Ransomware victim disclosure
← All victimsHorizon Media
listed as horizonmedia.com · Claimed by chaos · listed 3 months ago
Status timeline
- Listed
Feb 9, 2026
- Data leaked
At a glance
- Group
- chaos
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Feb 9, 2026
- Data size
- 3.2 TB
About the victim
AI dossier — public-source company profileHorizon Media is one of the largest independent media agencies in the United States, headquartered in New York City. The company specializes in media planning, buying, and data-driven marketing services across television, digital, radio, and out-of-home channels. It serves a broad portfolio of major national and global brand clients.
- Industry
- Media Buying & Advertising Agency
- Employees
- 1001-5000
- Founded
- 1989
Attack summary
Severity: high — The group claims exfiltration of 3.2 TB of sensitive corporate data from a large independent media agency with significant client and business information; while regulated PII at scale is not explicitly confirmed, the volume and threatened distribution to regulatory bodies indicates significant business and potentially client data exposure.The Chaos ransomware group claims to have exfiltrated 3.2 TB of sensitive corporate data from Horizon Media and issued a 48-hour ultimatum to reach an agreement, threatening to publicly release the data and distribute it to global media outlets and regulatory bodies if terms are not met.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate data (3.2 TB)
- Sensitive business files
What the group claims
Official Announcement: Horizon Media Data Breach ULTIMATUM: Horizon Media has 48 hours to reach an agreement. If our terms are not met, a full leak consisting of 3.2 TB of sensitive corporate data will be made public and distributed to global media outlets and regulatory bodies. The leaked dataset…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
