On 22 May 2026, the ransomware group known as Genesis claimed responsibility for a data breach affecting an unnamed US entity, as reported on the ransomware monitoring platform ransomware.live. The…
Ransomware: qilin claims Semgrep (US) — Technology
BREACH. Sourced from ransomwarelive, summarised by Matproof.
AI Analysis
What changed and what to do.
A new ransomware incident has been publicly claimed by the Qilin group, targeting the US-based technology firm Semgrep. The claim was published on the ransomware.live leak site on May 22, 2026, under the BREACH framework. This indicates that the threat actor has allegedly exfiltrated data and is now applying pressure for payment. The specific nature of the compromised data has not been disclosed, but the incident underscores the ongoing risk of extortion-driven cyberattacks against technology companies.
Organizations in the technology sector, particularly those providing software development or security tools, are directly affected. However, any EU entity that relies on Semgrep’s services or shares data with them may face indirect supply chain risks. Compliance teams should also note that this incident may trigger notification obligations under GDPR if personal data of EU residents is involved, as well as potential reporting requirements under sector-specific frameworks like NIS2 or DORA.
Compliance teams should immediately verify whether their organization has any data-sharing or vendor relationship with Semgrep. If so, they should request a breach notification and assess the potential impact on personal data. Additionally, teams should review their incident response plans to ensure they can quickly assess third-party breaches and meet regulatory deadlines for reporting to supervisory authorities. Proactive vendor risk assessments and updated ransomware playbooks are strongly recommended.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More BREACH updates
Latest in BREACH.
On May 23, 2026, a ransomware incident involving the ShinyHunters group was reported against Baker Distributing Company, a US-based business services firm. The breach was published on the…
On May 23, 2026, a ransomware group known as ShinyHunters publicly claimed responsibility for a data breach affecting Charter Communications, Inc., a major U.S. telecommunications provider. The claim…
On May 23, 2026, a ransomware group known as ShinyHunters claimed responsibility for a data breach targeting DentaQuest.com, a U.S.-based healthcare organization. The incident was published on the…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.