Direwolf listing names Lightcast

Published September 7, 2026

A ransomware tracking site recorded a Direwolf leak-site listing that names Lightcast. The listing is an attacker claim, not confirmation that Direwolf breached Lightcast, stole data or encrypted systems.

Report priority
High
Involves
Lightcast
Group
Direwolf

What is known

  • The listing alleges data theft but doesn't explain how access was obtained.
  • It doesn't independently establish that Lightcast was compromised.

What to do

Employees should ask Lightcast's IT or security team whether the claim has been confirmed and whether their accounts or records were involved. Customers and partners should ask their usual Lightcast representative or their own organization's privacy contact whether their records were involved and what action they should take. A missing notice doesn't prove that your information was unaffected.

Ask Lightcast through your usual contact for confirmed guidance. Have your IT or privacy team verify that any incident message is authentic before following its instructions.

Reported details

Tracking identifier: RANSOM-direwolf-lightcast. Ransomware.live recorded the Lightcast entry under Direwolf on September 7, 2026 at 14:27 UTC and gives the same date as its estimated attack date. The tracker warns that the entry may duplicate another record, while noting that separate attacks can sometimes look like duplicates. The listing is an unverified claim of data theft, not independent confirmation of an intrusion or encryption.