On February 28, 2026, the NightSpire ransomware group claimed responsibility for a cyberattack on GoHighLevel, a US-based technology company. The attack was estimated to have occurred around February 21, 2026. The specific types of data exposed have not been made available to the public, with NightSpire's statement indicating "Data is not available now."
Threat intelligence suggests that 7,626 users and 13 employees were compromised, along with 15 third-party employee credentials. The involvement of specific data types such as SSN, medical, or financial data has not been publicly confirmed. Official breach notification letters from GoHighLevel, company statements, and State Attorney General filings have not yet been disclosed.
This is an ongoing incident, and additional information regarding official notifications, regulatory filings, and litigation may become available as the situation develops.