LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Baker Tilly Morrison Murray Listed by sarcoma Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Baker Tilly Morrison Murray Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 24, 2024
Baker Tilly Morrison Murray Listed by sarcoma Ransomware Group

Reported December 24, 2024.

HIGH
Severity
December 24, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Baker Tilly Morrison Murray was listed by the sarcoma ransomware group on December 24, 2024, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; individuals should check whether their information was involved and take any recommended protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Baker Tilly Morrison Murray, a firm of registered auditors and chartered accountants based in Westville, Durban, South Africa, was listed by the sarcoma ransomware group on 24 December 2024. Public reporting indicates that internal files were exfiltrated in a ransomware attack, though the number of people affected remains unknown and further operational details have not been disclosed.

The listing itself constitutes a claim by the group rather than independent confirmation of every asserted detail. For clients, staff and business partners of an accounting practice that handles sensitive financial and advisory material, the incident raises clear questions about the scope of any data exposure and the practical steps that may follow.

What happened

According to available public information, Baker Tilly Morrison Murray appeared on the sarcoma ransomware group’s leak site on 24 December 2024. The reported summary states that internal files were exfiltrated in a ransomware attack. No precise timeline for the intrusion, no confirmed volume of data, and no technical description of the initial access method have been released in the public record. The number of individuals potentially affected is listed as unknown. Beyond the group’s claim that internal files were taken, the exact contents and any subsequent publication of those files remain unconfirmed at the time of reporting.

Who is sarcoma?

Sarcoma is a ransomware operation that has been observed listing victims on dedicated leak sites after claiming to have stolen data. Like other groups in this category, it typically combines encryption of systems with the threat of publishing exfiltrated material if demands are not met. Public reporting on sarcoma has described a pattern of targeting organisations across multiple sectors and geographies, often publicising the names of claimed victims to increase pressure. In the present case, the group’s listing of Baker Tilly Morrison Murray should be treated as an unverified claim regarding the specific incident; no independent confirmation of the full extent of the intrusion or of any ransom negotiation has been provided in the available facts.

About Baker Tilly Morrison Murray

Baker Tilly Morrison Murray is a firm of Registered Auditors and Chartered Accountants located in Westville, Durban, South Africa. Its history reaches back to 1914, and it has developed a position as a niche provider of auditing and business advisory services in the local market. The firm operates as an independent member of Baker Tilly International, a global network of accountancy and business advisory practices. Organisations of this type routinely hold client financial records, tax documentation, audit working papers, correspondence and other commercially sensitive material. A ransomware incident affecting such a firm therefore carries potential consequences for both the practice itself and the clients who entrust it with confidential information.

What was likely exposed

The only data category named in the public facts is “internal files exfiltrated in ransomware attack.” No further breakdown—such as specific document types, client names, personal identifiers or financial figures—has been disclosed. Accounting and audit firms typically maintain client ledgers, tax filings, payroll data, contracts, email archives and internal operational records. Whether any of these categories were among the files taken remains unconfirmed. Readers should therefore treat statements about precise contents as speculative until official notification or verified evidence appears.

The real-world impact

For individuals and businesses whose information may have been held by the firm, the principal risks include potential misuse of financial details, targeted phishing that leverages knowledge of client relationships, and longer-term identity or fraud concerns if personal data were present. For the organisation, the incident can disrupt operations, require forensic investigation, trigger regulatory notification obligations under South African data-protection rules, and affect client trust. Because the number of people affected is unknown and the exact data types beyond “internal files” are undisclosed, the scale of these risks cannot yet be quantified. Affected parties will need to rely on any formal communications issued by the firm or by regulators once more information becomes available.

Were you affected?

If you are a current or former client, employee or supplier of Baker Tilly Morrison Murray, monitor communications from the firm for official notices. Review bank and credit statements for unusual activity, enable multi-factor authentication on financial and email accounts, and remain alert to unsolicited messages that reference the firm or recent audit work. As a practical first check, you can run a free exposure scan of your email address to see whether it has already appeared in known breach data sets. Keep records of any correspondence and consider consulting a trusted adviser if you receive confirmation that your information was involved.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyBaker Tilly Morrison Murray security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Baker Tilly Morrison Murray’s full breach history →

More recent breaches

Michelle Accesorios Listed by sarcoma Ransomware GroupDecember 26, 2024Kern Services Listed by sarcoma Ransomware GroupDecember 24, 2024CP Construplan Listed by sarcoma Ransomware GroupNovember 14, 2024Micon National Listed by sarcoma Ransomware GroupNovember 3, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Baker Tilly Morrison Murray Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram