LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › THQ Nordic Listed by Direwolf Ransomware Group

HIGH severityUnverified claimHow we verify

THQ Nordic Listed by Direwolf Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 30, 2026
THQ Nordic Listed by Direwolf Ransomware Group

Reported August 30, 2026.

HIGH
Severity
August 30, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

THQ Nordic has been listed by the Direwolf ransomware group, with the disclosure reported on August 30, 2026. The exposed data includes personal information of an undisclosed number of individuals; anyone who may have shared data with the company should verify their status and take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On August 30, 2026, the ransomware group known as Direwolf listed THQ Nordic on its leak site and claimed to have taken internal data from the company. Public detail is limited: the listing does not establish how many people might be affected, what files if any were copied, or how the claimed intrusion occurred. THQ Nordic has not publicly confirmed the claim as of writing. Because the only source is an extortion-site claim, the matter remains an unverified accusation rather than a settled breach record.

For players, partners, and staff connected to a major games publisher, a listing of this kind still matters. It raises questions about whether confidential material could surface and what practical steps make sense if the claim later proves partly or fully accurate. What follows separates what the listing actually says from what it does not, and outlines conditional guidance without treating the accusation as proven fact.

Inside the listing

According to the available record, THQ Nordic appears on the Direwolf ransomware leak site with a reported date of August 30, 2026. The group claims to have stolen internal data. The listing does not publicly name specific data categories, file volumes, employee or customer counts, or a technical method of access. People affected are recorded as unknown, and data types named as exposed are not disclosed.

Leak-site posts are marketing and pressure tools for extortion crews. They can exaggerate, recycle older material, or assert access that has not been independently verified. Nothing in the public summary confirms that systems were encrypted, that a ransom demand was paid or refused, or that any archive has been released. Timing beyond the reported listing date, scale, and intrusion path remain undisclosed. Readers should treat the entry as a claim by Direwolf, not as a confirmed inventory of what left the company.

The group behind it: Direwolf

Direwolf is known in public reporting as a ransomware and data-extortion actor that publishes victim names on a leak site to coerce payment. Like other groups in this category, it typically claims theft of internal files and threatens release if negotiations fail. Public descriptions of such crews often include double-extortion patterns—encryption paired with exfiltration threats—or pure leak pressure without confirmed encryption. Specific tactics vary by incident and are not detailed in this listing.

Notable prior activity attributed to Direwolf in open sources involves naming organizations across sectors and posting purported samples or full dumps when deadlines pass. Those patterns are general background on the actor, not proof of what happened at THQ Nordic. For this case, the only incident-specific assertion on record is that the group has listed the company and claims to have stolen internal data. No independent confirmation of that claim is included in the facts provided here.

About THQ Nordic

THQ Nordic is a well-known games publisher and developer brand within the wider Embracer Group ecosystem, associated with a portfolio of PC and console titles, studios, and related commercial operations. Organizations in this sector routinely manage game builds, unreleased content, licensing and contract files, employee and contractor records, customer support and storefront data, marketing materials, and partner correspondence. The exact systems and datasets involved in any given claim are not established by a leak-site entry alone.

A listing that names a publisher is consequential because the industry depends on timed releases, intellectual property control, and trust with players and platform partners. Even an unconfirmed claim can prompt concern among staff, freelancers, and customers who wonder whether their information might be implicated if files were taken. That concern does not convert the Direwolf post into verified fact; it explains why ordinary people watch these listings closely.

What data was at risk

The facts state that data types named as exposed are not disclosed. Direwolf claims theft of internal data, but the listing does not provide a reliable inventory. It is therefore not possible to state which records, if any, left THQ Nordic systems.

If files were taken, firms in games publishing and related development typically hold combinations of workforce identity and payroll-related information, business contracts, source or build artifacts, player or community contact details tied to support and marketing, and credentials or configuration material used inside corporate networks. Those are sector norms, not a description of this incident. Exact contents remain unconfirmed, and no count of affected individuals is available. Any discussion of exposure must stay conditional on whether the group’s claim is later substantiated by the company, a regulator, or other independent evidence.

What's at stake

If internal data were copied and released, risks to people could include phishing that references real project or HR details, account takeover attempts using reused passwords, and unwanted contact if personal or work emails appear in dumps. For creative and commercial staff, premature exposure of unreleased work can disrupt schedules and partnerships. For the organization, reputational pressure and legal notification duties may follow only if a real incident is established under applicable law—none of which is confirmed solely by a leak-site claim.

Conversely, if the listing is inflated or false, the main near-term harm is uncertainty and the cost of checking. Extortion groups benefit from fear; calm verification serves readers better than assuming the worst. Until THQ Nordic or an authoritative third party confirms scope, individuals should not treat their personal data as proven stolen. The stake is the possibility of misuse if the claim holds, not a demonstrated mass compromise.

What to do now

If you have worked with, contracted for, or held accounts tied to THQ Nordic or related labels, treat the situation as conditional. Monitor official company channels for any statement. Prefer unique passwords and multi-factor authentication on email, storefront, and work accounts so a password appearing in any breach corpus is less useful. Be skeptical of unexpected messages that cite an internal project, invoice, or HR matter and push you to click or pay; verify through known contacts. If you receive notice from the company or a regulator later, follow that guidance on credit monitoring or document replacement.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets unrelated or related to past incidents. That check does not prove or disprove the Direwolf claim about THQ Nordic, but it helps you see whether your credentials need immediate rotation. Public detail on this listing remains limited; updates should be judged by whether the company confirms facts, not by further unverified posts on an extortion site.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyTHQ Nordic security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See THQ Nordic’s full breach history →

More recent breaches

Erdem Hospital Listed by Direwolf Ransomware GroupAugust 30, 2026Hospital Clnico Universidad de Chile Listed by Direwolf Ransomware GroupAugust 30, 2026Studio Legale ESE Listed by Direwolf Ransomware GroupAugust 25, 2026National Kidney Registry Listed by Direwolf Ransomware GroupAugust 25, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the THQ Nordic Listed by Direwolf Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by direwolf — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram