The JAG Group, a U.S.-based entity, experienced a data breach in June 2026. The Stormous ransomware group claimed responsibility and posted data online on June 21, 2026, marking it as a direct breach of JAG Group's internal systems. This incident was listed on Ransomware.live. As of June 25, 2026, the company has not issued a public breach notification statement.
The breach involved corporate emails (@jaggroup.com), Active Directory (AD) domain logins, clear plain-text passwords, Microsoft Dynamics GP databases, software license keys, financial reports, system configurations, compressed archives, and SQL server connection data. The number of affected individuals is unconfirmed, but the inclusion of AD data suggests widespread username and password exposure across the organization. SSN or medical data exposure has not been explicitly confirmed. No public regulatory filings or class action lawsuits have been reported, and no customer notification campaign has been confirmed.
Details about data breaches can emerge over time, and official notices may be delayed.