Alleged data theft involves 86.7m session records, infrastructure maps, and threats against eight locations, without corroboration or ransom demand
Ransomware group N0n has on 18 September 2026 claimed an attack against Transcom WorldWide, an outsourced customer-support provider associated with PayPal operations.
The claim had appeared on a dark-web leak site, and was subsequently cataloged by ransomware trackers. N0n alleges that it has obtained 86.7m records documenting daily support-agent sessions involving PayPal’s corporate Citrix and authentication, authorisation and accounting systems, commonly known as AAA.
The group also claims to possess a detailed map of Transcom’s internal Active Directory and public-key infrastructure, as well as its Netskope and Zscaler security tenants across eight sites. All eight locations are subject to a network blackout pending settlement with a deadline of 21 September 21 at 03:01 UTC. However, no ransom demand has been made regarding the extent or nature of data theft. The 86.7m figure comes solely from N0n, and the group has provided no verifiable samples, documents, file listings, screenshots, or other artifacts to support its claims.
Cybersecurity advisory firm CyPro has characterised the listing as unconfirmed, and warns that it should not be treated as proof that Transcom or PayPal have actually been breached:
- The available information does not establish which Transcom legal entity, network, or operating environment was allegedly affected.
- It also does not show that PayPal’s broader corporate network, payment systems, or customer accounts were accessed.
- The 18 September date reflects when the allegation was reported, not necessarily when an intrusion or data theft occurred. No public confirmation has been issued by Transcom WorldWide or PayPal, and no trusted independent investigator, regulator, or security researcher has verified the claim.
Ransomware.live has described N0n as an emerging group and has advised readers to treat its allegations cautiously until corroborating evidence becomes available.
Past and possible N0n activities
The current claim is part of a broader burst of alleged activity attributed to N0n, which also listed organisations including the United Federation of Teachers and digital-securities platform STOKR on the same day.
Ransomware.live has similarly marked the teachers’ federation claim as requiring independent verification.
Separately, PayPal had recently disclosed an incident involving its loan application software, in which a coding error had exposed the personal information of a small number of customers to unauthorised individuals between 1 July and 3 December, 2025; the affected information could include names, contact details, business addresses, social security numbers, and dates of birth. That exposure was linked to an application coding error, not a confirmed ransomware intrusion.
Analysts maintain that, until Transcom, PayPal, or a credible independent source provide evidence, the incident should be described as an unverified extortion-site claim rather than a confirmed ransomware attack.
