ErgoFloor Listed by 8base Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ErgoFloor was listed by the 8base ransomware group on 23 September 2024 after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone who has done business with the company should check for updates and monitor their accounts.
On 23 September 2024, the Danish flooring company ErgoFloor was listed on the leak site operated by the 8base ransomware group. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.
A listing of this kind signals that the group claims to hold stolen data and may threaten to publish it. For customers, suppliers and staff connected to ErgoFloor, the practical question is what information may have left the organisation and what steps can reduce any resulting risk.
What happened
According to the available record, ErgoFloor was named by 8base on 23 September 2024. The report describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. No public confirmation has been issued that the listing has been independently verified by the company or by law-enforcement agencies. The scale of the intrusion, the precise date of initial access, the encryption status of systems, and any ransom demand remain undisclosed. People affected are listed as unknown.
In short, the only concrete public statements are the group’s claim of a listing and the characterisation of the event as a ransomware attack involving the theft of internal files. Everything else about timing, method and volume is unconfirmed at this stage.
The group behind it: 8base
8base is a ransomware operation that has been active in public view since at least 2022–2023. Like many contemporary groups, it typically follows a double-extortion model: data is stolen before systems are encrypted, and the operators threaten to release the material on a dedicated leak site if payment is not made. The group has been observed advertising itself as a ransomware-as-a-service offering, recruiting affiliates who conduct the initial compromise and share proceeds with the core operators.
Public reporting on 8base has documented attacks against organisations across manufacturing, professional services and other commercial sectors, often mid-sized firms rather than the largest global enterprises. The group’s leak site is used both to pressure victims and to demonstrate that data has been taken. In the present case, the listing of ErgoFloor should be treated as an unverified claim by the group; it does not by itself prove the full extent or accuracy of any data set the operators say they hold.
About ErgoFloor
ErgoFloor describes itself as a supplier of flooring and underlay solutions. Its product range covers rubber coatings, rubber mats, stable mats, fall pads, rubber tiles, safety tiles, safety flooring, sports flooring, design vinyl and commercial flooring intended for specialised environments. The company operates from Denmark and maintains a public website at ergofloor.dk.
Organisations of this type typically maintain customer and supplier records, order and logistics data, product specifications, internal correspondence, and employee information. A breach involving internal files therefore carries potential consequences for commercial partners and staff as well as for the company’s own operations and reputation. Because ErgoFloor serves both specialised and commercial markets, the data it holds may include details of contracts, site installations and contact information that third parties would prefer to keep private.
What data was at risk
The public facts state only that internal files were exfiltrated. No inventory of file types, no count of records, and no confirmation of personal data categories have been released. Exact contents therefore remain unconfirmed.
Companies in the flooring and industrial-supplies sector commonly store customer contact details, delivery addresses, invoices, product orders, technical drawings, supplier agreements and internal HR or payroll material. Any of these could, in principle, have been among the internal files taken. Until ErgoFloor or an investigating authority publishes a clearer description, it is not possible to state which specific data elements were exposed. Readers should treat the risk as real but unquantified.
The real-world impact
For individuals whose details may appear in ErgoFloor’s systems—customers, site contacts, suppliers or employees—the main practical risks are phishing and social-engineering attempts that reference genuine company relationships, possible misuse of contact or address data, and, if financial or identity documents were present, longer-term fraud exposure. Because the number of people affected is unknown, it is impossible to say how widely these risks extend.
For the organisation itself, the consequences can include operational disruption if systems were encrypted, the cost of investigation and recovery, potential regulatory notification duties under European data-protection rules, and reputational damage among commercial partners. None of these outcomes has been publicly confirmed; they remain the ordinary range of effects observed after similar ransomware claims.
What to do if you're exposed
If you have done business with ErgoFloor or worked for the company, treat unsolicited emails, calls or messages that reference the firm with extra caution. Verify any request for payment, password changes or personal information through a known official channel. Monitor bank and credit accounts for unusual activity and consider placing fraud alerts where available. Change passwords that may have been reused across work and personal accounts, and enable multi-factor authentication wherever possible.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can show whether your address has surfaced elsewhere and help you prioritise further protective measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Grupo Bébécar Listed by 8base Ransomware GroupISEKI and CO.,LTD Listed by 8base Ransomware GroupTRAFILERIE ALLUMINIO ALEXIA S.P.A. Listed by 8base Ransomware GroupInnoGroup Listed by 8base Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ErgoFloor Listed by 8base Ransomware Group →
Publicly posted by 8base — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.