LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Antenne Reunion Radio Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

Antenne Reunion Radio Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 9, 2024
Antenne Reunion Radio Listed by sarcoma Ransomware Group

Reported October 9, 2024.

HIGH
Severity
October 9, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On October 9, 2024, Antenne Reunion Radio was listed by the sarcoma ransomware group, which claims to have exfiltrated internal files. If you have any relationship with the station, review the available information and follow any guidance issued by the organization.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or professional details sit inside the systems of a local broadcaster may now face uncertainty about whether those records have left the organisation’s control. On 9 October 2024 the ransomware group sarcoma listed Antenne Reunion Radio on its leak site, claiming to have taken internal files. The number of individuals involved remains unknown, yet any exposure of internal material can create lasting practical problems for staff, partners and members of the public who appear in those files.

Public detail is limited to the group’s own listing and a reported archive size. What follows is a factual account of what is known, what is claimed, and what ordinary people can do next.

Inside the incident

On 9 October 2024 sarcoma added Antenne Reunion Radio to its public leak site. The group stated that it had exfiltrated internal files during a ransomware attack and that the resulting archive measured 146 GB and contained files. No further technical description of the intrusion method, the precise date of the attack, or the systems involved has been released by the organisation or by independent investigators. The number of people whose data may appear in the archive is listed as unknown. Because the only public source is the threat actor’s own claim, the scale and completeness of the alleged theft remain unverified.

No statement confirming or denying the listing has been issued in the material available for this report. Consequently the incident rests on the group’s assertion that internal files were taken and prepared for release.

Inside sarcoma

Sarcoma is a ransomware operation that follows a familiar double-extortion pattern: it encrypts systems and simultaneously copies data, then threatens to publish the material if a ransom is not paid. Like other groups of this type, it maintains a leak site where it posts victim names, sample files and download links for larger archives. Public reporting over recent years has shown sarcoma targeting organisations across multiple sectors and geographies, typically advertising the volume of data it claims to hold. The group’s listings are promotional claims; they are not independent confirmation that every file was successfully stolen or that every named organisation was in fact compromised.

In the present case the only specific assertion sarcoma has made about Antenne Reunion Radio is the listing itself, the 146 GB archive size, and the description “files.” No additional statements unique to this victim have been recorded in the available facts.

Who is Antenne Reunion Radio?

Antenne Reunion Radio forms part of the Antenne Réunion multimedia group, a French broadcaster based on the island of Réunion. The group operates television and radio services that hold a leading position in the local market and maintain a strong presence among the island’s population. As a regional media organisation it routinely handles programme material, staff records, commercial contracts, audience correspondence and operational documents.

A breach at such an organisation is consequential because local broadcasters sit at the intersection of public information, employment data and commercial relationships. Even when the precise contents of an archive are unconfirmed, the mere possibility that internal files have left the organisation’s control can affect employees, freelancers, advertisers and members of the public who have interacted with the station.

What data was at risk

The facts name the exposed material only as “internal files exfiltrated in a ransomware attack.” No inventory of specific data types—such as names, contact details, financial records or editorial documents—has been published. The group’s listing describes a 146 GB archive containing files, but offers no further breakdown.

Organisations of this kind typically store employee information, contributor contracts, advertising agreements, internal correspondence and programme-related documents. Whether any of those categories appear in the claimed archive is unconfirmed. Readers should therefore treat the exact contents as unknown until independent verification or an official disclosure is available.

What's at stake

For individuals, the practical risks centre on the possible misuse of any personal or professional information that may have been present in the internal files. Even limited exposure can lead to targeted phishing, identity-related fraud or unwanted contact. For the organisation the consequences include operational disruption, potential regulatory scrutiny under French and European data-protection rules, and the need to restore trust with staff and the local audience.

Concrete points to keep in mind:

Were you affected?

If you have worked for, contributed to, or corresponded with Antenne Reunion Radio or its parent group, treat the possibility of exposure seriously even though the exact data types remain unconfirmed. Change passwords on any accounts that may have been linked to the organisation, enable multi-factor authentication where available, and watch for unexpected messages that reference the station or local media. Monitor financial and identity accounts for unusual activity. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Official updates, if issued by the organisation or by French authorities, should be followed as the primary source of further guidance.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAntenne Reunion Radio security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Antenne Reunion Radio’s full breach history →

More recent breaches

Initiative Var Listed by sarcoma Ransomware GroupMarch 26, 2025Michelle Accesorios Listed by sarcoma Ransomware GroupDecember 26, 2024Baker Tilly Morrison Murray Listed by sarcoma Ransomware GroupDecember 24, 2024Kern Services Listed by sarcoma Ransomware GroupDecember 24, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Antenne Reunion Radio Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram