Nothing Technology Breached by INC_RANSOM, 52GB Exposed: Ransomware Claim — What’s Alleged & What To Do
Nothing Technology reported a data breach on May 20, 2026, in which INC_RANSOM exposed 52 GB of company data and credentials. Anyone with an account or relationship with Nothing should check for signs of exposure and change any reused passwords immediately.
Breaking down the breach
The incident is known only through the group's public listing on its leak site. The entry reports that 52GB of material was taken from Nothing and made available for download. No independent confirmation of the data volume, its contents, or the date of the initial intrusion has been released by the company or by investigators.
Nothing has not issued a public statement on the matter, and the scale of any impact on customers or staff is not yet known.
Inside incransom
INC_RANSOM is a ransomware operation that typically deploys encryption on targeted networks and then threatens to publish stolen files if payment is not received. The group maintains a site on which it lists organizations it claims to have compromised, often accompanied by sample files or volume estimates. These listings constitute the group's own assertions; independent verification of each claim is not always available.
The operation has appeared in multiple public reports over recent years, following a pattern of double-extortion in which both encryption and data publication are used as leverage.
About Nothing
Nothing is a London-headquartered technology firm that designs and markets consumer devices such as smartphones and wireless earbuds. Companies of this type routinely hold customer account details, order histories, device identifiers, and internal operational records required for sales, support, and product development.
A breach at such an organization can therefore touch both personal customer information and proprietary business material.
What was likely exposed
The listing names company data and credentials as the categories of material released. The precise composition of the 52GB archive has not been confirmed by any party outside the group.
- Company records
- Credentials
Why it matters
Credentials that appear in public leaks can be tested against other online services, especially where password reuse occurs. Internal company records may contain operational details whose wider circulation could create follow-on risks for the organization and its partners.
Because the number of affected individuals is still unknown, the full scope of personal exposure cannot yet be assessed.
Were you affected?
Anyone who holds an account with Nothing should review recent login activity and update passwords, particularly where the same credentials are used elsewhere. Running a free exposure scan with a known email address against public breach datasets provides one practical way to check for prior appearances of that address in other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Foxconn Interconnect Technology Limited (FIT) Listed by incransom Ransomware GroupUniflex Technology Inc Listed by incransom Ransomware Groupv-silicon.com Listed by incransom Ransomware Grouptecnocurva.com.br Listed by incransom Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Nothing Technology Breached by INC_RANSOM, 52GB Exposed →
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.