Data breach
Novum Energy
- Records
- 228,651
- Breach date
- 26 July 2026Estimated
- Added
- 31 July 2026
What was exposed
11 types of data · 4 put you at serious risk
- Email addresses228,651
- Names25,756
- Driving licence numbers15,293
- Phone numbers13,554
- Passport numbers8,075
- Street addresses1,295
- Licence plates1,065
- Dates of birth906
- Vehicle VINs312
- Bank account numbers155
- Social security numbers25
About this breach
Global Secret Group, a ransomware and data extortion operation, listed Novum Energy on its dark web leak site on July 26, 2026, claiming it had stolen data from the Texas-based energy company. The group said it exfiltrated 842 GB of material, which it described as roughly 971,000 files across 117,000 folders, and threatened to publish the full leak unless the company negotiated. The claim has not been independently confirmed by Novum Energy. According to Ransomware.live, which tracks ransomware group postings, the listing was discovered on July 26, 2026, and the group described Novum Energy as a company in the convenience store and gas station sector with estimated revenue of $966 million.
The investigation team estimates the attack occurred on or around July 26, 2026, and indexes the listing at 228,651 records. Reporting on the incident has come mainly from threat-tracking services, including Ransomware.live, Dexpose, and HookPhish, which all cite the group's own leak site posting.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: 228,651
Names: 25,756
Driver license numbers: 15,293
Phone numbers: 13,554
Passport numbers: 8,075
Dates of birth: 906
Street addresses: 1,295
Vehicle license plates: 1,065
Vehicle identification numbers (VINs): 312
Bank account details: 155
Social Security numbers: 25
Not every individual is affected by every type of data listed here.
Because the listing stems from a claimed wholesale exfiltration of company files, the exact contents of those files are not fully cataloged, and the count above reflects what our investigation team identified in the indexed data.
What Are the Potential Risks for Affected Individuals?
The combination of government identification numbers with names, dates of birth, and addresses creates a realistic risk of identity theft and account fraud. Passport and driver license numbers can be used to impersonate someone in verification checks, and Social Security numbers are the key ingredient in opening fraudulent lines of credit.
Email addresses and phone numbers in this breach also support targeted phishing. Because the affected company operates in energy and fuel retail, criminals may craft convincing messages that reference billing, deliveries, or account verification. Bank account details, though limited in count, carry a direct fraud risk where present.
What Should You Do If You Were Affected?
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks most new credit from being opened in your name.
Check your credit reports for accounts you do not recognize at AnnualCreditReport.com.
Request an IRS Identity Protection PIN if you are concerned about tax-related identity fraud.
Consider a fraud alert or an extended fraud alert if you have evidence of misuse.
Be cautious with unexpected emails, texts, or calls that ask for personal details, login credentials, or payments, even if they reference a real company or account.
If your bank details were involved, monitor your statements for unfamiliar transactions and alert your bank promptly.
Change passwords on any accounts tied to the exposed email address and enable two-factor authentication where offered.
