A Daily Dark Web report published on September 5, 2025, claims the Lynx ransomware group added 15 new victims to its data leak site on September 4, 2025. The report states the alleged attack spans multiple continents and targets various industries, including technology, manufacturing, municipal governments, and hospitality. The report claims the cybercriminal group exfiltrated sensitive data and provided "Proof" of the breaches to pressure victims into paying a ransom. The entities named are FirstLight, Ziegler-Design, Elektro-Buder, Simmons Boardman, Six Guns LLC, Pesado Construction, HighDoc, Medway Plastics, Denray Tire, Metro Technology Centers, City of Batavia, Volanno, Bemac-Merivale, Primax, and Ona Hotels.
Specific data types confirmed as exfiltrated and the exact number of affected individuals for each entity have not been publicly confirmed. There is no verified information available regarding potential SSN, medical, or financial data exposure. Details about official notifications to consumers or regulators, or whether these incidents involved vendor breaches, also remain unclear. The report does not specify which states or countries were affected or provide any additional information to corroborate the claims.
While the Daily Dark Web report indicates alleged breaches, no verified information from authoritative sources, such as state Attorney General sites or company statements, confirms these incidents. Details can emerge later, and notices to affected individuals may be delayed.