LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ascoma Group Listed by akira Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Ascoma Group Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 12, 2025
Ascoma Group Listed by akira Ransomware Group

Reported March 12, 2025.

HIGH
Severity
March 12, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Ascoma Group was listed on March 12, 2025, by the Akira ransomware group, which claims to have stolen internal files. Individuals who may have shared personal or business information with Ascoma are advised to monitor their accounts and consider protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On March 12, 2025, the Ascoma Group was listed by the akira ransomware group, which claims responsibility for a ransomware attack involving the exfiltration of internal files. Public reporting indicates that the number of people affected remains unknown, and the precise scope of the incident has not been independently confirmed beyond the group's assertions. The listing matters because Ascoma operates in insurance and healthcare cost management, sectors that routinely handle sensitive personal and corporate records; any confirmed exposure could create lasting risks for employees, customers, and partners.

What is known so far rests largely on the ransomware group's own statements. Akira asserts it is prepared to release more than 12 GB of corporate material. No official confirmation of the breach's full extent, technical method, or remediation status has been detailed in the available record.

Inside the incident

According to the reported listing, Ascoma Group was named by akira as a victim of a ransomware attack in which internal files were exfiltrated. The date associated with the public report is March 12, 2025. The group states it holds more than 12 GB of essential corporate documents and is ready to upload them. No further public detail has been provided on the initial intrusion vector, the duration of unauthorized access, encryption of systems, or any ransom demand. The number of individuals whose information may be involved is listed as unknown. Because the primary source of these claims is the threat actor's leak-site posting, the details remain unverified assertions rather than independently established facts.

Ascoma itself has not been quoted in the available summary with any public statement acknowledging or denying the claims. Timing of the actual compromise, if it occurred, is undisclosed. Scale beyond the claimed data volume is likewise unconfirmed. In the absence of additional reporting, the incident is best understood as a claimed ransomware event centered on data theft rather than a fully documented operational disruption.

Inside akira

Akira is a ransomware operation that became active in early 2023 and has since been documented in multiple public cybersecurity analyses. The group typically employs a double-extortion model: it encrypts victim systems while simultaneously exfiltrating data, then threatens to publish the stolen material on a dedicated leak site if payment is not made. Akira has been observed targeting organizations across manufacturing, education, professional services, and other sectors, often gaining initial access through compromised credentials, vulnerable remote-access services, or phishing. Once inside a network, operators move laterally, disable security tools where possible, and stage large volumes of data for theft before deploying the ransomware payload.

The group maintains a Tor-based leak site where it posts victim names, sample files, and countdown timers. Listings are claims by the operators and do not by themselves prove successful compromise or the authenticity of every file set. Akira has previously released data from victims who did not pay, contributing to its reputation for following through on threats. Public knowledge of the group's tactics does not, however, extend to inventing specific statements about Ascoma beyond the content of the March 2025 listing itself. That listing asserts possession of more than 12 GB of Ascoma-related documents and readiness to publish them; those assertions should be treated as unverified claims until corroborated by independent sources or the victim organization.

About Ascoma Group

Ascoma Group maintains two cross-functional divisions. ASCOMA International serves as a coordination center for international operations. ASCOMA Health/PACTILIS functions as the group's competence center for health insurance, healthcare cost management, and personal insurance more broadly. Organizations of this type operate at the intersection of insurance underwriting, claims processing, and international coordination, routinely handling personal identifiers, policy details, medical-cost data, and corporate correspondence.

A breach involving such an entity is consequential because the data typically processed includes both employee records and customer information that can be sensitive or regulated. Even when the exact contents of any stolen set remain unconfirmed, the sector's reliance on accurate personal and health-related records means that unauthorized access can affect individuals' privacy, financial standing, and ability to manage insurance matters. The international dimension of Ascoma's operations further raises the possibility that data subjects in multiple jurisdictions could be implicated, though no geographic breakdown has been disclosed.

The information in question

The available facts state that internal files were exfiltrated in a ransomware attack. Akira specifically claims readiness to upload more than 12 GB of essential corporate documents, listing examples that include contact numbers and e-mail addresses of employees and customers, internal correspondences, passports, and other employee and customer documents. These categories are presented as the group's own description of the material; they have not been independently verified.

Because the precise contents remain unconfirmed, it is useful to note what organizations in health insurance and personal-insurance coordination typically hold: policyholder names and contact details, identification documents, medical-cost or claims-related records, employee personnel files, and internal business communications. Whether any of those categories actually appear in the claimed 12 GB set is unknown. Public detail on file types, volume of personal records, or presence of financial or medical data beyond the group's listed examples is limited. Readers should therefore treat the named categories as claimed rather than established fact.

The real-world impact

If the claimed data set is authentic, employees and customers whose contact details, correspondence, or identity documents appear could face elevated risks of phishing, social-engineering attempts, and identity misuse. Passport images or similar documents, if present, can be reused for fraudulent applications or account takeovers. Internal correspondence may reveal business relationships, negotiation details, or operational practices that competitors or fraudsters could exploit. For the organization itself, the incident—if confirmed—could entail regulatory notification obligations, potential contractual liabilities, and the operational cost of investigating and containing the event.

Because the number of people affected is unknown and the exact data types unconfirmed, the concrete scale of harm cannot yet be quantified. Even so, the combination of employee and customer records in an insurance context means that any verified exposure would require careful monitoring of credit activity, insurance accounts, and unsolicited communications. The absence of public confirmation does not eliminate risk; it simply leaves the full picture incomplete.

If your data was in this claimed breach

Individuals who have had dealings with Ascoma Group as employees or customers should remain alert for unexpected messages that reference insurance policies, personal details, or urgent requests for verification. Practical first steps include changing passwords on related accounts, enabling multi-factor authentication where available, and monitoring financial and insurance statements for irregularities. If identity documents such as passports are believed to be involved, consider placing fraud alerts with relevant credit or identity-protection services according to local procedures.

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan provides an additional data point but does not confirm or rule out involvement in this specific incident. Stay informed through official channels from Ascoma or competent authorities rather than relying solely on threat-actor claims.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAscoma Group security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Ascoma Group’s full breach history →

More recent breaches

Trubee Wealth Advisors Listed by akira Ransomware GroupDecember 24, 2025Rosland Capital Listed by akira Ransomware GroupDecember 5, 2025MD Manouel InsuranceAgency Listed by akira Ransomware GroupDecember 1, 2025Standing Chapter 13 Trustee Listed by akira Ransomware GroupNovember 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Ascoma Group Listed by akira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by akira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram