LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › TapClicks (marketing analytics platform) Listed by N0n Ransomware Group

HIGH severityUnverified claimHow we verify

TapClicks (marketing analytics platform) Listed by N0n Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 25, 2026
TapClicks (marketing analytics platform) Listed by N0n Ransomware Group

Reported September 25, 2026.

HIGH
Severity
September 25, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

TapClicks, a marketing analytics platform, was listed by the N0n ransomware group on September 25, 2026; the group claims it holds data of an undisclosed number of individuals, but the organisation has not issued any statement and no independent verification has been published. Individuals should check whether they have accounts with TapClicks and consider changing passwords or enabling additional security measures if they may be affected.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as N0n has listed TapClicks, a marketing analytics platform, on its leak site, with the listing dated around September 25, 2026. No public confirmation from the company or a regulator appears in the material available for this write-up, so the episode remains an unverified accusation rather than an established incident. For people who use marketing tools, manage client campaigns, or work inside agencies that rely on such platforms, the practical stake is straightforward: if the claims were accurate, business and account-related information could be at risk of misuse, and ordinary users would need clear steps rather than speculation.

Public detail is limited. The listing does not establish how many people might be affected, and nothing in the available record states that data left TapClicks’ systems. What follows treats N0n’s statements as claims, explains what a listing of this kind does and does not prove, and outlines conditional steps readers can take if they believe their information could be involved.

What is being claimed

N0n has listed TapClicks (described in the listing context as a marketing analytics / SaaS business in the United States) on its leak site. According to the listing, the group claims access to material it describes as the complete platform source code (stated as 97,000+ commits with full history); a multi-tenant instance management system with production architecture; and a customer’s full marketing database said to include 354 advertising platform datasets, client lists, user accounts with password hashes, and ad-platform connection credentials. The listing text asserts that “Everything is real, complete and verifiable,” and marks the entry as active with a deadline of 2026-09-28 01:59 UTC.

The number of people affected is unknown in the available record. Method of intrusion, dwell time, and independent verification of the files are not disclosed. TapClicks has not publicly confirmed the claim as of writing. A leak-site post is a pressure tactic used in extortion campaigns; it is not the same as a claimed breach inventory, a regulator notice, or a company disclosure.

Who is N0n?

N0n appears in public reporting as a ransomware and extortion-style actor that uses leak-site listings to pressure organisations. Groups in this category commonly claim to have stolen data, post sample descriptions or file lists, set deadlines, and threaten publication or sale if payment demands are not met. Their public posts are marketing for leverage: volume claims, technical-sounding inventories, and urgency language are typical, and independent researchers often treat them as unverified until a victim, insurer filing, or official notice corroborates them.

For this specific listing, only what appears in the facts should be attributed to N0n about TapClicks: the group claims the categories of material summarised above and presents the entry as active against the stated deadline. No further victim-specific statements beyond that listing language are treated as established here. Readers should separate well-documented patterns of how such crews operate from any assumption that a particular claim about a named company is true.

TapClicks (marketing analytics platform) and its sector

TapClicks is known publicly as a marketing analytics platform—software that helps organisations pull together advertising and campaign performance data, reporting, and related workflows, often in a multi-tenant SaaS model used by agencies and marketing teams. Firms in this sector typically sit between advertising platforms, client organisations, and internal users. They may process campaign metrics, connection settings to ad networks, client and contact structures, user login material, and operational configuration for many customers on shared infrastructure.

A credible incident affecting a platform of this type would matter because the same systems can hold both operational secrets (how the product is built and run) and customer-facing business data (who the clients are, how accounts connect to ad platforms, and credentials or hashes tied to users). Even without treating N0n’s inventory as fact, the sector’s role explains why listings aimed at marketing analytics vendors attract attention: the potential blast radius, if data were ever taken, could extend beyond one company to agencies and brand clients who never logged into the vendor’s admin tools directly.

What was likely exposed

The facts do not provide an independently verified inventory. Data types are those named in N0n’s listing language only; they are not confirmed as taken. Exact contents remain unconfirmed. If files of the kind the group describes were ever obtained from a marketing analytics SaaS provider, organisations in this sector typically hold items such as:

None of the above should be read as a finding that TapClicks lost those items. The listing is the attacker’s description. People affected, if any, are unknown. Conditional risk discussion is all that the record supports.

Why it matters

If the claimed material were authentic and exfiltrated, risks would fall on several groups at once. End users and agency staff could face account takeover attempts where password hashes can be cracked or where reused passwords unlock email and other services. Client organisations could see business relationships, campaign structures, or competitive marketing detail misused for fraud, spear-phishing, or unwanted outreach. Connection credentials to ad platforms, if real, could allow unauthorised access to advertising accounts, budget abuse, or data pulls from those platforms. Source code and production architecture claims, if accurate, could help attackers map weaknesses in similar systems over time—again, only if the material is genuine.

For the organisation named on the leak site, an active extortion listing creates reputational and operational pressure regardless of eventual proof: customers ask questions, partners reassess risk, and legal and contractual notice duties may be triggered if a real incident is later established. What a leak-site listing does establish is that a crew chose to name the company and publish a sales-style description. What it does not establish is theft, scope, or negligence. There is no confirmed incident in the provided record from which to infer security failures, detection gaps, or culture. The responsible reading is narrower: an unverified claim exists; confirmation does not; and people who might be touched should act on possibility, not on panic.

If your data was involved

Because nothing here confirms that your information was taken, treat the following as precautions if you use TapClicks, work for a client that does, or manage ad-platform connections through similar tools. Change passwords on related accounts and stop reusing them elsewhere; prefer a password manager and unique credentials. Enable multi-factor authentication on email, TapClicks-related logins if you have them, and advertising platform accounts. Watch for phishing that references campaigns, invoices, or “urgent security” messages timed to extortion news. Review ad-platform access logs and API or partner connections for unfamiliar devices or apps. If you are a business customer, ask your vendor contacts through official channels whether they have issued any notice—do not rely on leak-site screenshots alone. Consider credit or account monitoring if financial or identity data could reasonably have been in scope for your role, while remembering that the public record does not name confirmed victim counts or verified file contents.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets unrelated or related to circulating dumps. That kind of check does not prove involvement in this listing, but it can show whether your email is already circulating in broader breach corpuses and whether you should tighten credentials further. Stay with official company and regulator statements if and when they appear; until then, N0n’s listing remains a claim, TapClicks has not publicly stated the incident as of writing, and measured personal hygiene around passwords, MFA, and phishing is the proportionate response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyTapClicks (marketing analytics platform) security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See TapClicks (marketing analytics platform)’s full breach history →

More recent breaches

AFRICA-TECH (IT services / document processing) Listed by N0n Ransomware GroupSeptember 22, 2026Fanatics (global sports commerce platform) Listed by N0n Ransomware GroupSeptember 20, 2026Inter (Venezuela's largest internet provider) Listed by N0n Ransomware GroupSeptember 18, 2026FinSoft (Kolibri retail back-office software) Listed by N0n Ransomware GroupSeptember 22, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the TapClicks (marketing analytics platform) Listed by N0n Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by n0n — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram