Direwolf listing names Lightcast
A ransomware tracking site recorded a Direwolf leak-site listing that names Lightcast. The listing is an attacker claim, not confirmation that Direwolf breached Lightcast, stole data or encrypted systems.
- Report priority
- High
- Involves
- Lightcast
- Group
- Direwolf
What is known
- The listing alleges data theft but doesn't explain how access was obtained.
- It doesn't independently establish that Lightcast was compromised.
What to do
Employees should ask Lightcast's IT or security team whether the claim has been confirmed and whether their accounts or records were involved. Customers and partners should ask their usual Lightcast representative or their own organization's privacy contact whether their records were involved and what action they should take. A missing notice doesn't prove that your information was unaffected.
Ask Lightcast through your usual contact for confirmed guidance. Have your IT or privacy team verify that any incident message is authentic before following its instructions.
Reported details
Tracking identifier: RANSOM-direwolf-lightcast. Ransomware.live recorded the Lightcast entry under Direwolf on September 7, 2026 at 14:27 UTC and gives the same date as its estimated attack date. The tracker warns that the entry may duplicate another record, while noting that separate attacks can sometimes look like duplicates. The listing is an unverified claim of data theft, not independent confirmation of an intrusion or encryption.