Skip to content
[N0N] – Ransomware Victim: PayPal support operations (Transcom WorldWide)

[N0N] – Ransomware Victim: PayPal support operations (Transcom WorldWide)

Redpacketsecurity admin September 18, 2026

Verification alert Listings attributed to N0N have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity

See further information here: BankInfoSecurity

NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating to the content should be directed at the attackers, not RedPacket Security. This blog is an editorial notice informing that a company has fallen victim to a ransomware attack. RedPacket Security is not affiliated with any ransomware threat actors or groups and will not host infringing content. The information on this page is automated and redacted whilst being scraped directly from the N0N Onion Dark Web Tor Blog page.

AI Generated Summary of the Ransomware Leak Page

On September 18, 2026, a ransomware leak-site post identified PayPal support operations (Transcom WorldWide) as an alleged victim in the financial services sector. The post describes the organization as providing outsourced customer-support operations connected with financial services in the Netherlands and Tunisia. No compromise date is provided, so September 18, 2026, should be treated as the post date rather than a confirmed intrusion date. The listed impact is not explicitly categorized as encryption or data theft; however, the claims indicate alleged access to operational and infrastructure information. According to the post, the threat actor claims to possess 86.7 million connection records documenting daily support-agent sessions involving PayPal corporate Citrix and AAA systems. The post also claims to include a complete infrastructure map covering internal Active Directory and public key infrastructure environments, Netskope and Zscaler tenants, and all eight operational sites. It further alleges that all eight sites are enforcing a network blackout pending settlement and sets an active deadline of September 21, 2026, at 03:01 UTC. No ransom amount is stated. The page contains no screenshots or other images, and no downloadable files are indicated.

On September 18, 2026, a ransomware leak-site post identified PayPal support operations (Transcom WorldWide) as an alleged victim in the financial services sector. The post describes the organization as providing outsourced customer-support operations connected with financial services in the Netherlands and Tunisia. No compromise date is provided, so September 18, 2026, should be treated as the post date rather than a confirmed intrusion date. The listed impact is not explicitly categorized as encryption or data theft; however, the claims indicate alleged access to operational and infrastructure information.

According to the post, the threat actor claims to possess 86.7 million connection records documenting daily support-agent sessions involving PayPal corporate Citrix and AAA systems. The post also claims to include a complete infrastructure map covering internal Active Directory and public key infrastructure environments, Netskope and Zscaler tenants, and all eight operational sites. It further alleges that all eight sites are enforcing a network blackout pending settlement and sets an active deadline of September 21, 2026, at 03:01 UTC. No ransom amount is stated. The page contains no screenshots or other images, and no downloadable files are indicated.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Countries (2)

Industries (1)

Platforms (1)