Ransomware Group ‘Falcon’ Claims Attack on Hayward Holdings

A ransomware group calling itself Falcon claims to have carried out an attack against Hayward Holdings, with the claim dated August 31, 2026. This claim comes from a listing on the group’s own leak site, which is monitored by ransomware.live, a security research platform that tracks the public extortion pages of ransomware groups. At this time, the claim is unverified: Hayward Holdings has not confirmed any incident, and no regulator has issued any statement regarding this matter.

What we know — and don’t
  • A group calling itself Falcon listed Hayward Holdings on its leak site with a claimed date of August 31, 2026.
  • Hayward Holdings operates outside the finance, legal, education, retail, and healthcare sectors, and is categorized here as ‘other.’
  • The specific types of data the group claims to have obtained have not been disclosed in the listing and have not been independently confirmed.
  • No official confirmation from Hayward Holdings or any regulatory body has been made public as of this writing.
  • Claims made on ransomware leak sites are statements from the criminal group itself and should be treated with appropriate skepticism until verified.
What should you do if you have an account with this company?
  • Change your password for any account associated with Hayward Holdings, and avoid reusing that password on other sites.
  • Enable two-factor authentication (2FA) wherever it is offered, ideally using an authenticator app rather than SMS.
  • Be alert to phishing emails, texts, or phone calls that reference Hayward Holdings or claim to be following up on a security incident — do not click links or share credentials in response to unsolicited messages.
  • Monitor your bank and credit card statements for unfamiliar charges, and consider placing a fraud alert or credit freeze if you notice suspicious activity.
  • Since ransomware claims can precede the exposure of personal information, consider using a service like a service like Aura or LifeLock to monitor for identity theft and get alerted if your data appears in unexpected places.

BreachLetter will update this page if Hayward Holdings confirms this incident, or if it is officially reported to regulators or affected individuals.

Leave a Comment