ePerformax Listed by nokoyawa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The ePerformax Listed by nokoyawa Ransomware Group (reported May 13, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In May 2023, the customer-contact and outsourcing firm ePerformax was listed by the ransomware group nokoyawa. Public reporting dated 13 May 2023 states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational detail has not been disclosed. For a company whose business centres on handling client and customer interactions, any confirmed exposure of internal material raises practical concerns for the organisation and for individuals whose information may have been held in its systems.
What is established so far is limited to the listing itself and the description of internal files taken during the incident. No independent confirmation of the full scope, the precise method of intrusion, or the complete contents of the material has been made public in the available record.
Inside the incident
According to the reported information, ePerformax appeared on a nokoyawa-associated listing on or around 13 May 2023. The account of the event describes internal files as having been exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the duration of unauthorised access. Timing beyond the reporting date, the initial access vector, and whether encryption was also deployed on production systems are not detailed in the available facts. The scale of any impact on employees, clients, or end customers is likewise unconfirmed. In short, the incident is known principally through the group’s claim and the characterisation of the taken material as internal files; other particulars remain undisclosed.
The group behind it: nokoyawa
Nokoyawa is a ransomware operation that became publicly visible in the early 2020s and has been associated with double-extortion tactics: encrypting victim systems while also copying data and threatening to publish or sell it if demands are not met. The group has typically used leak sites to name organisations and, in some cases, to release samples or larger archives of stolen files. Its activity has spanned multiple sectors and geographies, consistent with opportunistic targeting rather than a single industry focus. Public technical reporting has linked nokoyawa tooling to evolving ransomware families and to the use of common initial-access methods seen across the ransomware ecosystem, though specific tooling used against any one victim is not always confirmed.
In this case, the group’s listing of ePerformax constitutes a claim that the organisation was compromised and that internal files were taken. That claim has not been independently verified in the facts provided here, and no further statements attributed to nokoyawa about this specific victim—such as ransom amounts, deadlines, or detailed file inventories—are included in the available record. Readers should treat the listing as an unverified assertion by the threat actor unless corroborated by the organisation or by other authoritative sources.
Who is ePerformax?
ePerformax traces its roots to 1988, when the Performance Consulting Group was founded by Teresa Hartsaw in Memphis, Tennessee. The business was established as a marketing, training, customer-contact and customer-engagement company focused on end-to-end outsourced customer-contact solutions. Organisations of this type typically operate contact centres, handle inbound and outbound customer communications, and support clients with workforce and engagement services. They routinely process operational records, client instructions, and varying amounts of personal and account-related data belonging to the end customers of the brands they serve.
A breach affecting such a provider is consequential because the firm sits between multiple corporate clients and large volumes of customer interactions. Compromise of internal systems can therefore touch not only the company’s own employees and proprietary material but also information entrusted to it by clients. Even when the exact contents of an exfiltration remain unconfirmed, the sector’s role profile means that any credible claim of data theft warrants careful attention from the organisation, its clients, and potentially affected individuals.
What data was at risk
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as employee records, client contracts, customer personal data, financial documents, or credentials—is provided. The number of people affected is unknown.
Companies in the outsourced customer-contact sector commonly hold workforce information, operational and quality-assurance records, client configuration and reporting data, and, depending on the services delivered, elements of consumer contact or account data. It is reasonable to expect that internal file stores could contain a mixture of these categories. However, the exact contents of what nokoyawa claims to have taken from ePerformax are unconfirmed. No inventory, sample set, or official notification detailing specific data types has been included in the reported facts. Any assumption about particular categories of personal or commercial information should be treated as speculative until verified.
The real-world impact
For individuals, the primary risks associated with a ransomware-related exfiltration of internal files are secondary misuse of any personal or contact information that may have been present, including phishing, social-engineering attempts that reference the company or its clients, and, in rarer cases, identity-related fraud if sufficient identifiers were included. Because the affected population size and data types are undisclosed, it is not possible to state how widely these risks apply. People who have worked for ePerformax, contracted with it, or been customers of brands it supports may wish to remain alert to unexpected communications that leverage knowledge of those relationships.
For the organisation, consequences can include operational disruption, costs of investigation and remediation, contractual and regulatory obligations to clients and authorities, and reputational strain with the brands that rely on its services. Clients of an outsourced contact provider may themselves face notification duties or customer-support burdens if their data or their customers’ data were involved. None of these outcomes is established as fact solely by a leak-site listing; they represent the ordinary range of impacts seen when internal material is claimed to have been stolen in a ransomware event. The absence of public figures on scale leaves the concrete severity of this incident unmeasured in the available record.
Were you affected?
If you have a past or present connection to ePerformax—as an employee, contractor, client contact, or customer of a brand it serves—consider practical steps: monitor accounts and communications for unusual activity, treat unsolicited messages that reference the company with caution, and follow any official guidance the organisation or its clients may issue. Where appropriate, review credit or fraud-alert options offered in your jurisdiction. Public detail on this incident remains limited, so official notices from ePerformax or from regulators will be the most reliable source of confirmation.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or rule out involvement in this specific incident, but it can help you identify credentials or personal details that have appeared elsewhere and that should be changed or monitored.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Studio Domaine LLC Listed by nokoyawa Ransomware GroupGlobal Remote Services Listed by nokoyawa Ransomware GroupPueblo Mechanical & Controls Listed by nokoyawa Ransomware GroupCONEX Listed by nokoyawa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ePerformax Listed by nokoyawa Ransomware Group →
Publicly posted by nokoyawa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.