Ransomware victim disclosure
← All victimsHayward Holdings, Inc.
listed as Hayward Holdings · Claimed by Falcon · listed 16 days ago
Status timeline
- ListedAug 31, 2026
- Data leakeddate unknown
At a glance
- Group
- Falcon
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Aug 31, 2026
About the victim
AI dossier — public-source company profileHayward Holdings is a publicly traded manufacturer and distributor of pool and spa equipment, listed on the NYSE under ticker HAYW. The company produces equipment and supplies for the swimming pool and spa industries.
- Industry
- Pool & Spa Equipment Manufacturing
Attack summary
Severity: critical — Confirmed exfiltration of large-scale PII (1M+ customer and business records), sensitive financial data, privileged credentials, and strategic business information from a publicly traded company. Data has been published. Scale and sensitivity of regulated personal data elevates to critical.Falcon claims to have exfiltrated approximately 848 GB of data from Hayward Holdings, including Salesforce databases, over 1 million business and customer records with PII, financial records, personnel files, IT infrastructure details, and privileged credentials. The group has published this data.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce database
- Business records (1M+)
- Customer records with PII (1M+)
- Distributor pricing lists
- Margin structures
- Financial records
- P&L statements
- Accounting ledgers
- Personnel files
- IT infrastructure blueprints
- Privileged account credentials
- Strategic board materials
What the group claims
Pool & spa equipment · NYSE: HAYW - Our 848 GB extraction includes your Salesforce, 1+ million of each business and customer records with PII, distributor pricing lists, margin structures, detailed financial records, P&L statements, accounting ledgers, extensive personnel files, IT infrastructure blueprints, privileged account credentials, strategic board preparation materials and much more.
Sources
Source
Indexed 16 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

