On July 23, 2026, the Killsec ransomware group announced on its leak site that it had exfiltrated internal files from CashCowboy. This disclosure was made by the ransomware group itself, not by CashCowboy.
The available reporting does not specify the types of data exposed within the internal files, nor does it provide a confirmed number of affected individuals. It is unclear if names, SSNs, medical data, financial data, credentials, or other personal information were compromised. Official breach notifications, company statements, state attorney general filings, or information regarding the number of individuals notified have not been publicly found.
Details surrounding the CashCowboy data breach, including the full extent of data compromised and the number of individuals affected, may emerge as further investigation occurs.