Kessler Creative NEW Listed by Coinbase Cartel Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Kessler Creative NEW has been listed by the Coinbase Cartel ransomware group, with the incident disclosed on 22 August 2026. An undisclosed number of individuals had personal data exposed; anyone who may have been affected should check their accounts and follow official guidance.
Coinbase Cartel has listed Kessler Creative NEW on its leak site, according to a report dated August 22, 2026. The listing presents the organization in connection with advertising networks and cites a figure of $17.1 million; it does not establish how many people may be affected or which records, if any, were obtained. Kessler Creative NEW has not publicly confirmed the claim as of writing. Until a company statement, regulator notice, or other independent verification appears, the matter remains an unverified claim by a ransomware and extortion group.
Leak-site postings are a form of pressure. They can be accurate, inflated, recycled from older incidents, or false. For clients, partners, and staff who work with advertising and creative firms, the practical question is what to watch for if the claim later gains support—not to treat the listing itself as proof that data has already moved.
What the listing says
The public report states that Coinbase Cartel has listed Kessler Creative NEW and frames the entry under advertising networks with a $17.1 million figure. The number of people affected is unknown. Data types said to have been exposed are not disclosed. Timing of any intrusion, method of access, whether files were copied, and whether any ransom demand was made are not detailed in the material provided.
Nothing in the available summary confirms that a breach occurred, that systems were encrypted, or that a countdown or file sample was published. The listing is the group’s assertion. Independent confirmation from Kessler Creative NEW or from a regulator is not part of the record described here.
Who is Coinbase Cartel?
Coinbase Cartel is known publicly as a ransomware and extortion-style actor that uses leak sites to name organizations and threaten publication of material it claims to hold. Groups in this category typically blend intrusion, data theft claims, and public shaming to push payment. Their posts are marketing as much as evidence: volume claims, sector labels, and dollar figures are chosen to maximize pressure and attention.
Well-documented patterns for such crews include listing victims before or without proof, recycling older datasets, and describing industries in broad terms. For this specific entry, only what appears in the listing summary should be attributed to the group: that it has named Kessler Creative NEW, associated the name with advertising networks, and attached a $17.1 million figure. No further claims by Coinbase Cartel about this organization are established in the facts at hand.
Who is Kessler Creative NEW?
Kessler Creative NEW is identified in the report as operating in advertising networks—work that typically involves campaigns, creative production, media buying, and coordination among brands, agencies, and publishers. Firms in this sector often sit between clients and a wide set of vendors, freelancers, and platforms.
A claimed incident involving an advertising or creative business matters because such organizations commonly handle commercial contracts, campaign plans, contact lists, billing details, and credentials used to reach client systems or ad platforms. Even an unconfirmed listing can create uncertainty for clients who need to know whether their materials or accounts could be at risk if the claim were later substantiated. That consequence follows from the sector’s role, not from any verified event at this company.
What was likely exposed
The listing does not name exposed data types. Exact contents are unconfirmed. It is not established that any particular category of file or record left the organization.
If files were taken from a firm in advertising and creative services, organizations of this kind typically hold business contact information, email correspondence, project and campaign files, invoices and payment-related records, contracts, and sometimes login material or API access used with ad platforms and partners. They may also hold personal data of employees and contractors. None of that inventory is confirmed here; it is a conditional description of sector norms only. Readers should not assume their information was included.
The real-world impact
For individuals, the main risks if a claim of this type were true would be phishing and social engineering that reference real campaigns or colleagues, misuse of business email addresses, and attempts to reset accounts tied to work or vendor relationships. Financial fraud risk depends on whether payment details or identity documents were among any material obtained—something the listing does not specify.
For the organization, an extortion listing can disrupt client trust, trigger contractual notice obligations if a breach is later confirmed, and consume time in investigation and communication even when the underlying claim is disputed. Those are ordinary consequences of public accusation in this threat model. They do not prove that Kessler Creative NEW lost control of systems or data.
A leak-site name alone does not tell the public whether backups were affected, whether customers were contacted by attackers, or whether any sample was genuine. Those points remain open until verified by the company or another authoritative source.
What to do now
Treat the Coinbase Cartel listing as a warning signal, not as confirmation that your data is in circulation. If you work with Kessler Creative NEW or receive unexpected messages that cite the firm, campaigns, invoices, or urgent payment changes, verify through a known phone number or official channel before acting. Prefer unique passwords and multi-factor authentication on email and any ad or vendor platforms you share with agencies. Watch bank and card statements if you have paid the firm directly.
If you later receive notice from the company or a regulator describing specific data, follow that guidance. Until then, keep steps proportional: skepticism toward unsolicited links, careful handling of attachments, and routine credential hygiene. Readers can also run a free exposure scan of their email to check whether their information has already surfaced in known breach data from other incidents, which is a separate check from this unconfirmed listing.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Tower Insurance NEW Listed by Coinbase Cartel Ransomware GroupIntegrated Health Systems NEW Listed by Coinbase Cartel Ransomware GroupAbacus Advisors NEW Listed by Coinbase Cartel Ransomware GroupKlasko Immigration Law Partners NEW Listed by Coinbase Cartel Ransomware GroupLatest breaches
Publicly posted by coinbase-cartel — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.