Eclipse

Active
9 victims named on the leak site
9 in the last 30 days
9 in the last 12 months
Aug 2026 first victim we recorded
Sep 15, 2026 most recent victim posted
1 leak site tracked

Data as of September 16, 2026.

What industries Eclipse targets

Sector identified for 7 of 9 victims.

Hospitality2
Logistics1
Manufacturing1
Financial Services1
Legal1
Education1

Where the victims are located

Country identified for 8 of 9 victims.

Singapore3
United States3
India1
France1

Every Eclipse victim

VictimSectorCountryPosted
Dublin City Schools dublincityschools.usEducationUnited StatesSep 15, 2026
Rosello & Fils rosello-fils.frNot identifiedFranceSep 15, 2026
The Zhou Law Group sanjoseattorneys.comLegalUnited StatesSep 9, 2026
TTG Asia Media ttgasia.comHospitalitySingaporeSep 9, 2026
Royal Plaza On Scotts royalplaza.com.sgHospitalitySingaporeSep 3, 2026
ETNA Software etnasoft.comFinancial ServicesUnited StatesAug 28, 2026
Simplex Engineering & Foundry Works simplexengg.inManufacturingIndiaAug 27, 2026
Crystal Pharmatech crystalpharmatech.comNot identifiedNot identifiedAug 22, 2026
Moscord moscord.comLogisticsSingaporeAug 17, 2026

Browse recent data breaches for more.

Eclipse leak site

The address we've seen Eclipse publish victims from. Any .onion address needs the Tor Browser.

  • eclipse4g5kxfwsvpu4qx5sdcnrji6gxl5gt67bucjlgt35g7akvjoid.onion

Eclipse questions

Is Eclipse still active?

Yes. Eclipse posted its most recent victim on September 15, 2026. That's 9 victims in the last 30 days.

How many victims has Eclipse claimed?

Eclipse has named 9 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Eclipse first appear?

The first victim we recorded for Eclipse was posted on August 17, 2026. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Eclipse target?

Hospitality accounts for the most victims we can classify, with 2. Logistics follows at 1. We could identify a sector for 7 of 9 victims, so treat this as the shape of the targeting rather than a full census.

Has Eclipse already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.