Ransomware Group Qilin Claims Attack on iPic

A ransomware group calling itself Qilin claims to have carried out a cyberattack against iPic, with the claim reportedly posted to the group’s dark-web leak site on or around August 21, 2026. This claim comes from an entry on the group’s own extortion listing, which was tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. At this time, the claim is unverified: iPic has not issued any public confirmation, and no regulator has confirmed that an incident occurred. BreachLetter is reporting on the existence of the claim itself, not on the underlying facts of any breach.

What we know — and don’t
  • A group calling itself Qilin listed iPic on its leak site with a claimed attack date of August 21, 2026.
  • iPic operates in the ‘other’ sector category; no further business-activity detail has been independently verified as part of this claim.
  • The specific types of data the group claims to have obtained have not been disclosed or confirmed — no record counts, file types, or categories of information have been made public.
  • iPic has not issued a statement confirming or denying the claim as of this writing.
  • No regulatory filing or breach notification tied to this claim has been identified.
What should you do if you have an account with this company?
  • Change your password for any account associated with iPic, and avoid reusing that password on other sites.
  • Enable two-factor authentication (2FA) wherever iPic or related services offer it.
  • Be alert for phishing emails, texts, or calls that reference iPic, an order, or a claimed data incident — attackers often use these events as bait.
  • Monitor your bank and card statements for unfamiliar charges if you’ve made purchases through iPic.
  • Consider signing up for an identity monitoring service such as a service like Aura or LifeLock to get alerted if your personal information turns up somewhere it shouldn’t.
  • Avoid clicking links in unsolicited messages claiming to offer more details about this incident; go directly to iPic’s official website or verified customer support channels instead.

This claim remains unverified. BreachLetter will update this page if iPic confirms the incident, issues a public statement, or if the matter is officially reported to regulators.

Leave a Comment