Ransomware victim disclosure
← All victimsPresentations.AI
Claimed by Unsafe · listed 21 days ago
Status timeline
- ListedAug 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Unsafe
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Aug 10, 2026
About the victim
AI dossier — public-source company profilePresentations.AI is an AI-powered SaaS platform that automatically generates professional presentation slide decks from various input formats (text, documents, URLs, PDFs). The platform serves over 12 million enterprise users and teams globally, offering tools including an AI Presentation Maker, Pitch Deck Generator, and slide templates. The company is SOC 2 Type II certified and GDPR compliant.
- Industry
- Software as a Service (SaaS) / Artificial Intelligence
Attack summary
Severity: critical — Claimed exfiltration of personally identifiable information at massive scale (10 million users) from a widely-used SaaS platform serving enterprise clients. The data includes user records and client information, constituting sensitive personal data exposure affecting millions globally.The ransomware group 'unsafe' claims to have exfiltrated data regarding 10 million users and enterprise clients from Presentations.AI and pitchdeck.io. The group offers decryption keys in exchange for contact, implying encryption of infrastructure backups alongside data theft.
Data the group says was taken
AI dossier — extracted from the leak post- user account data (10 million users)
- enterprise client information
- infrastructure snapshots/backups
What the group claims
Revenue: $5 million
The leak post
captured from the group's site``` www.presentations.ai and www.pitchdeck.io Sumanth Raghavendra and Ravi Kasthuri Data regarding 10 million users and enterprise clients has been downloaded and saved to my backups. If you need the decryption keys for all your snapshots, contact me to restore your infrastructure. ```
Screenshot of the leak post

Sources
Source
Indexed 21 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

