LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › L3Harris Listed by Kyber Ransomware Group

HIGH severityUnverified claimHow we verify

L3Harris Listed by Kyber Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 30, 2026

SourceLeak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.

L3Harris Listed by Kyber Ransomware Group

Reported July 30, 2026.

HIGH
Severity
July 30, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

L3Harris was listed by the Kyber ransomware group on July 30, 2026, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; individuals are advised to check whether their data was involved and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to single out large technology and defense contractors, treating leak-site listings as both pressure tactics and public claims of access. In that landscape, a July 30, 2026 report that L3Harris had been named by the Kyber ransomware group fits a familiar pattern: an unverified assertion of intrusion and data theft against an organisation whose work sits close to government and critical systems. Public detail on this incident remains limited; what is known so far is the listing itself and a high-level description of what the group says was taken.

L3Harris, a global aerospace and defense technology company, was reported as listed by Kyber in connection with a ransomware attack in which internal files were said to have been exfiltrated. How many people may be affected is unknown, and independent confirmation of the claim has not been set out in the available record. For employees, partners, and others who deal with the firm, the episode still warrants clear-eyed attention to what has been stated and what has not.

Inside the incident

According to the reported facts, L3Harris was listed by the Kyber ransomware group on or about July 30, 2026. The listing is associated with a ransomware attack in which internal files were described as exfiltrated. The number of people affected is unknown. Timing of the underlying intrusion, the technical method of access, the volume of data involved, and any ransom demand or negotiation are not disclosed in the material at hand.

Because the primary public signal is a threat-actor listing, the incident should be treated as a claim by Kyber rather than as a fully corroborated account from the victim or independent investigators. No further operational detail—such as which systems were touched, how long access lasted, or whether encryption was deployed alongside theft—appears in the reported summary. Readers should therefore separate the fact of the listing from any assumption that every element of the group’s narrative has been verified.

Inside Kyber

Kyber is known in open reporting as a ransomware operation that follows a model common among contemporary groups: gain access to a network, move laterally, exfiltrate data, and then threaten or carry out public disclosure on a leak site to increase pressure. Such groups typically advertise victims with short descriptions of stolen material and deadlines, framing the listing as proof of compromise. Their public posts are claims; they are not, by themselves, forensic confirmation.

Well-documented patterns for actors of this type include double-extortion (theft plus encryption or the threat of leaks), use of initial access through phishing, exposed remote services, or compromised credentials, and staged release of sample files to demonstrate possession. None of that general tradecraft should be read as a specific reconstruction of how L3Harris was supposedly breached. For this incident, the facts state only that Kyber listed the organisation and that internal files were said to have been exfiltrated in a ransomware attack. Any broader assertion about Kyber’s exact tools, affiliates, or internal communications regarding L3Harris would go beyond the record and is not made here.

L3Harris and its sector

L3Harris is described in the reported summary as a global aerospace and defense technology innovator that provides mission-critical solutions for government, defense, and commercial sectors. Organisations in this category typically design, build, and support communications, sensing, avionics, and related systems used by military and civilian customers. They often hold controlled technical data, contractual information, employee and contractor records, and correspondence with government agencies.

A breach claim against a firm in this sector is consequential because the same environment that holds ordinary corporate data may also hold sensitive program, supply-chain, or personnel information. Even when the precise contents of a theft remain unconfirmed, the combination of national-security adjacency and large partner ecosystems means that partners, suppliers, and staff have a legitimate interest in understanding what was alleged and what protective steps remain prudent. That interest does not require assuming negligence; it follows from the nature of the work and the data such enterprises ordinarily process.

The information in question

The facts name the exposed material only at a high level: internal files exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of personal data categories (such as names, contact details, financial identifiers, or security-clearance related information) are provided. The number of people affected is unknown.

Organisations of this kind typically hold a mix of corporate documents, engineering and program files, human-resources data, vendor contracts, and communications with government and commercial customers. Whether any of those categories were among the files Kyber claims to hold is unconfirmed. Until a fuller disclosure or official statement specifies contents, it is accurate only to say that internal files were alleged to have been taken and that the exact composition of that material has not been publicly detailed in the available record.

Why it matters

For individuals, the practical risk of an unconfirmed internal-file theft is uncertainty. If personal or contact data were among the files, affected people could face phishing, social engineering, or identity-related misuse that draws on accurate employment or organisational context. If only technical or contractual documents were involved, the direct risk to private individuals may be lower, while the organisational risk—competitive exposure, contractual friction, or scrutiny from customers—may be higher. Because the facts do not settle which scenario applies, caution without panic is the proportionate response.

For L3Harris and its sector peers, a public ransomware listing can affect trust among government and commercial partners even before forensic findings are complete. It can also draw attention from regulators and customers who expect clear communication when mission-adjacent suppliers are named. None of that establishes fault as a matter of public fact; it describes why the claim carries weight beyond a routine corporate IT event.

What to do if you're exposed

If you have a past or present relationship with L3Harris—as staff, contractor, or close partner—treat the Kyber listing as a reason to tighten ordinary hygiene rather than as proof that your personal data is already in criminal hands. Concrete first steps include:

Public detail on this incident is still thin. Rely on verified updates from the organisation and from reputable reporting, and avoid treating an unverified leak-site claim as a full accounting of what occurred.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyL3Harris security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See L3Harris’s full breach history →

More recent breaches

Deas Millwork Listed by Akira Ransomware GroupAugust 20, 2026Wis Logistics Listed by Qilin Ransomware GroupAugust 19, 2026Senvest Capital Listed by Thegentlemen Ransomware GroupAugust 19, 2026Thrifty Building Supply Listed by Qilin Ransomware GroupAugust 19, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the L3Harris Listed by Kyber Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by kyber — unverified claim, pending independent verification. Leak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram