Ransomware victim disclosure
← All victimsCrosslists Data
Claimed by Akira · listed 4 months ago
Status timeline
- ListedJan 29, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jan 29, 2026
- Data size
- 21 GB
About the victim
AI dossier — public-source company profileCrosslists Data is a US-based company specializing in providing high-quality new business data for marketers. Their services include custom segmentation and data acquisition, serving a diverse clientele that includes publishers and non-profits. No public website was available to verify additional details.
- Industry
- B2B Marketing Data & List Services
Attack summary
Severity: critical — The exfiltration claim includes regulated PII (passports, driver's licenses) for employees and financial/accounting data belonging to customers, combined with a confirmed 21 GB data publication, constituting a critical-level breach of sensitive personal and financial information.Akira claims to have exfiltrated approximately 21 GB of corporate data from Crosslists Data, including employee personal information (passports, driver's licenses, addresses), customers' financial and accounting files, contracts, agreements, NDAs, and other confidential documents.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driver's licenses
- Employee addresses and personal information
- Customer financial and accounting files
- Contracts and agreements
- NDAs
- Confidential corporate files
What the group claims
Crosslists Data specializes in providing high-quality new busines s data for marketers across the country. Their services include c ustom segmentation and data acquisition, catering to a diverse cl ientele that includes publishers and non-profits. We will upload 21gb of corporate data soon. Employee personal inf ormation (passports, DLs, address and so on), customers' financia l and accounting files, contracts and agreements, confidential fi les, NDAs and so on.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

