appen.com Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Appen.com was listed by the apt73 ransomware group on 17 October 2024, with internal files reported to have been exfiltrated. Individuals should check whether their information was exposed and take appropriate protective steps.
People who have registered with Appen or contributed data to its AI training platform may now face the practical risk that their personal and professional details have been taken by a ransomware group. On 17 October 2024 the organisation appen.com was listed by the group known as apt73, which claims to have exfiltrated internal files. The number of people affected remains unknown, yet the listing itself is enough to warrant careful attention from anyone whose email or account may be linked to the service.
Public detail is limited to the group’s claim and a reported summary of the material. No independent confirmation of the full scope has been released, so the immediate task for potentially affected individuals is to understand what is known, what remains unverified, and what concrete steps reduce further harm.
Inside the incident
According to the available record, appen.com was listed by the apt73 ransomware group on 17 October 2024. The group asserts that it carried out a ransomware attack and exfiltrated internal files. The reported summary describes the material as the registered user base of the appen.com platform, an AI training company, and cites 5 887 922 lines containing email addresses, employers, IP addresses, names, passwords and related fields. The exact method of intrusion, the date the intrusion began, and whether systems were encrypted or merely copied have not been publicly disclosed. The number of distinct individuals represented by those lines is also unknown. All that can be stated with certainty is that the listing appeared and that the group presented the data as stolen from Appen’s environment.
Inside apt73
apt73 is a ransomware group that operates by gaining access to corporate networks, exfiltrating data, and then publishing or threatening to publish the material on a leak site if payment is not made. Like other groups of this type, it typically claims responsibility for attacks against organisations across multiple sectors and uses the threat of public exposure as leverage. Public reporting on apt73 has documented a pattern of listing victims and releasing sample files to demonstrate possession of data. In the present case the group claims to have taken files from appen.com; that claim has not been independently verified beyond the listing itself. No additional statements from the group about this specific victim have been recorded in the available facts.
appen.com and its sector
Appen is a company that supplies data and annotation services used to train artificial-intelligence and machine-learning systems. Its platform recruits contributors—often freelancers or contractors—who perform tasks such as labelling images, transcribing audio or evaluating search results. Organisations of this kind routinely hold accounts for large numbers of registered users, including contact details, employment information, payment or tax identifiers, and technical logs such as IP addresses. Because the work involves personal data from many jurisdictions and because contributors may reuse credentials across platforms, a breach at an AI-data provider can affect both the company’s commercial clients and the individuals who supply the labour. The sector’s reliance on distributed remote workforces makes the volume of stored personal information especially large, which is why the reported scale of the listing is consequential even while exact confirmation remains pending.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack and summarise them as the registered user base of the appen.com platform. The reported contents include 5 887 922 lines listing email addresses, employers, IP addresses, names and passwords, among other fields. Beyond that summary the precise file inventory, the completeness of any password hashes or plaintext credentials, and whether additional categories such as financial or identity documents were present remain undisclosed. Organisations that run large contributor platforms typically store account registration data, task-history logs and communication records; it is therefore plausible that similar categories were among the files, yet the exact contents of this incident stay unconfirmed. Readers should treat the listed data types as the group’s claim rather than as a verified inventory.
What's at stake
For individuals whose details appear in the material, the immediate risks include credential stuffing if passwords were reused, targeted phishing that references real employment or project information, and possible identity-related fraud if names and contact data are combined with other breaches. Contributors who work as freelancers may also face unwanted contact from third parties who now know their association with AI training work. For Appen the stakes include operational disruption, potential regulatory scrutiny under data-protection regimes, and erosion of trust among the contributor community that supplies its core service. Because the number of people affected is unknown and the full data set has not been independently audited, the practical impact will become clearer only as further verification or notifications emerge. Until then the prudent assumption is that any registered user of the platform could be represented in the exfiltrated files.
What to do if you're exposed
If you have ever created an account or performed tasks for Appen, change any password that may have been used on that platform and ensure it is unique. Enable multi-factor authentication wherever it is available, and treat unsolicited messages that reference Appen projects or payments with caution. Monitor financial and email accounts for unusual activity. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets; doing so provides an early indication of whether further protective steps are warranted. Stay alert for any official notification from Appen itself, and avoid sharing additional personal details in response to unverified requests.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
www.prixet.com Listed by apt73 Ransomware Groupleadboxhq.com Listed by apt73 Ransomware Groupwww.certifiedinfosec.com Listed by apt73 Ransomware Groupwww.netromsoftware.ro Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the appen.com Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.