Back to Blog
high severity August 14, 2026 · 4 min read Unverified claim — what this is

Radiant Listed by Qilin Ransomware Group

If you have an account with Radiant, here’s what is being claimed, and what it would mean for you.

Radiant was listed on a ransomware/extortion leak site. The group claims to have stolen internal data. This is the group's claim, not a confirmed finding.

Radiant Listed by Qilin Ransomware Group

If you had an account with Radiant, the Qilin ransomware group has listed the company on its leak site. According to the listing, the group claims to possess files taken from the organization. Radiant has not publicly confirmed any breach or data theft as of this writing. This leaves you in an uncertain position: you do not know whether any of your information is actually in the attackers’ hands.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

That uncertainty itself matters. When a ransomware crew posts a company’s name, it is usually an attempt to pressure the victim into paying. Sometimes the files are genuine. Sometimes they are old, recycled, or never existed in the first place. Your immediate task is to treat the possibility as real while recognizing that the claim remains unverified.

What the Qilin Listing Claims About Your Account

The group’s post mentions that a password field was included in the material they say they obtained. The storage scheme for those passwords has not been disclosed. This is important because the strength of protection depends entirely on how Radiant stored the passwords. Without that detail, the safest assumption is that you should act as though the password associated with your Radiant account could be at risk.

No permanent government or biographic identifiers such as Social Security numbers, driver’s license numbers, or dates of birth appear in the description of the claimed data. That is genuinely good news. The absence of those fields means this incident does not create new avenues for identity theft that cannot be undone.

What you can still control is your password. If you reused the same password on other services, change it immediately on every site where it appears. Reused passwords are the most common way an unconfirmed leak turns into real account takeovers elsewhere. Even if the Radiant password was strongly protected, the prudent move is to assume the credential could be tested by the group or sold to others.

What a Ransomware Leak-Site Listing Actually Establishes

A listing on a ransomware group’s leak site is an accusation, not evidence. These crews publish names to create urgency and force payment. The described data is marketing copy written by the attacker. It is not an audited inventory. Many such listings later turn out to contain recycled data from earlier incidents, exaggerated file counts, or material obtained through means other than a full network compromise.

Real confirmation would require one of three things: an admission or detailed notification from the company itself, regulatory filings that name the incident, or independent forensic evidence released by a trusted third party. None of those exist here. Until one does, the correct stance is cautious skepticism. Treat your own exposure as possible but do not treat the group’s claims as proven fact. This distinction protects you from overreacting while still prompting reasonable defensive steps.

Most readers in your position want a clear answer: “Am I breached or not?” The honest answer today is that nobody outside the parties involved knows for certain. That ambiguity is common with leak-site postings and is exactly why conditional advice matters more than alarmist certainty.

The Current Ransomware Extortion Pattern

Ransomware groups have made unverified listings a standard pressure tactic. They frequently name companies whether or not a genuine compromise occurred, counting on fear of publicity to prompt payment. This pattern means you will likely see more of these announcements in the coming years, often with similar levels of proof.

The usable lesson for the next incident is simple: separate the noise from the signal. A name on a leak site should trigger password updates and monitoring, but it should not automatically be treated as a confirmed loss of every record the group claims to hold. Keeping that mental filter prevents both complacency and panic when the next listing appears.

Concrete Steps You Should Take Today

  1. Change your Radiant password immediately and do not reuse it anywhere else. Because the storage method was not disclosed, treat the credential as potentially usable by the group or anyone they share it with.
  2. Review every other account where you used that same password and change those as well. Password reuse remains the fastest way a single leak creates multiple compromises.
  3. Enable two-factor authentication everywhere it is offered, preferring app-based or hardware keys over SMS. This blocks most credential-stuffing attacks even if your password becomes known.
  4. Monitor your accounts and credit reports for unusual activity over the next several months. While no permanent identifiers were listed, unusual login attempts or new account fraud can still appear if the group possesses more than they have advertised.
  5. Set up ongoing breach monitoring so you are alerted if Radiant or any other service later confirms additional exposure. GalaxyWarden provides continuous monitoring across 13.1B+ breach records and 100+ platforms, along with identity-chain mapping and remediation support by specialists.

Uncertainty is uncomfortable, but it does not leave you powerless. The actions above address the realistic risks created by this type of listing while avoiding unnecessary alarm over data that may never have left Radiant’s control. Start with the password changes. Everything else follows from there.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Radiant is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 14, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email