Dona Formosa Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Dona Formosa was listed by the sarcoma ransomware group on January 16, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may be affected; anyone connected to the organisation should check for signs of exposure and take protective steps.
People connected to Dona Formosa—employees, suppliers, retail partners or others whose details may sit in company systems—now face the practical possibility that internal files taken in a ransomware attack could surface online or be misused. The listing of the company by the group sarcoma, reported on 16 January 2025, is the public signal that such material may have left the organisation’s control. Exact numbers of people affected remain unknown, and the full contents of the files have not been independently verified, so the immediate task for anyone who deals with the firm is simply to treat the claim seriously and take basic protective steps.
What is known so far is limited to the group’s own assertion that internal files were exfiltrated. No confirmed count of records, no public sample of the data, and no statement from Dona Formosa itself appear in the available record. That scarcity of detail does not remove the risk; it only means affected individuals must act on the information that does exist rather than wait for fuller disclosure.
Inside the incident
According to the reported listing, Dona Formosa was named by the sarcoma ransomware group on 16 January 2025. The group states that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the date the intrusion began, the volume of data taken, or whether systems were also encrypted—have been made public. The number of people whose information may be involved is listed as unknown. The incident is therefore known only through the group’s claim on its leak site; independent confirmation of the breach’s scale or success has not been published.
Public reporting on the matter consists of the headline that Dona Formosa was listed and the accompanying note that internal files were taken. Beyond that, timing of the intrusion, any ransom demand, and the current status of the data remain undisclosed.
The group behind it: sarcoma
Sarcoma is a ransomware operation that follows the now-common double-extortion model: after gaining access to a network it both encrypts systems and copies data, then threatens to publish the stolen material if a ransom is not paid. Like other groups of this type, it maintains a leak site where it posts victim names and, in some cases, samples or full archives of the claimed data. Its listings are public assertions rather than Reported Facts; victims sometimes confirm the intrusion later, sometimes dispute the claims, and sometimes remain silent.
The group’s typical tactics include phishing or exploitation of remote-access services to enter networks, followed by lateral movement, data staging and exfiltration before encryption. Prior activity attributed to sarcoma has involved organisations across manufacturing, logistics and professional services, though each listing must be evaluated on its own evidence. In the present case the only claim on record is that Dona Formosa’s internal files were taken; no additional statements by the group about this specific victim have been reported.
Who is Dona Formosa?
Dona Formosa is a dairy-products manufacturer and distributor that has operated since 1999. Its own description states that it produces dairy goods and distributes partner brands, supplying restaurants, buffets, industrial kitchens and large supermarket chains. The company emphasises quality recognition by professional chefs and a broad retail footprint. As a mid-sized food manufacturer and wholesaler it necessarily maintains records of suppliers, customers, employees, logistics partners and product specifications—exactly the categories of internal material that ransomware groups routinely target.
A breach at such an organisation is consequential because the food-supply chain depends on trusted commercial relationships and because employee and partner data often include contact details, banking information for payments, and operational schedules. Even if the precise files taken remain unconfirmed, the sector’s ordinary data holdings make the listing material for anyone who has done business with the firm.
The information in question
The only data type named in the available record is “internal files exfiltrated in a ransomware attack.” No inventory of those files—whether they contain employee records, customer lists, invoices, recipes, contracts or other material—has been published. Organisations of this kind typically hold personnel files, supplier agreements, sales data, quality-control documents and contact databases for retail and food-service clients. Because the exact contents are unconfirmed, it is not possible to state which of those categories, if any, were among the files claimed by sarcoma.
Readers should therefore treat the exposure as potentially broad but still unverified. The absence of a detailed data inventory does not mean the risk is low; it means the risk cannot yet be narrowed.
Why it matters
For individuals, the concrete risks include phishing or social-engineering attempts that use accurate internal details, identity-related fraud if personal information was present, and commercial pressure if supplier or customer contracts appear. For the organisation the risks include disruption of production and distribution relationships, possible regulatory scrutiny under data-protection rules, and the operational cost of investigating and containing the incident. Because the number of people affected is unknown and the files remain undescribed in public sources, both personal and corporate exposure must be regarded as open questions rather than settled facts.
The listing itself also creates secondary pressure: once a name appears on a ransomware leak site, opportunistic actors may begin scanning for related credentials or launching follow-on scams that reference the incident, regardless of whether the original data ever appears in full.
If your data was in this claimed breach
If you have worked for, supplied, or bought from Dona Formosa, treat the claim as a prompt for ordinary hygiene rather than panic. Practical first steps include:
- Change passwords on any accounts that used the same credentials as work-related systems, and enable multi-factor authentication where available.
- Watch bank and credit statements for unexpected activity and consider a fraud alert with credit bureaus if you supplied personal financial details.
- Be sceptical of emails or calls that reference the breach and request urgent payment, credentials or further personal information.
- Review any documents you previously shared with the company and note what identifiers they contained.
- Run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets.
These measures do not depend on confirmation of every detail; they simply reduce the chance that any exposed information can be turned against you while fuller facts, if they emerge, are assessed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Unimed do Brasil Listed by sarcoma Ransomware GroupHarinera del Valle Listed by sarcoma Ransomware GroupMachu Picchu Foods Listed by sarcoma Ransomware GroupMiller & Stewart Listed by sarcoma Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Dona Formosa Listed by sarcoma Ransomware Group →
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.