Miga

Quiet since September 25, 2025
7 victims named on the leak site
0 in the last 30 days
7 in the last 12 months
Sep 2025 first victim we recorded
Sep 25, 2025 most recent victim posted
2 leak sites tracked

Data as of August 16, 2026.

What industries Miga targets

Sector identified for 5 of 7 victims.

Retail1
Healthcare1
Hospitality1
Manufacturing1
Education1

Where the victims are located

Country identified for all 7 victims.

United States3
Singapore1
Switzerland1
Brazil1
China1

Every Miga victim

VictimSectorCountryPosted
Plaid Enterprises arteza.comRetailUnited StatesSep 25, 2025
Curaleaf curaleaf.comHealthcareUnited StatesSep 25, 2025
Ascott discoverasr.comHospitalitySingaporeSep 25, 2025
Kixat kixat.comNot identifiedSwitzerlandSep 25, 2025
Resideo resideo.comManufacturingUnited StatesSep 25, 2025
Unyleya Educacional unyleya.com.brEducationBrazilSep 25, 2025
WeChat wechat.comNot identifiedChinaSep 25, 2025

Browse recent data breaches for more.

Miga leak sites

Addresses we've seen Miga publish victims from. Any .onion address needs the Tor Browser.

  • q7gmt7pbo4rrt27ydkiv2kxd7cimhztq2x7hzd557jthhu5zp6ujieid.onion
  • pixeldrain.com

Miga questions

Is Miga still active?

It's gone quiet. The last victim we recorded was September 25, 2025, and nothing has appeared since. Groups do go quiet and come back, so we're still watching.

How many victims has Miga claimed?

Miga has named 7 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files.

When did Miga first appear?

The first victim we recorded for Miga was posted on September 25, 2025. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Miga target?

Retail accounts for the most victims we can classify, with 1. Healthcare follows at 1. We could identify a sector for 5 of 7 victims, so treat this as the shape of the targeting rather than a full census.

Has Miga already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.