Ransomware victim disclosure
← All victimskyyba.com
Claimed by Unsafe · listed 6 hours ago
Status timeline
- ListedSep 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Unsafe
- Status
- Data leaked
- Country
- Finland
- Sector
- Technology
- Listed on leak site
- Sep 21, 2026
About the victim
AI dossier — public-source company profileKyyba is a global technology and consulting organization specializing in digital transformation, AI modernization, and legacy system migration for government, healthcare, and automotive sectors. Operating offices in the USA and India, the company provides services including IAM, data engineering, document processing, and staffing.
- Industry
- Technology Consulting & Digital Transformation
- Address
- USA and India offices (specific address not provided)
Attack summary
Severity: high — Alleged exfiltration of client repositories and data with credible access indicators (AWS S3 compromise, contact form access). Kyyba serves government, healthcare, and financial sectors, suggesting potential exposure to sensitive regulated data. No actual proof files published yet, but threat credibility is elevated by specificity of attack vectors.The 'unsafe' group claims to have compromised Kyyba's systems and threatened to leak client repositories and data incrementally. The group claims to have left contact information on an AWS S3 bucket and the company's contact form.
Data the group says was taken
AI dossier — extracted from the leak post- client repositories
- client data
- AWS S3 contents
What the group claims
Revenue: $53.1 million
The leak post
captured from the group's site``` All your client respostitories and data will be leaked one by one. Get in touch with me via the link I left you on your aws S3 or Contact form on the blog ```
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

