Ransomware Group Claims Attack on Merge

A ransomware group calling itself Direwolf claims to have carried out an attack on a company identified as Merge, with the claim reportedly dated August 10, 2026. This claim comes from an entry on the group’s own dark-web leak-site listing, which is tracked and archived by ransomware.live, a security research platform that monitors public statements made by ransomware groups. At this time, the claim is unverified: it has not been confirmed by Merge, and no regulator or independent investigator has substantiated it. BreachLetter is reporting on the existence of the claim itself, not on any confirmed breach.

What we know — and don’t
  • A group calling itself Direwolf listed Merge on its leak site, with a claimed date of August 10, 2026.
  • Merge’s sector is classified here as ‘other’ based on available information; this classification may be refined as more details emerge.
  • The specific types of data the group claims to have obtained — such as personal, financial, or operational records — have not been disclosed in the listing and have not been independently confirmed.
  • No official statement from Merge confirming or denying the incident is currently available.
  • No regulatory filing or public breach notification tied to this claim has been identified as of publication.
What should you do if you have an account with this company?
  • Change your password for any account associated with Merge, and avoid reusing that password elsewhere.
  • Enable two-factor authentication (2FA) wherever it is offered, particularly on email and financial accounts.
  • Be cautious of unexpected emails, texts, or calls referencing Merge, especially any asking you to click a link, verify account details, or make a payment.
  • Monitor your bank and credit card statements for unfamiliar activity in the coming weeks.
  • Consider signing up for an identity monitoring service like a service like Aura or LifeLock to get alerted if your personal information appears somewhere it shouldn’t.
  • Keep records of any suspicious communications in case they are needed later for reporting to your bank or relevant authorities.

BreachLetter will update this page if Merge confirms this incident, if it is officially reported to regulators, or if further verified details come to light.

Leave a Comment