LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Nexon Corp. Listed by Global Secret Group Ransomware Group

HIGH severityUnverified claimHow we verify

Nexon Corp. Listed by Global Secret Group Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 26, 2026
Nexon Corp. Listed by Global Secret Group Ransomware Group

Reported July 26, 2026.

HIGH
Severity
1
Data types exposed
July 26, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Nexon Corp. was listed by the Global Secret Group ransomware group on July 26, 2026, after internal files were exfiltrated in a ransomware attack. The number of individuals affected has not been disclosed; readers should check any notifications or alerts from Nexon Corp. and follow recommended security steps if they believe their information may be involved.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Nexon Corp. Listed by Global Secret Group Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Ransomware groups continue to pressure large digital entertainment firms by claiming access to internal systems and threatening to publish stolen material. In that climate, a fresh listing that names a major online-games company draws attention because the sector holds large volumes of account, payment and operational data.

On 26 July 2026 Nexon Corp. appeared on the leak site operated by the group that calls itself Global Secret Group. Public detail remains limited: the number of people affected is unknown, and the only data category described is internal files said to have been taken during a ransomware attack. An internal infrastructure audit is reported to have found multiple critical entry points across distributed network segments. The listing itself is an unverified claim by the group.

Breaking down the breach

According to the available record, Nexon Corp. was listed by Global Secret Group on 26 July 2026. The report characterises the incident as a ransomware attack in which internal files were exfiltrated. No public figure has been given for the volume of data, the number of systems involved, or the number of individuals whose information may be implicated.

The same record states that an internal infrastructure audit identified multiple critical entry points spanning distributed network segments. Beyond that statement, the precise initial access method, the duration of any unauthorised presence, and the timeline of encryption or data theft have not been disclosed. No independent confirmation of the group’s claims has been supplied in the material available for this account.

The group behind it: Global Secret Group

Global Secret Group is presented in open reporting as a ransomware operation that maintains a public leak site. Like other actors in this category, such groups typically gain access to corporate networks, move laterally, exfiltrate selected files, and then demand payment under threat of publishing the material. They often list victims before or after negotiations stall, using the listing itself as leverage.

Well-documented patterns among comparable groups include double-extortion tactics, selective release of sample files to prove possession, and pressure campaigns aimed at both the organisation and its customers or partners. Nothing in the present record goes beyond the group’s claim that it holds internal Nexon files obtained in a ransomware attack; no additional statements attributed to Global Secret Group about this specific victim have been provided.

About Nexon Corp.

Nexon Corp. is a well-known developer and publisher of online games, operating titles that attract large player bases across multiple regions. Companies of this type routinely maintain account credentials, profile data, payment-related records, customer-support logs, and extensive internal operational documents covering development, infrastructure and business processes.

A breach affecting such an organisation is consequential because the same systems that support millions of player accounts also store the technical and administrative material needed to keep those services running. Even when the precise contents of a theft remain unconfirmed, the combination of consumer-facing and internal data raises both individual and corporate risk.

What was likely exposed

The facts name only one category: internal files exfiltrated in a ransomware attack. No inventory of file names, folders or record types has been released, and the number of people affected is listed as unknown.

Organisations in the online-games sector typically hold:

Whether any of those categories were among the files taken in this incident is unconfirmed. The exact contents remain undisclosed.

What's at stake

For individuals, the principal risks are credential stuffing, targeted phishing that references real account or support details, and potential misuse of any payment or personal data if such records were included. Because the scale is unknown, it is not possible to say how many people, if any, face those exposures.

For the organisation, the stakes include operational disruption, the cost of incident response and system hardening, possible regulatory scrutiny, and reputational damage if internal material is published. The reported discovery of multiple critical entry points across distributed segments also indicates that remediation must address more than a single compromised host.

What to do if you're exposed

If you maintain an account with Nexon or related services, treat the situation as a prompt to review your own security posture. Change passwords on the gaming account and on any other services where you reused the same credentials. Enable multi-factor authentication where it is offered. Monitor bank and card statements for unfamiliar charges. Be alert to phishing messages that claim to relate to a breach or that urge urgent action.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Keep records of any suspicious contact and report confirmed fraud to your financial institution and, where appropriate, to local authorities. Public detail on this incident is still limited; further verified information, if released, should guide any additional steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyNexon Corp. security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Nexon Corp.’s full breach history →

More recent breaches

Prism Telecom Listed by Global Secret Group Ransomware GroupJuly 26, 2026Stratos Network Listed by Global Secret Group Ransomware GroupJuly 26, 2026Cipher Dynamics Listed by Global Secret Group Ransomware GroupJuly 26, 2026OmniLink AG Listed by Global Secret Group Ransomware GroupJuly 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Nexon Corp. Listed by Global Secret Group Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by global-secret-group — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram