your statement or the company’s own site. Anyone genuine is fine with that. Beyond it, turn on two-factor authentication on your email and banking, because email is the account that resets all the others, and stop using the same password anywhere it still repeats. If a date of birth or a Social Security number was in the set that holds you, freeze your credit at all three bureaus as well.
6. Expect the second wave, aimed at victims
Every large published set is followed by people working it. The recurring scripts are a message about a settlement or compensation that asks you to confirm bank details, a fake claim site standing up within days of any real lawsuit, an offer of identity protection that collects exactly the data that leaked, and a call offering to “secure” your account that ends with a one-time code being read aloud. Some victims of these sets have also had extortion emails sent directly to them, quoting their own leaked details as proof. None of that needs a reply. Real claim processes run through a court-appointed administrator and are announced on the company’s own breach page — our guide to settlement claims covers how to tell one from a fake.
7. Shrink the half of your profile that is still in your control
None of the published records can be pulled back. What can be cut is the public layer that makes them workable — the people-search and data-broker sites listing your current address, phone number, age and relatives, which is what lets someone combine a stale record from one of these sets with a live phone number for you today. Removing that does not undo any breach and it does make the follow-up materially harder. Our data-broker opt-out guide has the free, site-by-site route, and what to do after a data breach covers the general order of operations.
The “pay or leak” breaches, answered
I have never had an account with that company. Why is my email in its breach?
Several names on this list are not consumer brands at all. A property-management firm, a commercial-security contractor, a school records platform, a distributor of air-conditioning parts — none of them sell to you directly, and all of them end up holding your details because someone you did deal with passed them along. Your landlord, your employer, your child’s school district or a shop that installed something in your home is the link. There is no account to close in those cases and no password to change, which is why the response below is about the follow-up contact rather than about logins.
Did any of the companies pay?
A few have said publicly that they refused, most have said nothing either way, and there is no reliable way to tell from the outside. What the pattern shows is that the data ended up published for every company on this list, whether or not money changed hands. Treat a demand like this as a disclosure event from the first day rather than something a payment can undo — files that have been copied stay copied.
Can I check whether I am in one of these sets?
For most of them, yes: the published records have been indexed by the breach databases our free check runs against, so a single lookup tells you which of these names hold your address. The exception is anything with health data in it. Those sets are deliberately kept out of public email lookups so that nobody can type in a neighbour’s address and learn something medical about them, so no tool will confirm the Exact Sciences set for you — ours included.
Is this one group of people?
The name has been attached to different crews and different tactics for years, and security reporting has repeatedly described it as a label that gets picked up and reused rather than a fixed roster. For anyone whose data is in one of these sets, that argument does not change much. The method is consistent, the sets keep appearing, and the exposure is identical whoever is behind the keyboard.
Are the passwords in these sets?
Mostly not, and that is what people get wrong about this campaign. These are records lifted out of business systems — customer lists, contact databases, support and billing records — rather than login tables, so what comes out is name, email, phone number, postal address, sometimes a date of birth or the last four digits of a card. Changing your password is still worth doing where you had an account, but it is not the defence here. The material is the kind that makes a stranger sound like they already know you.
Will I get a letter about it?
Often yes, and often late. Notification duties depend on which state you live in and what category of data was involved, and a company working through a set of several hundred thousand records can take months to send anything. Some of the companies here published a notice on their own site and never wrote to individuals at all. If the set holding your address is already public, waiting for the post is the slowest way to find out.
Does a credit freeze help with this kind of breach?
It helps against one specific outcome — somebody opening an account in your name — and it is free at all three bureaus, so it is worth doing if a date of birth or a Social Security number was in the set. It does nothing about the more likely outcome here, which is contact: a caller or an email that quotes a real order, a real address or a real policy number to get you to hand over something new. Those two risks need different responses, and most people only cover the first one.
The files are out. Your live details do not have to be.
See which sites are publishing your address, phone and relatives right now — free, in about a minute.
Run a free exposure scan →