LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Mammut.Com Listed by Clop Ransomware Group

HIGH severityUnverified claimHow we verify

Mammut.Com Listed by Clop Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 12, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Reported August 12, 2026.

HIGH
Severity
August 12, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Mammut.Com has been listed by the Clop ransomware group as the target of a breach, with the disclosure made public on August 12, 2026. An undisclosed number of individuals may have had personal data exposed; users should check the company’s notices and take protective steps if their information is affected.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as Clop has listed Mammut.Com on its leak site, according to a report dated August 12, 2026. The listing is an unverified claim. Mammut.Com has not publicly confirmed any incident as of writing. For customers, partners, and staff who may have dealt with the company, the practical stakes are straightforward: if personal or business information were ever taken and published, it could be misused for fraud, phishing, or unwanted contact. Nothing in the public listing establishes that this has happened, or that any particular person’s data is involved.

Public detail is limited. The number of people who might be affected is unknown, and the listing does not provide a clear, confirmed inventory of personal data. What follows separates what the group claims from what is known about Clop’s usual methods and about organisations in this sector, so readers can judge risk without treating an extortion-site post as settled fact.

What the listing says

Clop has listed Mammut.Com on its leak site. The report associated with that listing is dated August 12, 2026. According to the listing’s summary, the group claims data exfiltration that included .png files and files described in connection with “Windchil,” a total size given as 136Gb, and a revenue figure of $281,000,000. Those details come from the attackers’ own marketing language on the leak site; they are not an independent inventory and have not been confirmed by the company or by a regulator in the material provided here.

The listing does not disclose a verified count of affected individuals. It does not describe a claimed intrusion method, timeline of access, or proof package that third parties have validated. How the group says it obtained any material, whether any files were actually taken from Mammut.Com systems, and whether anything will be published remain unconfirmed. Readers should treat the post as a claim made under extortion pressure, not as a completed forensic finding.

The group behind it: Clop

Clop (also styled CL0P) is a long-running ransomware and extortion operation that has repeatedly used dedicated leak sites to name organisations and pressure them into paying. In well-documented campaigns over recent years, the group has often combined data theft with public threats to release files, sometimes after exploiting widely used enterprise software, and has posted victim names, sample files, or volume claims to increase leverage. Those patterns are part of the public record about Clop as an actor; they do not prove what occurred in any single new listing.

When Clop lists a company, the group typically asserts that it has copied data and will drip or dump it unless demands are met. Listings can exaggerate scale, recycle older material, or misattribute sources. For this Mammut.Com entry, the only incident-specific assertions available here are those on the listing itself—including the claimed file types, the 136Gb figure, and the revenue number—and they should be read as the group’s claims, not as verified outcomes.

About Mammut.Com

Mammut.Com is associated with Mammut, a known name in outdoor and mountaineering equipment—apparel, footwear, climbing gear, and related retail and brand operations. Companies in this sector commonly run e-commerce sites, customer accounts, warranty and service records, wholesale and dealer relationships, and internal product or design workflows. Systems that support product lifecycle or engineering collaboration (names resembling “Windchill”-style platforms appear in manufacturing and product contexts more broadly) can sit alongside marketing assets, image libraries, and finance or partner data.

A leak-site claim against a consumer brand matters because the organisation may hold contact details, order history, and business correspondence that criminals could abuse if they truly obtained them. It also matters commercially: brand trust, partner confidence, and regulatory expectations around personal data all rise when an extortion group puts a company name in public view. None of that converts Clop’s listing into a claimed breach; it only explains why people connected to the brand pay attention when such a claim appears.

What data was at risk

The facts provided do not name confirmed categories of personal data as exposed. Data types are effectively not disclosed in any reliable, independent sense. The listing’s own wording refers to .png files and files tied to a “Windchil” description, plus a claimed total size of 136Gb. That is attacker-supplied description, not a verified contents list. It is not established which systems, if any, were touched, or whether customer, employee, or partner records were among any files the group claims to hold.

If files were taken from an organisation of this kind, firms in outdoor retail and product businesses typically hold some mix of customer account and order information, email and phone contacts, payment-related metadata (often tokenised rather than full card data), employee and HR records, dealer or wholesale terms, and internal documents or media. Product and engineering-related repositories can contain designs, specifications, or project files. Whether any of that is involved here is unconfirmed. The revenue figure cited on the listing is likewise a claim on the leak site, not an audited statement about what was stolen.

The real-world impact

For individuals, impact depends entirely on whether personal information was actually copied and whether it later appears in dumps, markets, or scam campaigns. Conditional risks include targeted phishing that references real orders or brand relationships, account-takeover attempts on email or shopping logins, and identity fraud if government IDs or financial details were ever stored and taken—none of which is established by the listing alone. People affected is unknown, so there is no basis to tell any reader that their data is out.

For the organisation, a public extortion listing can mean reputational pressure, customer support load, partner questions, and the cost of investigation whether or not the claim is accurate. Clop’s model is built on that pressure. A listing does not by itself prove negligence, successful exfiltration, or the accuracy of the 136Gb or file-type claims. It establishes that a known extortion group has chosen to name Mammut.Com; it does not establish the full technical story.

Steps worth taking either way

Because the incident is unconfirmed, the useful posture is precaution without panic. If you have used Mammut-related accounts or shared personal details with the brand or its partners, sensible steps include:

You can also run a free exposure scan of your email to check whether your address has already appeared in known breach datasets unrelated to this claim. That does not confirm or deny Clop’s listing about Mammut.Com, but it helps you see whether your credentials or contact details are already circulating from other incidents. Treat any future company or regulator notice as the authoritative source if one appears; until then, the responsible reading is that Clop has made a public claim, Mammut.Com has not confirmed it in the information available here, and personal risk remains conditional on facts that are still undisclosed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMammut.Com security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Mammut.Com’s full breach history →

More recent breaches

Ipmsolutions.Sk Listed by Clop Ransomware GroupAugust 12, 2026Philips.Com Listed by Clop Ransomware GroupAugust 12, 2026Cornelius.Com Listed by Clop Ransomware GroupAugust 12, 2026Tristar.Com Listed by Clop Ransomware GroupAugust 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Mammut.Com Listed by Clop Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by clop — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram