Company Breach Ratings
Companies that appear in our tracker — some through breaches the organisation, a regulator or a breach index has confirmed, and most through unconfirmed listings posted by ransomware and extortion groups. Each carries a DoxxScan™ Rating for how exposed their customers’ information may be if the reports behind it are accurate (lower rating = higher doxx risk), and a Safety Grade summarising that public record (higher = cleaner). Unconfirmed claims are labelled as such and count for less in both numbers. A listing is not proof that a breach happened.
Companies we track
Plaxen Adler Muncy, P.A.
Simon & Schuster, LLC
Kovack Financial, LLC
USA DeBusk LLC
My Doctor, LLC
Midtown Community Health Center, Inc.
Boston Healthcare for the Homeless Program
Gila Health Resources, LLC
Golden Opportunities And Local Support, LLC
Sciencenter Discovery Museum
Independent Solutions Wealth Management, LLC
Anesthesia Group of Albany, P.C.
Guardian Credit Union
Homeless Prevention Center
CTS Journey Holdings, LLC d/b/a Corporate Travel Service
Eyemart Express, LLC
Malin + Goetz, Inc.
JRK Property Holdings, Inc.
Grant County Public Hospital District #2
CTS Journey Holdings
TELUS International AI
The Moody Bible Institute of Chicago
Superb Shifts, Inc.
Aesto Health
Miles Partnership, LLLP
Everside Health (Aesto, LLC)
SM Energy
The City of New Britain
Schembre & Gannon, LLC
Microcode, Inc. (CommonSpirit Health)
Wei Wei & Company LLP
TransGlobal Insurance Agency
Taft Stettinius & Hollister LLP
Index Packaging, Inc.
Herbert Smith Freehills Kramer (US) LLP
ADT, Inc.
Archdiocese of Indianapolis
Doxa Insurance Holdings, LLC
SPay Inc dba Stack Sports
Doxa Programs, LLC
Doxa E&S Solutions, LLC
Bridgeway Benefit Technologies LLC
Alabama Symphonic Association Inc.
Hilldun Corporation
Virginia Transportation Corporation
Safetyfirst Systems, LLC
The Devereux Foundation
Humana Inc.
Questo, Inc.
Kootenai County, ID
The DoxxScan™ Rating is an automated, informational estimate of how exposed a company’s customers may be if the incidents on its public record are accurate, derived solely from that record — the number of incidents, how recent and severe they were, the sensitivity of the data involved, and who established the incident. Most incidents we track are unverified listings published by ransomware and extortion groups; those are accusations, not established facts, and they count for less. A lower rating indicates a higher likelihood that personal information tied to this company is circulating and could be used to dox or target individuals. It is not an audit, certification, or assessment of the company’s current security controls, and it does not represent present-day risk. It may rely on incomplete or unverified public reports and can change as new information emerges. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company named here. Provided for general awareness only — not legal, financial, or security advice. How the rating is calculated →
