LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › AdScale Listed by coinbasecartel Ransomware Group

HIGH severityUnverified claimHow we verify

AdScale Listed by coinbasecartel Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 15, 2025
AdScale Listed by coinbasecartel Ransomware Group

Reported September 15, 2025.

HIGH
Severity
September 15, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

AdScale has been listed by the coinbasecartel ransomware group, with internal files reported exfiltrated; the incident was disclosed on September 15, 2025, though the actual date of the intrusion remains unknown. Individuals are advised to check whether their information may have been exposed and to take any recommended protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to list companies on dark-web leak sites as a pressure tactic, turning claims of data theft into public leverage even when independent confirmation remains limited. In this environment, a listing can surface long before full details of scale, method or impact are known, leaving customers and partners to weigh incomplete information against real risks of exposure.

On 15 September 2025 AdScale, an AI-driven advertising platform for e-commerce and digital marketers, was listed by the ransomware group coinbasecartel. The group claims internal files were exfiltrated in a ransomware attack. The number of people affected is unknown, and public detail beyond the listing itself is limited. The incident matters because advertising platforms routinely process campaign data, account credentials and business information that can be misused if they leave the organisation’s control.

What happened

According to the public record, AdScale was listed by the coinbasecartel ransomware group on 15 September 2025. The listing asserts that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access vector, the precise date of intrusion, the volume of data taken, or any ransom demand—have been disclosed in the available facts. The number of individuals potentially affected remains unknown. At present the listing stands as an unverified claim by the group; independent confirmation of the breach’s full scope has not been provided in the public summary.

Inside coinbasecartel

coinbasecartel is a ransomware operation that follows the now-familiar double-extortion model: encrypt systems and simultaneously claim to have stolen data, then threaten to publish the material on a dedicated leak site if payment is not made. Like other groups in this category, it typically posts victim names, sample files or brief descriptions to demonstrate access and to increase pressure. Public reporting on the group has noted its use of standard ransomware tooling and leak-site announcements rather than novel techniques unique to any single campaign. In the present case the group claims AdScale’s internal files were taken; no additional statements or sample data specific to this victim have been detailed in the available facts, so the listing itself remains the sole public assertion.

About AdScale

AdScale is described as an AI-driven advertising platform built for e-commerce businesses and digital marketers. It offers unified campaign management across major advertising networks, helping clients plan, launch and optimise paid campaigns from a single interface. Organisations of this type typically hold customer account details, campaign performance data, billing information, API credentials and internal operational files. Because the platform sits between brands and large advertising ecosystems, a compromise can affect not only AdScale’s own systems but also the marketing operations of the merchants and agencies that rely on it. A ransomware incident therefore carries consequences that extend beyond the company itself into the wider digital-advertising supply chain.

What data was at risk

The available facts state only that internal files were exfiltrated in a ransomware attack. No specific categories—such as customer lists, payment records, employee data or campaign credentials—have been named. Advertising platforms of this kind commonly store account credentials, campaign configurations, performance metrics, contact details of marketers and merchants, and internal business documents. Whether any of those categories were among the files claimed by coinbasecartel is unconfirmed. Until more precise inventories are released, the exact contents of the exfiltrated material remain unknown.

What's at stake

For individuals whose information may have been present in internal files, the practical risks include targeted phishing, credential stuffing if login details were stored, and social-engineering attempts that reference legitimate advertising campaigns. Merchants and agencies that use the platform could face disruption to ongoing campaigns, unauthorised changes to ad accounts, or exposure of proprietary marketing strategies. For AdScale the stakes include operational downtime, reputational damage, potential regulatory scrutiny and the cost of investigation and remediation. Because the number of people affected is unknown and the precise data types are undisclosed, the full extent of these risks cannot yet be quantified; the listing alone is sufficient to warrant caution.

What to do if you're exposed

If you hold an account with AdScale or have shared business data through the platform, treat the listing as a prompt to act rather than as confirmed proof of personal compromise. Change passwords on any related accounts, enable multi-factor authentication where available, and monitor for unusual login activity or unexpected campaign changes. Review recent invoices and payment methods for anomalies. Be alert to phishing messages that reference advertising services or claim to come from AdScale. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Continue to watch for official statements from AdScale that may clarify the scope of the incident and any recommended next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAdScale security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See AdScale’s full breach history →

More recent breaches

GDEV Listed by coinbasecartel Ransomware GroupDecember 12, 2025Canias ERP Listed by coinbasecartel Ransomware GroupOctober 13, 2025Geno Bank Listed by coinbasecartel Ransomware GroupMarch 15, 2026Insight Listed by coinbasecartel Ransomware GroupDecember 20, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the AdScale Listed by coinbasecartel Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by coinbasecartel — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram