Ransomware victim disclosure
← All victimsJag Group
listed as jaggroup.com UPDATE-FULL DATA DUMP · Claimed by Stormous · listed 6 hours ago
Status timeline
- ListedJun 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Stormous
- Status
- Data leaked
- Listed on leak site
- Jun 21, 2026
About the victim
AI dossier — public-source company profileJag Group is a company operating under the domain jaggroup.com. Limited public information is available; the company appears to use Microsoft Dynamics GP for enterprise resource planning.
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive data: Active Directory credentials with plain-text passwords, financial reports, and complete database backups represent severe exposure of authentication mechanisms, financial information, and operational systems. The presence of database credentials and configuration data amplifies risk of secondary compromise.Stormous claims to have exfiltrated a full database containing corporate emails, Active Directory credentials with plain-text passwords, Microsoft Dynamics GP databases, financial reports, software licenses, project management files, and SQL server connection data.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate email accounts
- Active Directory domain credentials
- Plain-text passwords
- Microsoft Dynamics GP databases
- Financial reports
- Software license keys
- System configuration files
- SQL server connection data
- Project management spreadsheets
- User listings
- Purchasing and sales logs
What the group claims
Full database containing corporate emails (@jaggroup.com), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (zBackups.zip, wetransfer packages), SQL server connection data, and IM.mdb database files.Internal project management sheets (Jag Project.xlsx), user listings, purchasing, and sales import logs.
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

