LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › PayPal support operations (Transcom WorldWide) Listed by N0n Ransomware Group

HIGH severityUnverified claimHow we verify

PayPal support operations (Transcom WorldWide) Listed by N0n Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 18, 2026
PayPal support operations (Transcom WorldWide) Listed by N0n Ransomware Group

Reported September 18, 2026.

HIGH
Severity
September 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

PayPal support operations (Transcom WorldWide) were listed on September 18, 2026 by the N0n ransomware group, which claims to hold customer data. Anyone who contacted PayPal support through Transcom should check their accounts for unusual activity and consider changing passwords or enabling extra verification.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware crews continue to pressure large service providers by posting corporate names on leak sites and threatening to release material if a payment is not made. Those postings are accusations, not verified breach reports, and they often appear before any company, regulator, or independent index has confirmed that an incident occurred.

On September 18, 2026, the group styling itself N0n listed Transcom WorldWide in connection with outsourced PayPal support operations, according to that leak-site entry. Transcom WorldWide has not publicly confirmed the claim as of writing. Public detail on whether any systems were accessed, what if anything left the network, or how many people might be affected remains limited to the group’s own claims.

Inside the listing

The listing frames Transcom WorldWide as handling outsourced customer support and financial-services work linked to PayPal, with references to operations involving the Netherlands and Tunisia. N0n’s entry states that material will be published if no settlement is reached. The group’s description of what it says it holds includes claims of roughly 86.7 million connection records tied to daily support-agent sessions into PayPal corporate Citrix and AAA systems, a purported complete infrastructure map covering internal Active Directory, PKI, Netskope and Zscaler tenants, and all eight sites, and an assertion that all eight sites are enforcing a network blackout until settlement.

Those figures, technical labels, and operational claims come from the listing itself. They are not independently verified in the material available for this article. The number of people affected is unknown. Timing of any alleged intrusion, the method of access if any, and whether files were actually copied are undisclosed beyond the group’s marketing language on the leak site. A leak-site post establishes that a named crew chose to accuse a named firm; it does not by itself establish theft, exposure, or the accuracy of the inventory the crew advertises.

The group behind it: N0n

N0n appears in public reporting as a ransomware and extortion-style actor that uses leak sites to name organisations and threaten publication unless a payment is made. Like other groups in this category, it typically pairs encryption or access claims with timed disclosure pressure, and it may recycle, exaggerate, or misattribute data to increase leverage. Well-documented patterns across this class of actors include posting partial samples, infrastructure diagrams, or session-related artefacts as proof, and setting settlement deadlines that may or may not be real.

For this specific listing, only what appears on the N0n entry should be treated as the group’s claim. Nothing in the available facts states that N0n obtained the volumes or maps it describes, that a blackout is in force across eight sites, or that PayPal corporate systems were involved in the way the listing asserts. Readers should separate the general reputation of extortion crews from any conclusion about this particular accusation.

Who is Transcom WorldWide?

Transcom WorldWide is a customer-experience and contact-centre provider that delivers outsourced support and related services for large brands, including work that can touch financial-services and payments environments. Firms in this sector often operate across multiple countries and sites, staff large agent populations, and connect into client platforms under strict contractual and regulatory controls.

A listing that ties such a provider to a major payments brand matters because support operations can sit close to identity, session, and account-help workflows even when the provider is not the bank or wallet issuer itself. That proximity is why extortion groups target business-process outsourcers: the claim alone can create operational, contractual, and reputational pressure. Whether any of N0n’s specific technical claims about Transcom or PayPal are accurate is unconfirmed.

What data was at risk

Named data types in the available record are not disclosed as confirmed exposures. The leak-site text is the attacker’s description of what it says it will publish, not a verified inventory. According to that listing, the group claims connection records related to support-agent sessions into Citrix and AAA systems, plus infrastructure mapping across directory services, certificate infrastructure, cloud security tenants, and multiple sites.

If files of that kind were ever taken from an organisation in this sector, firms typically hold workforce identities, authentication and remote-access logs, internal network diagrams, vendor and client integration details, and sometimes customer-support case metadata. Customer financial account data, full payment credentials, or end-user wallets are not established as part of this listing. Exact contents, if any, remain unconfirmed, and no affected-person count is known.

Why it matters

For individuals, the practical concern is conditional. If support-session or identity-related records were involved, risks could include targeted phishing that references real ticket or login patterns, social engineering against people who work in or with support operations, and secondary fraud attempts that misuse internal jargon. None of that is proof that any particular person’s data is in this alleged set.

For the organisation and its clients, a public extortion listing can disrupt trust, force costly verification work, and complicate multi-site operations even when the underlying claim is disputed or false. Infrastructure maps and remote-access session claims, if genuine, would be sensitive because they can aid further intrusion planning; if fabricated or overstated, they still create noise that defenders and customers must sort through. The listing does not establish negligence, successful theft, or the truth of the blackout claim; it establishes only that N0n chose to name Transcom WorldWide on its site on the reported date.

What to do now

Treat the situation as an unverified extortion claim until Transcom WorldWide or another authoritative source confirms otherwise. Practical steps stay conditional on whether your information was ever involved:

Readers who want a simple check can run a free exposure scan of their email address to see whether that address has already appeared in other known breach datasets, which is separate from verifying this particular N0n listing. Public detail on this accusation remains limited to the group’s claims and the September 18, 2026 report date; Transcom WorldWide has not publicly confirmed the incident as of writing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyTranscom WorldWide security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Transcom WorldWide’s full breach history →

More recent breaches

Argentem Creek Partners (investment firm) Listed by N0n Ransomware GroupSeptember 18, 2026Vietnamese betting operator (GC789 network / Boundless TE) Listed by N0n Ransomware GroupSeptember 18, 2026BeLi Teacher / FSC education centers (AWS) Listed by N0n Ransomware GroupSeptember 18, 2026AstraZeneca Türkiye Listed by N0n Ransomware GroupSeptember 18, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the PayPal support operations (Transcom WorldWide) Listed by N0n Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by n0n — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram