A ransomware group calling itself Qilin claims to have compromised systems belonging to Clear Align, according to a listing posted to the group’s own dark-web leak site. The claimed attack is dated August 23, 2026, and was identified by ransomware.live, a security research platform that tracks the public leak sites operated by ransomware groups. At this time, this is solely a claim made by a criminal group seeking publicity and leverage — it has not been verified by Clear Align, by any independent security researcher, or by any regulator.
What we know — and don’t
- A group calling itself Qilin listed Clear Align on its leak site, with a claimed date of August 23, 2026.
- Clear Align’s activities do not fall neatly into finance, legal, education, retail, or healthcare, and the sector is being tracked here as ‘other.’
- The specific types of data the group claims to have obtained have not been disclosed on the listing or confirmed by any party.
- Clear Align has not issued a public statement confirming or denying that an incident took place.
- No regulatory filing or breach notification related to this claim is currently known to exist.
What should you do if you have an account with this company?
- Change your password for any account with Clear Align, and avoid reusing that password on other sites.
- Turn on two-factor authentication wherever it’s offered, for this account and others tied to the same email address.
- Be cautious of unexpected emails, texts, or phone calls referencing Clear Align, especially ones asking you to click links or confirm personal details — these could be phishing attempts trying to exploit uncertainty around this claim.
- Keep an eye on your bank and credit card statements for any unfamiliar activity in the coming weeks.
- Since it is not yet known what data, if any, was actually accessed, consider using a service like a service like Aura or LifeLock to monitor for identity theft and get alerted if your personal information turns up somewhere it shouldn’t.
BreachLetter will update this page if Clear Align confirms this incident, if new details emerge from security researchers, or if the matter is reported to regulators.