-
A hacker claims to have 100TB of data linked to 176 companies around the world.
-
They’re offering the full collection for $100,000, but are also willing to sell single companies’ data.
-
No outside evidence confirms the claim, and the listing gives two different figures for the number of companies.

A threat actor on a cybercrime forum claims to have a huge collection of company data for sale.
The vendor claims that the collection contains information about 176 organizations in different nations. The listing contains companies from the USA, Great Britain, Ukraine, Brazil, Italy, Germany, etc.
The total collection is offered for $100,000. The seller also says buyers can buy data tied to single companies. Names shown in the listing include Toyota Financial and Red Wing Shoe Company.
The claim is striking, but it remains unverified. The seller does not show enough proof to confirm new breaches or the 100 TB figure. The listing also has a clear mismatch. Its title says “179 major companies,” while the post says 176.
The Seller Claims a Huge Data Haul
The seller says the collection holds 100 TB of data. That would average about 568 GB for each company if split evenly across 176 names. The figure does not prove the claim. Large firms can hold huge amounts of email, documents and other files.
The seller does not explain how they obtained the data. The post also does not show that each company suffered a new breach.
The data could include old leaks, stolen login details, public records or files from earlier attacks. It could also combine data from several sources or contain duplicates. That is why the 100 TB figure should not be treated as proof of a fresh mass breach.
Samples could Help Test the Claim
The seller says samples will be available to buyers before payment. That could give researchers a way to test the offer. A real sample may contain details that companies can compare with their own records. But one sample would not prove the entire listing.
A criminal could possess data from an old breach and offer it as new. The seller could also have data from several unrelated incidents. Researchers would need to check file dates, unique records and company-specific details.
They would also need to compare the files with known leaks. Until that happens, the ad remains a claim from an underground seller.
Toyota Financial has a Relevant History
Toyota Financial is one of the biggest names in the listing. In November 2023, Toyota Financial Services Europe & Africa confirmed unauthorized activity on some systems. The company took some systems offline while it investigated.
The Medusa ransomware group then claimed responsibility and demanded $8 million. Toyota later warned that customer information had been compromised in Germany. Reports show that both names, addresses and bank details leaked.
Security experts believe the attackers exploited the CitrixBleed flaw to gain access to the company’s system. That was a research view, not a confirmed finding from Toyota. Old Toyota data could therefore appear in a new underground sale. But it does not prove that the seller has new Toyota data.
Toyota’s latest annual report gives another key detail. Toyota Motor Corporation says it had no material cyber incident to date. It also says it found no cyber risk in fiscal 2026 that was likely to materially affect the company.
That statement does not rule out an incident at a smaller unit. It does show why the new claim needs careful checks.
Red Wing Shoe is also on the List
Red Wing Shoe Company is another name that appeared in the visible part of the listing. The company maintains an advisory where it warns customers about scams that impersonate its brand to collect sensitive information from users.
The advisory also warns about fake emails, social media posts, and fake websites, as well as other tricks attackers use to get consumers’ personal or payment information.
That warning is not proof of the alleged 176-company breach. We also found no credible public report linking Red Wing Shoe Company to a new breach that matches the forum claim.
The Mismatch with the Number of Companies Matters
The difference between 176 and 179 companies may seem small, but it adds doubt. A simple typo could explain the mismatch. The seller may also have changed the list without changing the title. There is also no public evidence showing that it was the same actor who hit all the companies they named.
The organizations span many industries and countries. The seller may have gathered data from many sources rather than carried out one large attack.
The $100,000 Price Proves Nothing
The asking price isn’t proof that the claim is valid. Criminals often price data either based on the type of data or the amount. Having a high price can make an offer appear very valuable. But that doesn’t mean the data is real.
It is difficult to determine if 100TB of data is good or not without knowing its composition. In order to make an assessment, they need to know exactly what data belongs to each company and whether the files are unique. Another thing they’d need to find out is how fresh the data is.
A similar unverified claim targeted Kraken in January 2026, with a threat actor offering alleged access to its support panel for $1. Kraken denied the claim, highlighting why dark web allegations require independent verification.
Right now, it boils down to this: someone says they’re selling data from several companies for $100,000. But there’s no independent proof backing up the full stash, the 100 TB number, or the claim that all 176 firms actually suffered breaches. The number mismatch adds another reason for caution.
Toyota Financial’s past breach shows that real stolen data can resurface in underground markets. But that history does not prove this new offer.
Until researchers examine samples and affected companies confirm the data, the listing should remain an unverified cybercrime-market claim.