LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Eden Project Ltd Listed by incransom Ransomware Group

HIGH severityUnverified claimHow we verify

Eden Project Ltd Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 13, 2024
Eden Project Ltd Listed by incransom Ransomware Group

Reported May 13, 2024.

HIGH
Severity
May 13, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Eden Project Ltd Listed by incransom Ransomware Group (reported May 13, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People connected to Eden Project Ltd — staff, partners, supporters or programme participants — may now face uncertainty about whether internal records that include their details have left the organisation’s control. Public reporting so far is limited, yet the listing of the charity by a ransomware group means the practical risk of misuse of any copied files cannot be dismissed.

On 13 May 2024 the organisation appeared on the leak site associated with the incransom ransomware group. The group claims internal files were taken in a ransomware attack. How many people are affected and exactly which records were copied remain undisclosed.

What happened

According to the public listing dated 13 May 2024, Eden Project Ltd was named by the incransom ransomware group. The group states that internal files were exfiltrated during a ransomware attack. No further technical detail — such as the initial access method, the duration of any intrusion, encryption of systems, or confirmation that a ransom demand was issued — has been made public. The number of people whose information may be involved is unknown. The listing itself is a claim by the group; independent confirmation of the full scope of the incident has not been published in the available record.

Who is incransom?

incransom is a ransomware operation that has appeared in public reporting since the early 2020s. Like many contemporary groups, it typically follows a double-extortion model: operators encrypt systems to disrupt operations and simultaneously copy data so they can threaten to publish it if a ransom is not paid. Victims are commonly listed on a dedicated leak site, sometimes with sample files, as a form of pressure. The group has been associated with attacks across multiple sectors and geographies; its public communications usually focus on the volume or sensitivity of stolen material rather than detailed technical indicators. In this case the only specific assertion about Eden Project Ltd is the claim that internal files were exfiltrated and that the organisation has been listed.

Who is Eden Project Ltd?

Eden Project Ltd operates the Eden Project, an educational charity and social enterprise based in Cornwall, United Kingdom. It is best known for its large biomes and outdoor gardens that house plant collections from around the world, together with exhibitions, events and educational programmes. The organisation’s stated purpose is to explore how people can work with nature and with one another to bring about positive change; revenue from visitors and fundraising supports education work and related projects. As a visitor attraction, employer and grant-receiving charity, it routinely holds operational, financial, staff and supporter records. A ransomware claim against such an organisation therefore raises questions that extend beyond the immediate operational disruption to the privacy of people who interact with it.

What data was at risk

The only description provided in the public listing is that “internal files” were allegedly exfiltrated. No inventory of file types, no count of records and no confirmation of personal data categories have been released. Organisations of this kind typically maintain staff and volunteer personnel files, donor and membership databases, visitor booking or ticketing information, supplier contracts, financial records and programme-related correspondence. Whether any of those categories were among the copied material remains unconfirmed. Until the organisation or independent investigators publish a more precise account, the exact contents of the claimed exfiltration cannot be stated as fact.

What's at stake

For individuals, the main risks are secondary misuse of any personal information that may have been taken — phishing that appears to come from a familiar organisation, identity fraud if identity documents or financial details were present, or unwanted contact based on supporter or employee records. Because the scale and content of the files are unknown, it is not possible to quantify how many people face these risks or how severe they are. For Eden Project Ltd the stakes include potential regulatory scrutiny under data-protection law, reputational damage among visitors and funders, and the operational cost of investigation, notification and system recovery. The incident also illustrates the broader exposure of charities and educational bodies that hold both public-facing and internal data yet may have limited cybersecurity resources compared with large commercial firms.

What to do if you're exposed

If you have a past or present connection to Eden Project Ltd — as an employee, volunteer, donor, ticket holder or programme participant — treat the possibility of exposure seriously even while details remain limited. Practical first steps include:

Keep records of any suspicious contact and report confirmed fraud to the police and to your bank. Official updates from Eden Project Ltd or from the relevant data-protection authority, if and when they appear, should take precedence over third-party claims.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyEden Project Ltd security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Eden Project Ltd’s full breach history →

More recent breaches

gravetye-manor Listed by incransom Ransomware GroupMay 8, 2024Chickenshed Listed by incransom Ransomware GroupApril 11, 2025McKibbin Listed by incransom Ransomware GroupDecember 1, 2024NHS Alder Hey Listed by incransom Ransomware GroupNovember 26, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Eden Project Ltd Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram