Late April 2026, niche ransomware and OSINT channels listed APTIM in connection with the persona CoinbaseCartel and double-extortion-style marketing. Analyst commentary in the same ecosystem cautioned that some victim listings can be unverified or recycled; as of the late-April posting window, BreachHistory did not locate an APTIM press release or major outlet confirmation at the same level of detail as concurrent ADT-style corporate disclosures. The database row documents threat-intelligence visibility, not a confirmed PII scale.
Canonical record: APTIM 2026 (extortion claim) on BreachHistory.
Sources: RedPacket Security, Dexpose