2026 Logitech / Streamlabs — ShinyHunters leak-site claim; "final warning" 21 Aug deadline (unverified)
Data compromised
Not specified in the listing — ShinyHunters says it will leak unspecified internal data. No field-level inventory or record count published by the actor or the company as of 19 August 2026.
Technical writeup
Unverified ransomware/extortion claim — 18 August 2026. ShinyHunters (tracked by Google as UNC6040) added "Logitech / Streamlabs" (logitech.com, Switzerland) to its Tor leak site with a "FINAL WARNING — PAY OR LEAK" notice and an ultimatum of 21 August 2026. No data sample, record count, or field list was published; the listing threatens "several annoying (digital) problems" if Logitech does not negotiate. Logitech had not issued a public statement confirming or denying the claim as of 19 August. ShinyHunters is the same group behind the 2025–2026 Salesforce vishing campaign (UNC6040), the RingCentral 1.6M HIBP load, the Medtronic 3.83M patient breach, and multiple other enterprise extortion incidents tracked on BreachHistory. Logitech has a prior cataloged 2025 breach (1.8 TB via zero-day on a third-party platform). It is unclear whether this August 2026 claim is new access or residual material from that earlier incident. companyConfirmed false; recordsAffected 0 pending company statement or data publication.
Root cause
Unverified ShinyHunters (UNC6040) ransomware/extortion claim posted 18 August 2026; leak-site ultimatum demands contact by 21 August or data release; Logitech had not confirmed at indexing
References
- https://www.ransomware.live/id/TG9naXRlY2gvIFN0cmVhbWxhYnNAc2hpbnlodW50ZXJz
- https://cypro.co.uk/insights/cyber-bulletins/shinyhunters-ransomware-claim-targets-logitech-and-streamlabs/
- https://www.dexpose.io/shinyhunters-compromises-logitech-streamlabs-in-latest-ransomware-attack/
- https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-logitech-streamlabs/