On July 28, 2026, leaksear.ch indexed 62,920 records from an alleged July 1, 2026 ShinyHunters extortion leak involving Ingram Content Group (leaksear.ch metadata). Ingram describes its business as services for publishers, retailers, libraries, and educators, including digital and physical book distribution, print-on-demand, and digital learning (www.ingramcontent.com).
What happened
Public reporting frames the incident as an alleged ShinyHunters extortion or ransomware listing on July 1, 2026. DeXpose reported that ShinyHunters claimed responsibility for a cyberattack and threatened to leak data after negotiations failed, while GalaxyWarden described the listing as an unverified threat-actor claim and said it had not independently validated what was taken (www.dexpose.io, www.galaxywarden.com).
ClassAction.org reported that attorneys were investigating reports of a possible Ingram Content Group breach and were seeking current or former employees, authors, publishers, and other affiliated individuals, while noting that the potential breach had not been confirmed by Ingram at the time of its post (www.classaction.org). The access method, source system, and final affected population remain unconfirmed in the public reporting reviewed.
Public row counts also differ. DataBreach.com lists an Ingram Content Group breach page at 80,190 rows, added July 8, 2026, while leaksear.ch currently indexes 62,920 records from the dataset (databreach.com) (leaksear.ch metadata).
What data was exposed
leaksear.ch indexing metadata lists the searchable fields as address, country, date of birth, email, IP address, name, phone number, and username (leaksear.ch metadata).
Additional non-searchable record context includes account name, company, department, title, website, lead source, owner name, status, created date, last activity, last modified date, record type, source system, and source identifiers (leaksear.ch metadata). These fields are consistent with CRM, contact, lead, and account-management data rather than a password dump.
DataBreach.com separately lists Social Security Number, email, phone number, name, and street address on its public breach page; because the Social Security Number field is not present in the leaksear.ch indexing metadata, researchers should treat that as a separate public reporting claim, not a leaksear.ch field assertion (databreach.com) (leaksear.ch metadata).
Why this matters
Names, emails, phone numbers, usernames, physical addresses, dates of birth, and CRM context can give attackers more credible lures for phishing, impersonation, and account-recovery fraud (leaksear.ch metadata). The separate public claim that Social Security numbers appear in another index of the alleged breach, if accurate for a given person, would raise the risk of identity-theft attempts (databreach.com). Security teams should review whether relevant employees, authors, publisher contacts, or partner contacts appear in the indexed leak and watch for targeted messages referencing Ingram or publishing-related business relationships. Readers who want to check their own exposure should use the exposure check that follows this section.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include address, country, date of birth, email, ip address, name, phone, and username.
Sources
- Ingram Content Group: Ingram Content Group adds Union Square & Co. for Digital Sales and Distribution
- DeXpose: ShinyHunters Target Ingram Content Group in Ransomware Attack
- GalaxyWarden: Ingram Content Group, Inc. Listed by shinyhunters Ransomware Group
- ClassAction.org: Ingram Content Group Data Breach? Lawyers Examine Hackers' Claims
- DataBreach.com: Ingram Content Group, Inc. | Search the Data Breach