Daricon.com, a company that supports military operations for the US, Canada, and NATO, suffered a ransomware attack by the incransom group. Approximately 400 GB of data was stolen. The breach occurred on February 25, 2026, and was discovered the following day.
The compromised data includes correspondence with NATO and US Army employees, confidential documents, signatures of NATO generals, their passport addresses, shipment information to various countries, photos, videos, drawings, personal data, and emails of employees from various US and NATO armies. Additionally, phone numbers and contracts with the Canadian and US Army were exposed. Documentation on other companies involved in oil operations in Iraq, Uganda, and elsewhere was also compromised. There is no confirmation of SSN, medical, or financial data exposure. The number of affected individuals has not been publicly disclosed.
This is an early-reported incident, and official disclosures from Daricon.com or regulatory bodies have not yet been made. Details regarding the full scope and impact of the breach may emerge later, and official notices may be delayed.