Baker Tilly Morrison Murray Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Baker Tilly Morrison Murray was listed by the sarcoma ransomware group on December 24, 2024, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; individuals should check whether their information was involved and take any recommended protective steps.
Baker Tilly Morrison Murray, a firm of registered auditors and chartered accountants based in Westville, Durban, South Africa, was listed by the sarcoma ransomware group on 24 December 2024. Public reporting indicates that internal files were exfiltrated in a ransomware attack, though the number of people affected remains unknown and further operational details have not been disclosed.
The listing itself constitutes a claim by the group rather than independent confirmation of every asserted detail. For clients, staff and business partners of an accounting practice that handles sensitive financial and advisory material, the incident raises clear questions about the scope of any data exposure and the practical steps that may follow.
What happened
According to available public information, Baker Tilly Morrison Murray appeared on the sarcoma ransomware group’s leak site on 24 December 2024. The reported summary states that internal files were exfiltrated in a ransomware attack. No precise timeline for the intrusion, no confirmed volume of data, and no technical description of the initial access method have been released in the public record. The number of individuals potentially affected is listed as unknown. Beyond the group’s claim that internal files were taken, the exact contents and any subsequent publication of those files remain unconfirmed at the time of reporting.
Who is sarcoma?
Sarcoma is a ransomware operation that has been observed listing victims on dedicated leak sites after claiming to have stolen data. Like other groups in this category, it typically combines encryption of systems with the threat of publishing exfiltrated material if demands are not met. Public reporting on sarcoma has described a pattern of targeting organisations across multiple sectors and geographies, often publicising the names of claimed victims to increase pressure. In the present case, the group’s listing of Baker Tilly Morrison Murray should be treated as an unverified claim regarding the specific incident; no independent confirmation of the full extent of the intrusion or of any ransom negotiation has been provided in the available facts.
About Baker Tilly Morrison Murray
Baker Tilly Morrison Murray is a firm of Registered Auditors and Chartered Accountants located in Westville, Durban, South Africa. Its history reaches back to 1914, and it has developed a position as a niche provider of auditing and business advisory services in the local market. The firm operates as an independent member of Baker Tilly International, a global network of accountancy and business advisory practices. Organisations of this type routinely hold client financial records, tax documentation, audit working papers, correspondence and other commercially sensitive material. A ransomware incident affecting such a firm therefore carries potential consequences for both the practice itself and the clients who entrust it with confidential information.
What was likely exposed
The only data category named in the public facts is “internal files exfiltrated in ransomware attack.” No further breakdown—such as specific document types, client names, personal identifiers or financial figures—has been disclosed. Accounting and audit firms typically maintain client ledgers, tax filings, payroll data, contracts, email archives and internal operational records. Whether any of these categories were among the files taken remains unconfirmed. Readers should therefore treat statements about precise contents as speculative until official notification or verified evidence appears.
The real-world impact
For individuals and businesses whose information may have been held by the firm, the principal risks include potential misuse of financial details, targeted phishing that leverages knowledge of client relationships, and longer-term identity or fraud concerns if personal data were present. For the organisation, the incident can disrupt operations, require forensic investigation, trigger regulatory notification obligations under South African data-protection rules, and affect client trust. Because the number of people affected is unknown and the exact data types beyond “internal files” are undisclosed, the scale of these risks cannot yet be quantified. Affected parties will need to rely on any formal communications issued by the firm or by regulators once more information becomes available.
Were you affected?
If you are a current or former client, employee or supplier of Baker Tilly Morrison Murray, monitor communications from the firm for official notices. Review bank and credit statements for unusual activity, enable multi-factor authentication on financial and email accounts, and remain alert to unsolicited messages that reference the firm or recent audit work. As a practical first check, you can run a free exposure scan of your email address to see whether it has already appeared in known breach data sets. Keep records of any correspondence and consider consulting a trusted adviser if you receive confirmation that your information was involved.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Michelle Accesorios Listed by sarcoma Ransomware GroupKern Services Listed by sarcoma Ransomware GroupCP Construplan Listed by sarcoma Ransomware GroupMicon National Listed by sarcoma Ransomware GroupLatest breaches
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.