In June 2026, JAG Group experienced a data breach claimed by the Stormous ransomware group. The breach led to a full data dump that included corporate emails, Active Directory domain logins, and clear plain-text passwords. The exposed data also contained complete Microsoft Dynamics GP databases, software license keys, financial reports, system configuration files, SQL server connection data, and internal project management sheets. No official breach notification letter or statement from JAG Group has been publicly released.
The confirmed data types involved financial information such as financial reports, revenue sheets, general ledger accounts, and Profit and Loss statements. There is no evidence of SSN or medical data being compromised. The number of affected individuals remains unconfirmed. The company's public trading status and revenue are unknown.
Details about data breaches can emerge over time, and notifications to affected individuals may be delayed.