Ransomware victim disclosure
← All victimsRyan, LLC.
Claimed by shinyhunters · listed 1 month ago
Status timeline
- Listed
Apr 12, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Apr 12, 2026
About the victim
AI dossier — public-source company profileRyan, LLC is a United States-based business services company. No public website content was available to confirm further operational details. The company appears to use Salesforce as a CRM platform, suggesting client-facing or data-intensive business operations.
- Industry
- Business Services / CRM Data Management
Attack summary
Severity: critical — Claimed exfiltration of 4.8 million records containing PII at scale from a Salesforce environment meets the critical threshold for regulated/sensitive data exposure; the volume and nature of the data (PII) and the threat of additional 'digital problems' elevate severity further.ShinyHunters claims to have exfiltrated over 4.8 million Salesforce records containing PII and internal corporate data, threatening to publish the data and cause additional 'digital problems' unless a ransom is paid by 14 April 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally Identifiable Information (PII)
- Internal corporate data
What the group claims
Over 4.8M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
