LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › veritiv Listed by Iah647 Ransomware Group

HIGH severityUnverified claimHow we verify

veritiv Listed by Iah647 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 15, 2026
veritiv Listed by Iah647 Ransomware Group

Reported September 15, 2026.

HIGH
Severity
September 15, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Veritiv was listed by the Iah647 ransomware group on 15 September 2026; the group claims it has data belonging to an undisclosed number of people, but the organisation has not issued any statement and no independent confirmation has been published. Individuals who have shared personal information with Veritiv should monitor their accounts and consider placing fraud alerts or credit freezes as a precaution.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group calling itself Iah647 has listed veritiv on its leak site, according to a report dated September 15, 2026. The listing is an unverified claim by the group. As of writing, veritiv has not publicly confirmed that any incident occurred, that systems were accessed, or that any data was taken.

Public detail is limited to what appears on the group's listing: a claimed data volume, a status marker, and a countdown tied to hosting. No independent confirmation from the company, a regulator, or a established breach index is reflected in the available record. For people who do business with or work in distribution and packaging supply chains, the practical question is what a leak-site claim does and does not establish, and what to do if personal or business information later turns out to have been involved.

What the listing says

According to the listing, Iah647 has named veritiv and associated the entry with a claimed size of 1.9 TiB. The status is described as "soon," with hosting noted as having 2 days and 14 hours left at the time captured in the report. The number of people affected is unknown. Data types allegedly involved are not disclosed on the listing as reflected in the available facts.

The listing does not, in the material provided, describe a method of intrusion, a timeline of alleged access, ransom demands in dollar terms, sample file inventories, or proof packages beyond the headline figures and status fields. Those elements remain undisclosed. A leak-site entry of this kind is a public pressure tactic used by extortion crews; it is not the same as a claimed breach disclosure. Readers should treat volume figures and countdowns as part of the group's claim, not as audited measurements.

Inside Iah647

Iah647 appears in this context as a ransomware and extortion-style actor that uses a leak site to name organisations and threaten publication. Groups in this category typically claim to have stolen data, set timers or "soon" status labels, and use countdown or hosting windows to increase pressure on the named organisation. Public reporting on such crews often describes double-extortion patterns: encryption paired with a threat to release data if payment is not made, though whether encryption, theft, both, or neither occurred in any specific case is not established by a listing alone.

For this veritiv entry, the group claims a 1.9 TiB corpus and a near-term hosting window. No further victim-specific statements from Iah647 beyond what the listing fields show are included in the facts at hand. Prior activity by similarly named crews is sometimes recycled, exaggerated, or mixed with older material; nothing in the present record confirms authenticity of the files or the attribution. The listing establishes that Iah647 chose to name veritiv publicly. It does not by itself establish that the claim is true.

veritiv and its sector

veritiv is known publicly as a major player in business-to-business distribution, including packaging, facility solutions, print, and related supply-chain services for commercial customers. Organisations in this sector typically sit between manufacturers and a wide base of business clients. They often manage large volumes of order data, shipping and logistics records, customer and supplier contact details, contracts, invoicing, and internal employee information needed to run warehouses, sales, and corporate operations.

A claimed incident affecting a firm in this position matters because supply-chain intermediaries hold data that can touch many other companies at once. Even an unconfirmed listing can create uncertainty for customers, suppliers, and staff who must decide whether to heighten monitoring. Consequence here is about dependency and data concentration in B2B distribution, not about any verified event at veritiv.

What was likely exposed

The listing does not name specific data types. Exact contents are unconfirmed. If files were taken from an organisation of this kind, firms in packaging and distribution typically hold some mix of the following, though none of this is established as present in any Iah647 corpus related to veritiv:

Because the listing leaves data types undisclosed and the incident is unconfirmed, no inventory should be treated as fact. Claimed size alone (1.9 TiB) does not reveal what fraction, if any, is sensitive personal data versus bulk operational files, duplicates, or unrelated material.

The real-world impact

If the claim were accurate and if personal or business data were later published, affected individuals could face phishing that references real orders, employers, or counterparties; fraud attempts using business email patterns; or misuse of contact and identity details. Corporate customers could see competitive or contractual information misused if such material were genuinely exfiltrated. None of that is demonstrated by the listing alone.

For the organisation named, a public extortion listing can drive customer questions, legal and regulatory attention, and operational distraction even when facts remain unsettled. For the wider sector, leak-site claims against distributors underline how intermediaries are attractive targets for crews seeking leverage across many downstream firms. The gap between a countdown on a leak site and verified harm is often large; impact assessments should wait on confirmation, forensic clarity, and official notices rather than on attacker marketing copy.

If your data was involved

If you are an employee, contractor, customer, or supplier and you later receive a credible notice that your information was involved, treat the situation as conditional until that notice arrives. Practical first steps include watching for unexpected password resets or invoice changes; verifying payment or shipping requests through a known channel rather than email alone; enabling stronger authentication on email and work accounts; and documenting any suspicious contact that appears to reference internal details. Do not assume your data is in the claimed set solely because a group listed the company.

veritiv has not publicly confirmed this incident as of writing. Monitor official company channels for any statement rather than relying on leak-site posts. Readers who want a basic check can run a free exposure scan of their email address to see whether that address has already appeared in known breach datasets unrelated to this claim, and then tighten passwords and alerts accordingly if matches appear.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Companyveritiv security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See veritiv’s full breach history →
RelatedMore incidents at veritiv

More recent breaches

mat-holdings-inc Listed by Iah647 Ransomware GroupAugust 29, 2026trc-companies Listed by Iah647 Ransomware GroupAugust 29, 2026proampac Listed by Iah647 Ransomware GroupAugust 29, 2026swagelok Listed by Iah647 Ransomware GroupAugust 29, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the veritiv Listed by Iah647 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by iah647 — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram