LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › DIALLOG Listed by nova Ransomware Group

HIGH severityUnverified claimHow we verify

DIALLOG Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 27, 2025
DIALLOG Listed by nova Ransomware Group

Reported April 27, 2025.

HIGH
Severity
April 27, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

DIALLOG was listed by the nova ransomware group on April 27, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; individuals should check whether their information was exposed and take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

When a telecommunications provider appears on a ransomware group's leak site, the people who rely on that company for phone, internet or business connectivity face a practical problem: their personal details, account information or internal records may have left the organisation's control. For customers and staff of DIALLOG, the listing raises immediate questions about what was taken and what steps they should take next.

Public reporting on 27 April 2025 stated that DIALLOG had been listed by the nova ransomware group, which claimed to have exfiltrated internal files. The number of people affected remains unknown, and many operational details have not been disclosed. That uncertainty itself is part of the stakes for anyone whose data may be involved.

Inside the incident

According to the available record, DIALLOG was listed by the nova ransomware group on or around 27 April 2025. The group claimed that internal files had been exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published, and the precise timing of the intrusion, the method of initial access, and the full scope of systems involved remain undisclosed in public reporting.

What is known is limited to the leak-site claim itself and the characterisation of the material as internal files. No independent confirmation of the volume of data, the presence or absence of encryption on production systems, or any ransom demand has been included in the facts made available. In the absence of those details, the incident must be treated as an unverified claim of compromise pending further disclosure by the organisation or investigators.

Who is nova?

Nova is a ransomware operation that has appeared in public threat-intelligence reporting as a group that combines data theft with encryption threats—commonly described as double extortion. Like other actors in this category, it typically maintains a leak site on which it lists organisations it claims to have compromised, often posting samples or full archives if negotiations fail. Public analyses of the group have noted that it targets a range of sectors and that its listings function both as pressure and as advertising of capability.

In this case the group claims that DIALLOG was among its victims and that internal files were taken. That claim has not been independently verified in the material provided; it should be read as an assertion by the threat actor rather than as established fact. No statements attributed to nova beyond the listing and the description of exfiltrated internal files are part of the record for this incident.

DIALLOG and its sector

DIALLOG, also referred to as Diallog Telecommunications, is described as a Canadian-owned and operated telecom company based in Toronto and established in 1998. Telecommunications providers of this type typically manage customer account records, billing data, service-configuration details, network infrastructure information and employee records. They sit at the intersection of consumer services and critical communications infrastructure, which means a breach can affect both individual subscribers and the operational continuity of the services those subscribers depend on.

Because telecom operators hold identity, contact and sometimes payment-related information, and because they maintain systems that support voice and data connectivity, unauthorised access to their internal files carries consequences that extend beyond a single organisation. The sector is a known target for ransomware groups precisely because of the sensitivity of the data and the potential disruption to customers.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases or record counts has been disclosed. The number of people affected is listed as unknown.

Organisations in the telecommunications sector commonly hold customer names, addresses, phone numbers, account identifiers, billing histories, service plans and employee personnel data, as well as technical documentation related to network configuration. Whether any of those categories were present among the files claimed by nova has not been confirmed. Exact contents therefore remain unconfirmed; readers should treat any assumption about specific personal data as speculative until the organisation or competent authorities provide a verified inventory.

What's at stake

For individuals, the principal risks are misuse of personal or account information if it was among the internal files, including targeted phishing, identity fraud or unauthorised changes to service accounts. Because the scale is unknown, it is not possible to say how many people face that exposure. For the organisation, the stakes include potential regulatory scrutiny under Canadian privacy law, reputational damage, costs of investigation and remediation, and any operational disruption that may have accompanied the attack.

Even when encryption of production systems is not confirmed, the mere claim of data theft can erode customer trust and create long-term monitoring burdens for both the company and those whose information may have been involved. The absence of public detail on the precise data set leaves affected parties without a clear picture of residual risk, which itself is a practical harm.

What to do if you're exposed

If you are a customer, employee or partner of DIALLOG, treat the listing as a reason to take basic protective steps while waiting for any official notification. Practical first measures include:

Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. That check does not confirm or rule out involvement in this specific incident, but it provides a concrete starting point for personal risk assessment.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDIALLOG security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See DIALLOG’s full breach history →

More recent breaches

rawafid Listed by nova Ransomware GroupApril 23, 2025HELUKABEL Listed by nova Ransomware GroupApril 23, 2025​​​​agromate Listed by nova Ransomware GroupApril 22, 2025​​​​bettininformatica - suporteon Listed by nova Ransomware GroupApril 16, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the DIALLOG Listed by nova Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by nova — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram