On December 22, 2025, CoreHQ appeared on the leak site operated by the qilin ransomware group. The attackers claim they stole internal files from the company and have published samples as proof. Anyone whose personal information was stored in CoreHQ’s systems could now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch CoreHQ
Get alerted the next time CoreHQ files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about CoreHQ’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that CoreHQ was listed on the qilin ransomware leak site on December 22, 2025. The group states it exfiltrated internal data during a ransomware incident. The exact number of people affected remains unknown, and the specific types of records taken have not been fully detailed in available reporting. The leak site continues to display samples of the stolen material.
Why This Matters for You and Your Family
When a company that holds customer, employee, or vendor records is hit by ransomware, the consequences reach far beyond the business itself. Your name, address, email, phone number, or financial details could be among the files now circulating among criminals. Once that information is loose, it can be sold, traded, or used to target you and your family with identity theft, phishing, or harassment. Internal files exfiltrated often contain spreadsheets, databases, or documents that link multiple pieces of personal data together, making follow-on attacks easier and faster.
The Doxxing and Identity-Chain Implications
Stolen internal files frequently include email addresses, usernames, phone numbers, and notes that connect your online handles to your real identity. Criminals use these connections to build an identity chain: one leaked credential leads to another account, which leads to gaming profiles, family member details, or children’s accounts. A single breach like this can cascade into full doxxing, account takeovers, and persistent harassment. Public reporting describes how such chains allow attackers to map relationships across platforms that most people assume are unrelated.