On December 12, 2025, ransomware group coinbasecartel added Arcom Digital to its leak site and began publishing what it claims are the company’s internal files. Arcom Digital provides network monitoring tools used by internet service providers, and the exposed material may contain employee records, vendor contracts, customer contact details, and technical documentation that could be repurposed for identity theft or further attacks.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Arcom Digital
Get alerted the next time Arcom Digital files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Arcom Digital’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates the incident is a ransomware attack in which files were first exfiltrated and then the company was listed on the group’s dark-web portal. The exact number of records involved remains unknown, and Arcom has not yet issued a public statement detailing the scope. Available reporting describes the data as internal files rather than a structured database dump of customer credentials. The leak site link was indexed by ransomware trackers on December 12, 2025, and the group has set the customary extortion deadlines typical of its past operations.
Why This Matters for You and Your Family
Even when a breach hits a business you have never heard of, your personal information can still surface. Arcom’s tools are used by broadband providers that serve millions of households; vendor lists, support tickets, or test accounts often include names, addresses, phone numbers, and email addresses of ordinary customers. Once that information reaches criminal marketplaces, it can be combined with other leaks to build a profile that puts your family at risk of account takeovers, phishing campaigns, or identity fraud. Credential leaks like this one frequently cascade into gaming platforms, where children’s accounts become entry points for harassment or further data theft.
The Doxxing and Identity-Chain Implications
Ransomware operators rarely stop at the first company they hit. They sell or trade the data, allowing other criminals to link an email from the Arcom files to a reused password on a gaming service, a family member’s social-media handle, or a child’s Roblox or Fortnite account. This creates an identity chain that can lead to doxxing, swatting, or targeted extortion. Public reporting shows these chains move quickly once the initial dataset appears on leak sites. Families who believe “it’s just a business breach” often discover months later that their personal details have been packaged and sold alongside the corporate files.