LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Kessler Creative NEW Listed by Coinbase Cartel Ransomware Group

HIGH severityUnverified claimHow we verify

Kessler Creative NEW Listed by Coinbase Cartel Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 22, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Kessler Creative NEW Listed by Coinbase Cartel Ransomware Group

Reported August 22, 2026.

HIGH
Severity
August 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Kessler Creative NEW has been listed by the Coinbase Cartel ransomware group, with the incident disclosed on 22 August 2026. An undisclosed number of individuals had personal data exposed; anyone who may have been affected should check their accounts and follow official guidance.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Coinbase Cartel has listed Kessler Creative NEW on its leak site, according to a report dated August 22, 2026. The listing presents the organization in connection with advertising networks and cites a figure of $17.1 million; it does not establish how many people may be affected or which records, if any, were obtained. Kessler Creative NEW has not publicly confirmed the claim as of writing. Until a company statement, regulator notice, or other independent verification appears, the matter remains an unverified claim by a ransomware and extortion group.

Leak-site postings are a form of pressure. They can be accurate, inflated, recycled from older incidents, or false. For clients, partners, and staff who work with advertising and creative firms, the practical question is what to watch for if the claim later gains support—not to treat the listing itself as proof that data has already moved.

What the listing says

The public report states that Coinbase Cartel has listed Kessler Creative NEW and frames the entry under advertising networks with a $17.1 million figure. The number of people affected is unknown. Data types said to have been exposed are not disclosed. Timing of any intrusion, method of access, whether files were copied, and whether any ransom demand was made are not detailed in the material provided.

Nothing in the available summary confirms that a breach occurred, that systems were encrypted, or that a countdown or file sample was published. The listing is the group’s assertion. Independent confirmation from Kessler Creative NEW or from a regulator is not part of the record described here.

Who is Coinbase Cartel?

Coinbase Cartel is known publicly as a ransomware and extortion-style actor that uses leak sites to name organizations and threaten publication of material it claims to hold. Groups in this category typically blend intrusion, data theft claims, and public shaming to push payment. Their posts are marketing as much as evidence: volume claims, sector labels, and dollar figures are chosen to maximize pressure and attention.

Well-documented patterns for such crews include listing victims before or without proof, recycling older datasets, and describing industries in broad terms. For this specific entry, only what appears in the listing summary should be attributed to the group: that it has named Kessler Creative NEW, associated the name with advertising networks, and attached a $17.1 million figure. No further claims by Coinbase Cartel about this organization are established in the facts at hand.

Who is Kessler Creative NEW?

Kessler Creative NEW is identified in the report as operating in advertising networks—work that typically involves campaigns, creative production, media buying, and coordination among brands, agencies, and publishers. Firms in this sector often sit between clients and a wide set of vendors, freelancers, and platforms.

A claimed incident involving an advertising or creative business matters because such organizations commonly handle commercial contracts, campaign plans, contact lists, billing details, and credentials used to reach client systems or ad platforms. Even an unconfirmed listing can create uncertainty for clients who need to know whether their materials or accounts could be at risk if the claim were later substantiated. That consequence follows from the sector’s role, not from any verified event at this company.

What was likely exposed

The listing does not name exposed data types. Exact contents are unconfirmed. It is not established that any particular category of file or record left the organization.

If files were taken from a firm in advertising and creative services, organizations of this kind typically hold business contact information, email correspondence, project and campaign files, invoices and payment-related records, contracts, and sometimes login material or API access used with ad platforms and partners. They may also hold personal data of employees and contractors. None of that inventory is confirmed here; it is a conditional description of sector norms only. Readers should not assume their information was included.

The real-world impact

For individuals, the main risks if a claim of this type were true would be phishing and social engineering that reference real campaigns or colleagues, misuse of business email addresses, and attempts to reset accounts tied to work or vendor relationships. Financial fraud risk depends on whether payment details or identity documents were among any material obtained—something the listing does not specify.

For the organization, an extortion listing can disrupt client trust, trigger contractual notice obligations if a breach is later confirmed, and consume time in investigation and communication even when the underlying claim is disputed. Those are ordinary consequences of public accusation in this threat model. They do not prove that Kessler Creative NEW lost control of systems or data.

A leak-site name alone does not tell the public whether backups were affected, whether customers were contacted by attackers, or whether any sample was genuine. Those points remain open until verified by the company or another authoritative source.

What to do now

Treat the Coinbase Cartel listing as a warning signal, not as confirmation that your data is in circulation. If you work with Kessler Creative NEW or receive unexpected messages that cite the firm, campaigns, invoices, or urgent payment changes, verify through a known phone number or official channel before acting. Prefer unique passwords and multi-factor authentication on email and any ad or vendor platforms you share with agencies. Watch bank and card statements if you have paid the firm directly.

If you later receive notice from the company or a regulator describing specific data, follow that guidance. Until then, keep steps proportional: skepticism toward unsolicited links, careful handling of attachments, and routine credential hygiene. Readers can also run a free exposure scan of their email to check whether their information has already surfaced in known breach data from other incidents, which is a separate check from this unconfirmed listing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyKessler Creative NEW security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Kessler Creative NEW’s full breach history →

More recent breaches

Tower Insurance NEW Listed by Coinbase Cartel Ransomware GroupAugust 22, 2026Integrated Health Systems NEW Listed by Coinbase Cartel Ransomware GroupAugust 22, 2026Abacus Advisors NEW Listed by Coinbase Cartel Ransomware GroupAugust 22, 2026Klasko Immigration Law Partners NEW Listed by Coinbase Cartel Ransomware GroupAugust 22, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Kessler Creative NEW Listed by Coinbase Cartel Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by coinbase-cartel — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram