Falcon Ransomware Group: First Three Victims All NYSE-Listed
Falcon, a ransomware group first seen in August 2026, listed Globus Medical, DNOW and Hayward Holdings in 48 hours. All three are NYSE-listed. Here's why.

What the Falcon ransomware group claimed, and when
Globus Medical appeared on 30 August, alongside a claim of some 2.96 terabytes. DNOW, the energy distributor formerly known as DistributionNOW, was posted the same day at around 344 gigabytes. Hayward Holdings followed on the 31st, with roughly 848 gigabytes described as including Salesforce records, distributor pricing, financial documents and customer data with personal information attached.
The group calls itself Falcon. It was first observed in August 2026, it appears to be financially motivated, and it does not seem to be in the business of encrypting anything. There is no reporting of downed systems or ransom notes on locked screens. Falcon steals the data and threatens to publish it — the data extortion model that has displaced classic file encryption across most of the ransomware ecosystem.
What is unusual is the guest list.
Table of Falcon ransomware victims Globus Medical, DNOW and Hayward Holdings with NYSE tickers and claimed data volumes
Three victims, one stock exchange
Globus Medical trades on the New York Stock Exchange as GMED. Hayward Holdings trades as HAYW. DNOW trades under its own name. Falcon's first three publicly known victims are all NYSE-listed companies, and there is no other attribute they share.
Why a public company is worth more to a data extortion group
Since December 2023, a public company in the United States that determines it has suffered a material cybersecurity incident must disclose it on a Form 8-K within four business days. The SEC wrote the rule to stop investors being kept in the dark, and it does that. It also hands anyone extorting a listed company something a private-company victim cannot offer: a deadline enforced by somebody else.
A private firm that is quietly negotiating can take as long as its nerve holds. A listed one is running two clocks at once, and only one of them belongs to the attacker. The disclosure is coming regardless. The only question the victim controls is whether it arrives as a filing they wrote calmly, or one they wrote after a criminal published first and the story was already moving.
Falcon in context: twelve new ransomware groups in a single week
None of which is a reason to panic about Falcon in particular. New ransomware groups appear constantly, and most are gone within a year — absorbed, rebranded or arrested. Twelve leak sites published a first victim in the same week these three listings went up.
What makes this one worth a second look is the shape of the opening move. New groups usually begin where resistance is lowest, which is why the first weeks of most leak sites are full of dental practices, small manufacturers and regional accountancy firms. Falcon opened with three companies that file quarterly, answer to institutional shareholders and have a regulator waiting on the disclosure.
Either that is luck, or somebody worked out that the most useful thing about a listed victim is not the size of the balance sheet. It is the obligation to talk.
Two more names in the next month will settle which.
