Ransomware Group Qilin Claims Attack on PenLink

A ransomware group calling itself Qilin claims to have carried out an attack on PenLink, with the claim dated August 14, 2026. This information comes from an entry on the group’s own leak-site listing, which is tracked by ransomware.live, a security research platform that monitors ransomware groups’ public extortion sites. At this time, the claim is unverified: PenLink has not confirmed any breach, and no regulator has issued any statement regarding this incident.

What we know — and don’t
  • A group calling itself Qilin listed PenLink on its leak site, with a claimed date of August 14, 2026.
  • PenLink is categorized under the ‘other’ sector for the purposes of this listing.
  • The specific types of data allegedly accessed have not been disclosed by the group and have not been confirmed by PenLink or any independent party.
  • No official confirmation, regulatory filing, or public statement from PenLink has been identified at this time.
  • Claims made on ransomware leak sites are statements by criminal actors and are not independently verified evidence that an intrusion occurred.
What should you do if you have an account with this company?
  • Change your password for any account associated with PenLink, and avoid reusing that password on other sites.
  • Enable two-factor authentication (2FA) wherever it is offered, using an authenticator app rather than SMS if possible.
  • Watch closely for phishing emails, texts, or phone calls that reference PenLink or attempt to impersonate the company or its staff.
  • Avoid clicking on links or downloading attachments from unsolicited messages claiming to be related to this incident.
  • Consider signing up for identity monitoring, such as a service like Aura or LifeLock, to help spot any misuse of your personal information early.
  • Keep an eye on account statements and credit reports for any unfamiliar activity in the weeks ahead.

BreachLetter will update this page if PenLink confirms the incident, if new details emerge from credible sources, or if the matter is officially reported to regulators.

Leave a Comment