Skip to content
Back to Blog
high severity June 11, 2026 · 4 min read Unverified claim — what this is

suppcenter.global / suppcentersa.com Listed by m3rx Ransomware Group

If you are a customer of SuppCenter Global Services, here’s what is being claimed, and what it would mean for you.

+506 40003397. SuppCenter Global Services officially positions itself as one of the leading Xcitium solution partners and providers in the Latin America region. Xcitium is the new name of COMODO’s enterprise business. Their key cybersecurity specialization is based on a threat prevention architecture that uses Xcitium Zero Trust and ZeroDwell technologies. Official partnership: SuppCenter Global acts as a managed security service provider, or MSSP. They implement, configure, and support Xcitium/Comodo security solutions for large businesses, retail companies, and the public sector. Stolen: --

— from M3rx’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
suppcenter.global / suppcentersa.com Listed by m3rx Ransomware Group

On June 11, 2026, the ransomware group m3rx added suppcenter.global and suppcentersa.com to its leak site, claiming that it had exfiltrated internal files from a Latin American managed security service provider that specializes in Xcitium (formerly Comodo) cybersecurity solutions.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

What Public Reporting Shows

Public reporting indicates that SuppCenter Global Services operates as an official Xcitium partner and MSSP across Latin America. The company implements, configures, and supports Xcitium Zero Trust and ZeroDwell technologies for large businesses, retail companies, and public-sector organizations. The m3rx leak site lists both domains and includes the Costa Rican phone number +506 40003397 associated with the firm. No specific victim count or list of stolen files has been published on the leak page. Available reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated, though the precise volume and sensitivity of the data remain unclear at the time of writing.

Why This Matters for You and Your Family

When a cybersecurity service provider is breached, the ripple effects reach ordinary customers and their families. Many individuals and households rely on the same types of enterprise-grade tools that SuppCenter helps deploy. If internal files contained customer contact details, configuration data, or credentials, those records can quickly appear in other criminal marketplaces. Credential leaks like this one often cascade into account takeovers that start with email or remote-desktop access and spread to personal banking, health portals, and children’s online gaming accounts. Even if your name is not on any published list today, the exposure of a regional MSSP increases the chance that information tied to you or your family is already circulating among attackers who target everyday users.

The Doxxing and Identity-Chain Implications

Ransomware operators rarely stop at one dataset. Once internal files leave a company’s network, they are sorted, repackaged, and sold. A single email address or phone number found in those files can be linked to usernames on social media, gaming platforms, and shopping sites. Attackers then build an identity chain that connects your work email to your child’s Roblox or Fortnite account, your home address, and family photos. The result is doxxing that feels personal and persistent. Public reporting shows these chains frequently lead to harassment, SIM-swapping attempts, or demands for payment to prevent further leaks. Because SuppCenter serves both corporate and public-sector clients, ordinary families who interact with those organizations may find their data caught in the same net.

m3rx Group’s Publicly Known Track Record

Public reporting attributes m3rx with emerging in late 2024 as a ransomware-as-a-service operator. The group has claimed responsibility for attacks on a range of mid-sized businesses and service providers. Its typical playbook begins with initial access through compromised remote desktop credentials or phishing, followed by exfiltration of internal documents before encryption. Extortion follows a double-pressure model: demands are made to the victim company while stolen data is simultaneously prepared for publication on the group’s leak site if payment deadlines are missed. Exact prior victim lists fluctuate, but available reporting consistently describes m3rx as opportunistic, focusing on organizations whose data might hold value to both direct victims and secondary buyers on criminal forums.

What to do

  • Run a DoxxScan to map every link between your emails, phone numbers, usernames, and real-world identity so you can see exactly what an attacker could piece together from this breach.
  • Rotate any password you used at suppcenter.global or suppcentersa.com anywhere else it is reused, then switch on 2FA through an authenticator app rather than SMS.
  • Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next time your information surfaces you learn within hours instead of months.
  • Cover the household with DoxxScan family protection that extends to your children’s gaming accounts, which are often the weakest link in an identity chain that leads back to your home address.
  • Let remediation specialists handle the follow-up work of submitting takedown requests to data brokers and monitoring platforms where your family’s details may already be listed for sale.

The incident underscores a simple reality: data stolen from a cybersecurity provider can still endanger your family’s day-to-day digital life. Starting with a clear picture of your exposure and maintaining ongoing visibility is the most practical defense. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping that connects scattered handles to real identities, and hands-on remediation by specialists who manage takedowns for you. Its household coverage also protects children’s gaming accounts that frequently become entry points for larger doxxing campaigns. One forward-looking step today can prevent weeks of stress tomorrow.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
SuppCenter Global Services is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed June 11, 2026
Last reviewed August 8, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email