Chema Per Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Chema Per was listed by the sarcoma ransomware group on November 30, 2024 after internal files were exfiltrated in a ransomware attack, though the exact date of the intrusion is not established. An undisclosed number of individuals may be affected; anyone connected to the organisation should check whether their data has been exposed and take appropriate protective steps.
Ransomware groups continue to pressure industrial and manufacturing firms by claiming to steal internal data and threatening public release, a pattern that has become a routine feature of the current threat landscape. Listings on leak sites often surface before independent confirmation, leaving organisations and the public to weigh unverified claims against limited official detail.
On 30 November 2024, the ransomware group sarcoma listed Chema Per, a Peruvian industrial company, as a victim. Public reporting indicates the group claims to have exfiltrated internal files in a ransomware attack, with a stated archive size of 60 GB. The number of people affected remains unknown, and many operational specifics have not been disclosed.
Breaking down the breach
According to available reporting, Chema Per was listed by the sarcoma ransomware group on 30 November 2024. The group claims the incident involved a ransomware attack in which internal files were exfiltrated. The leak-site material is described as a 60 GB archive containing files. No further public detail has been provided on the precise date of intrusion, the initial access method, encryption of systems, or any ransom demand. The number of individuals affected is unknown. Because the listing originates from the threat actor, it should be treated as an unverified claim unless independently confirmed by the organisation or other authoritative sources.
Public information does not describe whether systems were restored from backups, whether law enforcement was notified, or whether any data has actually been published beyond the listing itself. In short, the known facts are limited to the group’s claim of a ransomware-driven exfiltration of internal files totaling roughly 60 GB, reported on that date, involving the Peruvian firm Chema Per.
Inside sarcoma
Sarcoma is a ransomware operation that has appeared in public threat reporting as a group that conducts double-extortion style campaigns: encrypting systems while also claiming to steal data and threatening to leak it if demands are not met. Like many contemporary ransomware actors, it has used dedicated leak sites to name alleged victims and post sample material or archives as pressure tactics. Public analyses of such groups typically note opportunistic targeting across industries, use of common initial-access vectors such as compromised credentials or vulnerable remote services, and a focus on organisations whose operational continuity or sensitive internal documents create leverage.
For this incident, the only specific claim tied to Chema Per is the leak-site listing itself: that internal files were taken in a ransomware attack and that a 60 GB archive of files is associated with the victim. No additional statements from the group about this particular organisation—such as detailed file inventories, screenshots of unique systems, or confirmed publication of the full archive—are part of the public facts provided here. Any broader characterisation of sarcoma’s methods therefore rests on its established public profile rather than on new, incident-specific disclosures.
About Chema Per
Chema Per is described as a leading Peruvian company specialising in additives and products for industry, mining and construction, with more than 43 years of experience. Firms in this sector typically supply chemical additives, construction materials, and related industrial products to mining operators, builders and manufacturing clients across Peru and potentially regional markets. Their operations often involve technical formulations, supply-chain relationships, commercial contracts, and regulatory compliance documentation tied to mining and construction standards.
A breach affecting such an organisation is consequential because industrial and mining-adjacent companies frequently hold proprietary process information, customer and supplier records, financial data, and employee information. Disruption or exposure can affect production schedules, contractual obligations, and trust with partners in critical sectors of the Peruvian economy. The geographic focus on Peru also places the incident within a broader pattern of ransomware pressure on Latin American industrial firms, where operational technology and business systems can be tightly linked.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack and that the associated archive is described as 60 GB of files. No further breakdown of data types—such as employee records, customer lists, financial documents, intellectual property, or technical formulations—has been publicly named. Exact contents therefore remain unconfirmed.
Organisations of this kind commonly hold employee personal data, commercial contracts, supplier and customer information, technical product specifications, quality-control records, and internal correspondence. Whether any of those categories were present in the claimed 60 GB archive cannot be verified from the available reporting. Readers should treat the exposure as involving unspecified internal files rather than assuming particular categories of personal or proprietary data.
What's at stake
For individuals whose information may have been among the internal files, risks include potential misuse of contact details, employment data or other personal identifiers if such material was present—though that presence is unconfirmed. Identity fraud, targeted phishing, or social-engineering attempts that reference the company are realistic concerns when corporate data is claimed to have been stolen. For Chema Per itself, stakes include possible operational disruption from the ransomware event, reputational damage from the public listing, competitive harm if proprietary formulations or commercial terms may have been exposed, and regulatory or contractual obligations that may arise under Peruvian data-protection and industry rules.
Because the scale of affected people is unknown and the precise file contents are undisclosed, the full impact cannot yet be measured. The combination of a claimed 60 GB exfiltration and the company’s role in mining and construction supply chains nonetheless underscores that both personal privacy and industrial confidentiality could be implicated if the group’s claims prove accurate.
What to do if you're exposed
If you have a current or past relationship with Chema Per—as an employee, contractor, customer or supplier—treat the listing as a prompt to increase caution rather than as confirmed proof that your data was taken. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and be sceptical of unexpected messages that reference the company or request credentials or payments. Consider placing fraud alerts with relevant credit or identity services if you believe personal data may have been involved.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step will not confirm or rule out involvement in this specific incident, but it can help you prioritise further protective measures if your address surfaces elsewhere. Stay alert for any official statements from Chema Per that may clarify the scope of the event as more information becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Supraterra Listed by sarcoma Ransomware GroupImportadora Monterrey SRL Listed by sarcoma Ransomware GroupSöllner Listed by sarcoma Ransomware GroupMSB Listed by sarcoma Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Chema Per Listed by sarcoma Ransomware Group →
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.