LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › agc.com Listed by blackbasta Ransomware Group

HIGH severityUnverified claimHow we verify

agc.com Listed by blackbasta Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 17, 2023
agc.com Listed by blackbasta Ransomware Group

Reported December 17, 2023.

HIGH
Severity
December 17, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The agc.com Listed by blackbasta Ransomware Group (reported December 17, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 17 December 2023, the ransomware group known as blackbasta listed agc.com among the organisations it claims to have attacked. Public detail remains limited: the number of people affected is unknown, and independent confirmation of the full scope has not been published. What is stated is that internal files were exfiltrated. For employees, contractors, partners and others whose information may sit inside those systems, the practical stakes are straightforward—possible exposure of workplace records, personal folders and business data that could be misused for fraud, social engineering or further intrusion.

This article sets out only what has been reported, places the claim in context, and outlines concrete steps people can take while the picture stays incomplete.

What happened

According to the available record, agc.com was listed by the blackbasta ransomware group on 17 December 2023. The group claims that internal files were exfiltrated in a ransomware attack and that the volume of data involved totals 1.5 TB. Categories referenced in the listing include users’ personal folders, technology material, human-resources material, finance material and other internal content. The precise method of initial access, the duration of any dwell time, and whether systems were encrypted as well as copied have not been publicly detailed in the facts provided. The number of individuals whose data may be involved remains unknown.

Because the information originates from a threat-actor leak-site listing, it should be treated as an unverified claim unless and until the organisation or independent investigators state the details. No dollar amounts, specific file names beyond the broad categories, or further technical indicators are supplied in the public summary.

Who is blackbasta?

Blackbasta is a ransomware operation that emerged in public reporting in 2022. Like other groups in this category, it has typically combined data theft with encryption, then pressured victims by threatening to publish stolen material on a dedicated leak site. The group has been observed using common initial-access routes such as compromised credentials, phishing and exploitation of exposed services, followed by lateral movement and bulk exfiltration before ransomware deployment. Its listings have previously named organisations across manufacturing, professional services and other sectors. These patterns are drawn from widely reported public knowledge of the actor; they do not constitute proof of the exact tactics used against agc.com in this specific case.

When blackbasta lists a victim, the listing itself is a claim. It does not automatically establish that every asserted file was taken or that every asserted category is accurate. Organisations and affected individuals therefore treat such announcements as indicators that warrant verification rather than as settled fact.

agc.com and its sector

AGC Inc., operating principally through agc.com, traces its origins to Asahi Glass, founded in 1907 in Japan. It is a major global producer of flat glass and related materials, with operations that have included plants and subsidiaries in Europe and North America. Headquartered at 1-5-1 Marunouchi, Tokyo, the company sits in the advanced materials and manufacturing sector, supplying glass and chemical products used in construction, automotive, electronics and industrial applications.

Organisations of this scale routinely hold substantial internal repositories: employee and contractor records, technical designs and process documentation, financial and procurement data, and correspondence with suppliers and customers. A breach affecting such an enterprise is consequential because the data can touch both workforce privacy and commercially sensitive information that competitors or criminals might exploit. The listing does not, by itself, prove negligence or state the full extent of any compromise; it simply places the organisation’s name in a public claim that requires careful follow-up.

What was likely exposed

The facts name the exposed material as internal files exfiltrated in a ransomware attack. The threat actor’s listing further asserts a total size of 1.5 TB and enumerates broad categories. Exact contents and the identities of any affected individuals remain unconfirmed in independent public reporting. In that light, the concrete points claimed are:

Companies in manufacturing and materials science typically retain personnel files, payroll and benefits data, technical drawings, research notes, supplier contracts and financial ledgers. Whether any of those specific record types were present in the claimed 1.5 TB set is not independently verified here. Readers should therefore regard the categories as the actor’s assertion rather than as a confirmed inventory.

The real-world impact

For individuals, the main risks are secondary misuse of any personal or employment data that may have been taken—phishing that references real internal details, identity fraud if identifiers were present, or targeted social engineering against staff and families. Because the count of affected people is unknown, it is not possible to state how widely those risks extend. For the organisation, exposure of technology, finance or human-resources files can create operational, competitive and regulatory pressures, including the need to notify regulators or individuals where laws require it, to reset credentials, and to review third-party access.

None of these outcomes is automatic. Impact depends on what was actually copied, whether the data were encrypted or otherwise protected, how quickly containment and notification occur, and whether the material appears for sale or publication. Calm, evidence-based response remains more useful than speculation.

If your data was in this claimed breach

If you have a past or present connection to AGC—as an employee, contractor, supplier contact or similar—treat the listing as a prompt to tighten ordinary defences rather than as proof that your records were taken. Change passwords on work-related and personal accounts that may have shared credentials, enable multi-factor authentication wherever it is offered, and watch for unexpected messages that cite internal projects, colleagues or financial details. Monitor financial and credit statements for unfamiliar activity. If you receive notification directly from the company, follow the instructions it provides; those instructions will be more specific than general advice.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That check will not confirm or deny involvement in this particular incident, but it can surface other exposures that deserve attention. Keep records of any suspicious contact and report clear fraud attempts to the relevant authorities. Public detail on this event is still limited; further verified information, if it emerges, should guide any additional steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyagc.com security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See agc.com’s full breach history →

More recent breaches

SYNQUESTLABS Listed by blackbasta Ransomware GroupAugust 17, 2023unitedindustries.co.nz Listed by blackbasta Ransomware GroupDecember 21, 2023cinfab.com Listed by blackbasta Ransomware GroupDecember 20, 2023envea.global Listed by blackbasta Ransomware GroupDecember 11, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the agc.com Listed by blackbasta Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by blackbasta — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram