A ransomware group calling itself ShinyHunters claims to have obtained data belonging to Neogen Corporation, according to a listing on the group’s leak site dated 2026-08-29. This claim has not been verified by Neogen Corporation, and no regulator has confirmed the incident. The listing was tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites, and independent confirmation from Neogen or law enforcement has not been reported at this time.
What we know — and don’t
- ShinyHunters posted a claim referencing Neogen Corporation on its leak site, with a claimed date of 2026-08-29.
- Neogen Corporation operates in a sector categorized here as ‘other’, reflecting its general business activity.
- The specific types of data ShinyHunters claims to have obtained — such as personal, financial, or operational information — have not been disclosed in the listing and have not been confirmed by any party.
- Neogen Corporation has not issued a public statement confirming or denying this claim as of this writing.
- No regulatory filing or breach notification tied to this claim has been identified so far.
What should you do if you have an account with this company?
- Change your password for any account associated with Neogen Corporation, and avoid reusing that password elsewhere.
- Enable two-factor authentication (2FA) wherever it is offered, particularly on email and financial accounts.
- Be cautious of unsolicited emails, texts, or calls referencing Neogen Corporation, as criminals often exploit breach claims to run phishing campaigns.
- Monitor your bank and credit card statements for unfamiliar activity in the weeks following any claimed incident.
- Consider using identity monitoring services like a service like Aura or LifeLock to get alerted if your personal information appears in places it shouldn’t.
- Keep an eye on official communications from Neogen Corporation for any updates or notification letters.
BreachLetter will update this page if Neogen Corporation confirms this incident, issues a public statement, or if the matter is officially reported to data protection regulators.