Eden Project Ltd Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Eden Project Ltd Listed by incransom Ransomware Group (reported May 13, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
People connected to Eden Project Ltd — staff, partners, supporters or programme participants — may now face uncertainty about whether internal records that include their details have left the organisation’s control. Public reporting so far is limited, yet the listing of the charity by a ransomware group means the practical risk of misuse of any copied files cannot be dismissed.
On 13 May 2024 the organisation appeared on the leak site associated with the incransom ransomware group. The group claims internal files were taken in a ransomware attack. How many people are affected and exactly which records were copied remain undisclosed.
What happened
According to the public listing dated 13 May 2024, Eden Project Ltd was named by the incransom ransomware group. The group states that internal files were exfiltrated during a ransomware attack. No further technical detail — such as the initial access method, the duration of any intrusion, encryption of systems, or confirmation that a ransom demand was issued — has been made public. The number of people whose information may be involved is unknown. The listing itself is a claim by the group; independent confirmation of the full scope of the incident has not been published in the available record.
Who is incransom?
incransom is a ransomware operation that has appeared in public reporting since the early 2020s. Like many contemporary groups, it typically follows a double-extortion model: operators encrypt systems to disrupt operations and simultaneously copy data so they can threaten to publish it if a ransom is not paid. Victims are commonly listed on a dedicated leak site, sometimes with sample files, as a form of pressure. The group has been associated with attacks across multiple sectors and geographies; its public communications usually focus on the volume or sensitivity of stolen material rather than detailed technical indicators. In this case the only specific assertion about Eden Project Ltd is the claim that internal files were exfiltrated and that the organisation has been listed.
Who is Eden Project Ltd?
Eden Project Ltd operates the Eden Project, an educational charity and social enterprise based in Cornwall, United Kingdom. It is best known for its large biomes and outdoor gardens that house plant collections from around the world, together with exhibitions, events and educational programmes. The organisation’s stated purpose is to explore how people can work with nature and with one another to bring about positive change; revenue from visitors and fundraising supports education work and related projects. As a visitor attraction, employer and grant-receiving charity, it routinely holds operational, financial, staff and supporter records. A ransomware claim against such an organisation therefore raises questions that extend beyond the immediate operational disruption to the privacy of people who interact with it.
What data was at risk
The only description provided in the public listing is that “internal files” were allegedly exfiltrated. No inventory of file types, no count of records and no confirmation of personal data categories have been released. Organisations of this kind typically maintain staff and volunteer personnel files, donor and membership databases, visitor booking or ticketing information, supplier contracts, financial records and programme-related correspondence. Whether any of those categories were among the copied material remains unconfirmed. Until the organisation or independent investigators publish a more precise account, the exact contents of the claimed exfiltration cannot be stated as fact.
What's at stake
For individuals, the main risks are secondary misuse of any personal information that may have been taken — phishing that appears to come from a familiar organisation, identity fraud if identity documents or financial details were present, or unwanted contact based on supporter or employee records. Because the scale and content of the files are unknown, it is not possible to quantify how many people face these risks or how severe they are. For Eden Project Ltd the stakes include potential regulatory scrutiny under data-protection law, reputational damage among visitors and funders, and the operational cost of investigation, notification and system recovery. The incident also illustrates the broader exposure of charities and educational bodies that hold both public-facing and internal data yet may have limited cybersecurity resources compared with large commercial firms.
What to do if you're exposed
If you have a past or present connection to Eden Project Ltd — as an employee, volunteer, donor, ticket holder or programme participant — treat the possibility of exposure seriously even while details remain limited. Practical first steps include:
- Monitor bank and credit-card statements for unfamiliar transactions and enable transaction alerts where available.
- Be cautious of unsolicited emails, calls or messages that reference the Eden Project or claim to need updated personal details; verify any such contact through official channels you already trust.
- Change passwords for any accounts that reused credentials associated with the organisation, and enable multi-factor authentication wherever it is offered.
- Consider placing a fraud alert or credit freeze with the major credit-reference agencies if you believe financial or identity data may have been involved.
- Run a free exposure scan of your email address against known breach datasets to see whether your information has already appeared in other public leaks; this does not confirm or rule out involvement in the present incident but can highlight existing risk.
Keep records of any suspicious contact and report confirmed fraud to the police and to your bank. Official updates from Eden Project Ltd or from the relevant data-protection authority, if and when they appear, should take precedence over third-party claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
gravetye-manor Listed by incransom Ransomware GroupChickenshed Listed by incransom Ransomware GroupMcKibbin Listed by incransom Ransomware GroupNHS Alder Hey Listed by incransom Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Eden Project Ltd Listed by incransom Ransomware Group →
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.