2026 APTIM — CoinbaseCartel ransomware claim (Apr; unverified in open sources)
Data compromised
Unknown pending vendor or law-enforcement confirmation
Technical writeup
In late April 2026, OSINT trackers and niche ransomware blogs (e.g., RedPacket-style victim pages, HookPhish/Dexpose summaries) listed global engineering and environmental services firm APTIM in connection with the actor persona “CoinbaseCartel” and double-extortion–style marketing. Analytic commentary in the same channel ecosystem cautioned that some victim listings can be unverified or recycled. As of the April 23–24, 2026 posting window, BreachHistory did not locate an APTIM press release or major mainstream outlet confirmation matching the same detail level as concurrent ADT/retail-breach coverage; the row documents extortion-claim presence for threat-intelligence indexing.
Root cause
Alleged ransomware / data-leak extortion (unconfirmed by independent mainstream disclosure at row creation)