Anglo American plc Listed by arkana Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Anglo American plc was listed by the arkana ransomware group on May 21, 2025, after an undisclosed number of internal files were taken. Individuals whose information may have been involved should review any notices from the company and change passwords or enable additional security steps where appropriate.
On 21 May 2025, the multinational mining company Anglo American plc was listed by the ransomware group known as arkana. The group claims that internal files were exfiltrated during a ransomware attack. Public reporting has not confirmed the scale of any intrusion, the number of people affected, or the precise methods used. What is known so far is limited to the listing itself and the description of the data as internal files.
For a company of this size and global footprint, even an unverified claim of data theft raises practical questions for employees, contractors, partners and others whose information may have been held in corporate systems. The absence of Reported Details means the full picture remains incomplete.
Inside the incident
According to available records, Anglo American plc appeared on a listing associated with the arkana ransomware group on 21 May 2025. The reported description states that internal files were exfiltrated in a ransomware attack. No further public detail has been provided on the date the alleged intrusion began, how long any access lasted, which systems were involved, or whether encryption of systems occurred alongside the claimed data theft.
The number of people affected is listed as unknown. No file counts, sample documents, ransom demands or confirmation from the company itself appear in the available facts. Because the listing originates from the threat actor, it remains an unverified claim unless independently confirmed. Timing beyond the reporting date, the exact attack vector and the volume of data involved are all undisclosed.
Inside arkana
Arkana is a ransomware group that has operated in the double-extortion model common among several modern ransomware operators. In this approach, groups typically gain access to a network, exfiltrate data, and then encrypt systems while threatening to publish or sell the stolen material if a ransom is not paid. Listings on dedicated leak sites serve both as pressure on the victim and as a public signal of claimed success.
Public reporting on arkana has described it as one of several groups that post victim names and, in some cases, samples or larger data sets after deadlines pass. Its tactics generally align with those of other ransomware operations: initial access through phishing, compromised credentials or unpatched vulnerabilities, followed by lateral movement, data staging and exfiltration. Specific claims made by arkana about Anglo American plc beyond the listing and the reference to internal files are not detailed in the available facts; any broader assertions about this particular incident should be treated as the group’s own statements rather than established fact.
Who is Anglo American plc?
Anglo American plc is a multinational mining corporation with headquarters associations in Johannesburg, South Africa, and London, United Kingdom. Founded in 1917, it ranks among the world’s largest mining and natural-resource companies. It is a leading producer of platinum and diamonds and also extracts copper, nickel, iron ore, and both metallurgical and thermal coal. Operations span more than 40 countries.
Organisations of this type routinely manage large volumes of operational, financial, geological and human-resources data. They maintain relationships with employees, contractors, suppliers, joint-venture partners and government entities across multiple jurisdictions. A claimed breach therefore carries potential consequences that extend beyond a single office or country, affecting people and business processes that rely on the confidentiality and integrity of corporate systems.
The information in question
The available facts describe the exposed material as “internal files exfiltrated in a ransomware attack.” No more granular inventory—such as employee records, financial documents, operational plans, customer or partner data, or technical schematics—has been publicly named or confirmed. Exact contents therefore remain unconfirmed.
Companies in the mining and natural-resources sector typically hold a range of sensitive information: personnel files, payroll and benefits data, contractor and supplier contracts, exploration and production data, environmental and regulatory filings, and internal communications. Whether any of those categories were among the files claimed by arkana is not established by the current public record. Readers should treat the precise nature of the material as unknown until further verified disclosure occurs.
Why it matters
When internal files are claimed to have left an organisation, the practical risks fall on both individuals and the company. For people whose personal or professional details may have been stored in those systems, possible outcomes include targeted phishing, identity fraud, or misuse of contact and employment information. Even without confirmation that personal data was included, the uncertainty itself can create lasting concern.
For Anglo American plc, a ransomware-related listing can disrupt operations, require forensic investigation and notification processes, and affect relationships with partners, regulators and investors. Reputational and contractual consequences may follow regardless of whether a ransom is paid or data is ultimately published. Because the number of people affected is unknown and the data types are only broadly described, the full scope of exposure cannot yet be measured. The incident underscores the value of treating any such claim seriously while waiting for clearer official information.
If your data was in this claimed breach
If you have a current or past relationship with Anglo American plc—as an employee, contractor, supplier or other contact—consider practical steps. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and be cautious of unexpected messages that reference the company or request personal details. Change passwords on any accounts that may have shared credentials with work systems. Keep records of any suspicious contact.
Public confirmation of exactly whose data was involved has not been issued. Readers can run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Doing so provides one additional data point while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Infinox Listed by arkana Ransomware GroupTicketmaster Listed by arkana Ransomware GroupSynopsys Listed by arkana Ransomware GroupOregon Surveillance Network - OSN! Listed by arkana Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Anglo American plc Listed by arkana Ransomware Group →
Publicly posted by arkana — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.