LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › ONE Contact Listed by Deadlock Ransomware Group

HIGH severityUnverified claimHow we verify

ONE Contact Listed by Deadlock Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 10, 2026
ONE Contact Listed by Deadlock Ransomware Group

Reported July 10, 2026.

HIGH
Severity
1
Data types exposed
July 10, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On July 10, 2026, the Deadlock ransomware group listed ONE Contact in connection with a ransomware attack in which internal files were exfiltrated. Individuals are advised to check whether their information was affected and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the ONE Contact Listed by Deadlock Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.
Ransomware operations continue to target service providers that hold operational records for large customer bases, with listings on leak sites often serving as the first public indication of an incident. In this case, the Deadlock group listed ONE Contact on or around July 10, 2026, stating that internal files had been taken during a ransomware attack. The number of individuals affected remains unknown, and no further confirmation of the listing or the scope of any data exposure has been made public.

What happened

The incident came to light when the Deadlock ransomware group added ONE Contact to its leak-site listing. The group claims to have exfiltrated internal files during a ransomware operation against the company. No details on the timing of the intrusion, the volume of data involved, or the method of access have been disclosed. The number of people whose information may be affected is also not known.

Who is Deadlock?

Deadlock is a ransomware group that has appeared in public reporting as an actor that deploys encryption malware and maintains a leak site to pressure victims. Like similar groups, it typically claims to have stolen data before encryption and lists organisations that do not meet its demands. Public records show the group has targeted entities across multiple sectors in prior activity, though specific claims regarding ONE Contact remain limited to the listing itself.

ONE Contact and its sector

ONE Contact operates as a contact centre with its physical office on Calle Padilla in Barcelona, Spain, while managed from Sweden. The company provides customer service, telemarketing, and retention services primarily for clients in the Scandinavian market, including first- and second-line support and digital customer-service solutions. Organisations in this sector routinely process call records, customer interaction logs, and account-management data on behalf of their clients.

What data was at risk

The Deadlock listing states that internal files were exfiltrated. No further breakdown of file types or contents has been released. Contact centres of this kind commonly hold operational records such as call logs and client account details, yet the precise categories of information involved in this incident remain unconfirmed beyond the general reference to internal files.

What's at stake

Exposure of internal operational files can reveal details about client relationships and day-to-day processes, which may affect both the organisation and the customers it serves. For individuals, any personal data contained in those files could be used for targeted social-engineering attempts or account takeovers. The organisation faces potential disruption to client contracts and the costs associated with investigating and containing the intrusion.

If your data was in this breach

Monitor accounts linked to any services handled by ONE Contact for unusual activity and consider enabling additional verification steps where available. Individuals can also run a free exposure scan of their email address against known breach data to check whether their information appears in public listings from this or other incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyONE Contact security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See ONE Contact’s full breach history →

More recent breaches

Carrier AB Listed by Deadlock Ransomware GroupJuly 25, 2026Aldaco Avance 2022 S.L. Listed by Deadlock Ransomware GroupJuly 12, 2026Schlenker and Cantwell, P.A. Listed by Deadlock Ransomware GroupJuly 10, 2026Consulting Valladolid Listed by Deadlock Ransomware GroupJuly 10, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the ONE Contact Listed by Deadlock Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by deadlock — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram