EARTHWORKS Group Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
EARTHWORKS Group was listed by the sarcoma ransomware group on October 09, 2024, with internal files reported to have been exfiltrated. Individuals connected to the organization should review any communications from EARTHWORKS Group or official notices and take protective steps if their information may be involved.
People who work with or for EARTHWORKS Group, or who have shared personal or project information with the firm, face a practical question: whether internal files taken in a claimed ransomware attack could expose them to identity misuse, targeted fraud, or unwanted contact. Public reporting so far leaves the scale and exact contents unclear, so the immediate stakes rest on what the listing itself implies rather than on confirmed victim counts.
On 9 October 2024 the EARTHWORKS Group appeared on a listing attributed to the sarcoma ransomware group. The claim states that internal files were exfiltrated. No independent confirmation of the intrusion, the volume of data, or the number of people affected has been made public. That uncertainty itself is part of the risk: until more is known, individuals connected to the firm have limited ways to judge whether their own records are involved.
What happened
According to the available record, the EARTHWORKS Group was listed by the sarcoma ransomware group on 9 October 2024. The listing asserts that internal files were taken during a ransomware attack. The number of people affected is unknown. No public detail has been released on the precise date of the intrusion, the technical method used, whether systems were encrypted, whether a ransom demand was issued, or whether any data has been published beyond the listing itself. The only concrete claim on record is the exfiltration of internal files. Everything else remains undisclosed.
Inside sarcoma
Sarcoma is a ransomware operation that has been publicly documented as using double-extortion tactics: operators encrypt victim systems while also copying data, then threaten to release the material if payment is not made. The group maintains a leak site on which it names organisations it claims to have compromised. Listings of this kind are assertions by the actors themselves; they are not independent verification that a breach occurred or that the volume and sensitivity of data match what is advertised. Sarcoma has been observed targeting a range of commercial and professional-services organisations rather than a single narrow sector. Its public communications typically emphasise the presence of stolen files and set deadlines for payment, after which it claims it will release or auction the material. None of those general patterns, however, state the specific details of any single listing, including the one that names EARTHWORKS Group.
EARTHWORKS Group and its sector
EARTHWORKS Group, Inc. is described in its own materials as a turn-key planning and design firm established in 1996. It supplies engineering, architectural, environmental, land-planning, geographic-information-systems, structural, construction-management, wetland-mitigation-banking and related consulting services to public- and private-sector clients across the southeastern United States. Firms of this type routinely handle project drawings, environmental assessments, client correspondence, contracts, employee records and, in some cases, personal identifiers of staff and of individuals living near project sites. Because the work often involves public infrastructure, land use and regulatory compliance, the data sets can include both commercially sensitive material and information that, if exposed, could affect private citizens. A breach at such an organisation therefore carries consequences that extend beyond the firm’s internal operations to clients, partners and potentially nearby communities.
The information in question
The only data type named in the public record is “internal files” said to have been exfiltrated. No inventory of those files has been released, nor has any confirmation of specific categories such as employee Social Security numbers, client financial details, project blueprints or personal contact lists. Organisations that perform engineering and environmental consulting typically retain personnel records, contracts, invoices, site photographs, GIS layers and correspondence that may contain names, addresses, phone numbers and professional credentials. Whether any of those categories were among the files claimed by sarcoma remains unconfirmed. Until a fuller accounting appears, the precise contents must be treated as unknown.
Why it matters
For individuals whose information may have been among the internal files, the concrete risks include phishing that references real projects or colleagues, attempts to open credit accounts with stolen identifiers, and social-engineering calls that exploit knowledge of ongoing work. Even without highly sensitive personal data, project-related documents can reveal enough context for targeted fraud. For the organisation itself, the listing can disrupt client trust, trigger contractual notification duties, and require forensic and legal expenditure regardless of whether a ransom is paid. Because the number of people affected is unknown and the exact data types are undisclosed, both the firm and anyone connected to it must operate under incomplete information—an added practical burden that can delay protective steps.
What to do if you're exposed
If you have reason to believe your data may have been held by EARTHWORKS Group, begin with basic hygiene: change passwords on any accounts that reused credentials shared with the firm, enable multi-factor authentication where available, and monitor bank and credit statements for unfamiliar activity. Consider placing a fraud alert with the major credit bureaus. Keep records of any suspicious contact that appears to reference the firm or its projects. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan does not prove or disprove involvement in this particular incident, but it can surface other exposures that warrant attention. Stay alert for official notices from EARTHWORKS Group or from regulators; those notices, when they arrive, will provide the most reliable guidance on what was actually taken.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
The Roberts Family Law Firm Listed by sarcoma Ransomware GroupMiami Management Listed by sarcoma Ransomware GroupMilberg Listed by sarcoma Ransomware Grouphttps://thesandersfirm.com/ Listed by sarcoma Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the EARTHWORKS Group Listed by sarcoma Ransomware Group →
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.