LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Aeonsparx Listed by fog Ransomware Group

HIGH severityUnverified claimHow we verify

Aeonsparx Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 5, 2025
Aeonsparx Listed by fog Ransomware Group

Reported March 5, 2025.

HIGH
Severity
March 5, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Aeonsparx was listed by the fog ransomware group on March 05, 2025, with internal files reported to have been exfiltrated. Individuals who may have had data held by Aeonsparx are advised to check the organisation’s statements and consider protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For anyone whose information may sit inside Aeonsparx systems, the practical concern is straightforward: a ransomware group has publicly claimed to have taken internal files from the organisation. When internal material leaves an organisation without authorisation, the people connected to that organisation—employees, partners, customers or contractors—can face follow-on risks such as targeted phishing, credential misuse or exposure of business relationships. Public reporting so far leaves the scale and exact contents unclear, which means affected individuals cannot yet know with certainty whether their own data is involved.

On 5 March 2025, Aeonsparx appeared on a listing associated with the fog ransomware group. The available summary describes the incident as involving internal files exfiltrated in a ransomware attack and refers to an “Extract from The 19 biggest gitlabs.” No confirmed figure for the number of people affected has been released, and independent verification of the claim remains limited.

Breaking down the breach

According to the public listing, fog claims to have conducted a ransomware attack against Aeonsparx that included the exfiltration of internal files. The reported date of the listing is 5 March 2025. Beyond that headline claim and the brief summary referencing an extract linked to “The 19 biggest gitlabs,” further operational detail—such as the precise date of intrusion, the initial access method, the volume of data taken, or any ransom demand—has not been disclosed in the available record. The number of people whose information may be implicated is listed as unknown. Because the information originates from a threat-actor leak site, it should be treated as an unverified claim until corroborated by the organisation or independent investigators.

Who is fog?

Fog is a ransomware operation that became publicly visible in 2024. Like many contemporary groups, it is known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish or sell it if a ransom is not paid. Public reporting on fog has described the use of common initial-access techniques, rapid deployment of encryption, and the maintenance of a leak site where victims are named and sample data is sometimes posted. The group has been observed targeting a range of organisations rather than a single industry. In this instance, fog’s listing of Aeonsparx constitutes a claim by the group; it does not by itself prove the full extent of any intrusion or the accuracy of any accompanying description.

Who is Aeonsparx?

Public detail on Aeonsparx itself is limited in the breach record. The organisation’s name and the accompanying reference to GitLab-related material suggest a technology or software-development context, but no further official description is supplied in the available facts. Organisations that operate or manage large code repositories, development platforms or related infrastructure typically hold source code, configuration files, internal documentation, credentials, employee records and partner information. A breach involving such material can therefore affect not only the organisation’s own staff but also any third parties whose data or intellectual property resides in those systems. Until Aeonsparx or regulators provide additional context, the precise nature of its operations and the sensitivity of its holdings remain incompletely documented in open sources.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack. No inventory of specific data types—such as personal identifiers, financial records, source code, credentials or customer lists—has been published. The summary phrase “Extract from The 19 biggest gitlabs” appears in the reporting but does not enumerate file contents or confirm what was actually taken. Organisations that maintain substantial GitLab or similar development environments commonly store source code, issue trackers, access tokens, internal wikis and user account data. Whether any of those categories were present in the claimed extract, and whether personal data of individuals was included, remains unconfirmed. Readers should therefore treat any assumption about exact contents as speculative until further disclosure occurs.

What's at stake

For individuals, the primary risks are secondary misuse of any personal or professional information that may have been present: phishing that references internal projects, attempts to reuse credentials, or social-engineering attacks that exploit knowledge of business relationships. For the organisation, the stakes include potential disruption of development workflows, loss of proprietary material, regulatory notification obligations if personal data is involved, and reputational damage arising from the public claim itself. Because the number of people affected is unknown and the precise data types are undisclosed, the concrete impact cannot yet be quantified. Both the organisation and any potentially affected parties are left managing uncertainty rather than a fully mapped incident.

If your data was in this claimed breach

If you have a past or present relationship with Aeonsparx—employment, contracting, partnership or use of its services—treat the claim as a prompt for basic hygiene rather than confirmed personal exposure. Change passwords on any accounts that may have been linked to the organisation, enable multi-factor authentication where available, and remain alert to unexpected messages that reference internal projects or colleagues. Monitor financial and account statements for unusual activity. Because the full contents of the claimed exfiltration have not been verified, a free exposure scan of your email address against known breach datasets can provide an additional check on whether your information has already appeared in other public incidents. Keep records of any suspicious contact and consider notifying the organisation if you receive communications that appear to draw on internal knowledge.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAeonsparx security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Aeonsparx’s full breach history →

More recent breaches

The 19 biggest gitlabs Listed by fog Ransomware GroupMarch 5, 2025Melexis Listed by fog Ransomware GroupMarch 5, 2025Eumetsat Listed by fog Ransomware GroupMarch 5, 2025Blue Planet Listed by fog Ransomware GroupMarch 5, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Aeonsparx Listed by fog Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by fog — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram