Breach: CTT (468,124 accounts) — Email addresses, Names, Phone numbers
Unverified claim published by a ransomware group, mirrored from hibp. Not confirmed by Matproof or by the named organisation.
Unverified claim
What was claimed, and what to do.
This is not a confirmed breach. This entry records that a ransomware group posted a claim on its own leak site. Matproof has not verified the claim and does not assert that any incident occurred. Such claims are often exaggerated, false, misattributed, or refer to a third party rather than the named organisation. The named organisation has not confirmed it.
If you represent a named organisation and this entry is inaccurate, email legal@matproof.com and we will correct or remove it.
On 2026-04-26, Have I Been Pwned published a listing attributed to a ransomware group's leak site, claiming an incident involving CTT and 468,124 accounts. The posting alleges exposure of email addresses, names, and phone numbers. CTT has not confirmed this claim. Leak-site claims are frequently exaggerated, false, or misattributed, and may refer to a third party rather than the named organisation.
Compliance teams should treat this as unverified. Contact CTT directly and request a written statement addressing the claim. Do not act on it as a confirmed incident, notify customers, or escalate internally until the organisation provides clarification. No further action is warranted based solely on the posting.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.