Acos Favorit Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Acos Favorit was listed by the Rhysida ransomware group on April 22, 2025, after internal files were exfiltrated in a ransomware attack. Individuals should check whether their information was affected and take steps to secure their accounts.
Ransomware groups continue to target industrial and distribution firms as part of a broader pattern of double-extortion attacks, in which data is stolen before systems are encrypted and victims are threatened with public release. On April 22, 2025, the group known as rhysida listed Acos Favorit on its leak site, claiming to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise scope is limited.
For an organisation that cuts and distributes specialised steels, any confirmed compromise of internal files raises questions about operational continuity, commercial confidentiality and the personal data of employees or partners that may have been stored alongside business records. What follows is a factual account based solely on the reported listing and the limited information available.
Inside the incident
According to the reported summary, Acos Favorit was listed by the rhysida ransomware group on April 22, 2025. The group claims that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access vector, the duration of the intrusion, the volume of data taken, or whether encryption was successfully deployed—have been publicly disclosed. The number of individuals whose information may have been involved is listed as unknown. At present the listing itself constitutes an unverified claim by the threat actor; independent confirmation of the breach’s full extent has not been provided in the available record.
Inside rhysida
Rhysida is a ransomware operation that emerged in public reporting in 2023 and has since been associated with attacks on healthcare, education, government and commercial targets. The group typically employs a double-extortion model: after gaining access, operators exfiltrate data and then encrypt systems, threatening to publish the stolen material on a dedicated leak site if a ransom is not paid. Rhysida has been observed using phishing, compromised credentials and exploitation of remote-access services as common entry points, though the precise method used against any individual victim is rarely confirmed in open sources. Listings on its leak site are presented by the group as evidence of successful intrusion; they remain claims until corroborated by the victim organisation or independent investigators. Prior activity attributed to rhysida has included the publication of internal documents, employee records and customer data from other organisations, underscoring the group’s focus on pressuring victims through the threat of exposure.
Who is Acos Favorit?
Acos Favorit Distribuidora Ltda was founded in 1996 by Rudolf Fritsch. The company specialises in the cutting and distribution of special steels for tools, stainless bars, mechanical construction steels, structural beams and mechanical tubes. As a mid-sized industrial distributor, it operates at the intersection of manufacturing supply chains, serving clients that require precise material specifications for tooling, construction and mechanical applications. Organisations of this type routinely maintain inventories of customer orders, supplier contracts, pricing data, quality-control records and employee information. A breach affecting such a firm can therefore touch both commercial secrets and personal data, with potential ripple effects across the supply chain that depends on reliable steel supply.
What was likely exposed
The only data type named in the available record is “internal files” said to have been exfiltrated in the ransomware attack. No inventory of specific file categories, document titles or data fields has been released. Companies engaged in steel cutting and distribution typically hold a range of internal material: purchase and sales ledgers, technical drawings or material certificates, employee personnel files, email correspondence, and customer contact lists. Whether any of these categories were among the files claimed by rhysida remains unconfirmed. Public detail is limited to the group’s assertion that internal files were taken; the exact contents and sensitivity of those files have not been independently verified.
What's at stake
For individuals whose information may reside in the claimed files, the primary risks are identity-related misuse, targeted phishing that leverages accurate personal or employment details, and potential financial fraud if banking or payroll data were present. For Acos Favorit itself, exposure of commercial documents could reveal pricing strategies, supplier relationships or client lists to competitors, while any disruption to operations could affect delivery schedules for specialised steels. Reputational harm and the cost of forensic investigation, system restoration and possible regulatory notification also form part of the practical consequences. Because the number of people affected is unknown and the precise data set is undisclosed, the full scale of these risks cannot yet be quantified.
If your data was in this claimed breach
If you have a past or present connection to Acos Favorit—as an employee, contractor, customer or supplier—consider monitoring financial accounts and credit reports for unusual activity and treating unsolicited messages that reference the company with caution. Change passwords on any accounts that may have shared credentials with work systems, and enable multi-factor authentication where available. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official updates from the organisation, if issued, should be followed for any specific guidance on notification or remediation steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Tex-Tube Listed by rhysida Ransomware GroupPeavey Electronics Corporation Listed by rhysida Ransomware GroupElite Trailers Listed by rhysida Ransomware GroupTrans-Tex Listed by rhysida Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Acos Favorit Listed by rhysida Ransomware Group →
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.