LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › FUJIFILM Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

FUJIFILM Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 5, 2025
FUJIFILM Listed by sarcoma Ransomware Group

Reported April 5, 2025.

HIGH
Severity
April 5, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On April 05, 2025, FUJIFILM was listed by the sarcoma ransomware group, which claims to have exfiltrated internal files. Individuals are advised to check whether their information may have been exposed and to take any recommended protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 5 April 2025 the ransomware group sarcoma listed FUJIFILM on its leak site, claiming it had exfiltrated internal files during a ransomware attack. The number of people whose information may be involved remains unknown, and public detail about the precise contents of those files is limited. For anyone who works with, supplies, or receives services from FUJIFILM, the listing raises ordinary but serious questions about whether personal, contractual or research-related data could now be in unauthorised hands.

Because the claim has not been independently confirmed in the available record, the practical stakes rest on the possibility rather than on proven exposure. Organisations of FUJIFILM’s size and sector routinely hold employee records, partner details and proprietary research; any of those categories, if present among the internal files, could create lasting inconvenience or risk for the individuals concerned.

Breaking down the breach

According to the public listing, sarcoma asserts that it conducted a ransomware attack against FUJIFILM and successfully removed internal files. The incident was reported on 5 April 2025. No figure for the number of people affected has been released, nor has any detailed timeline of the intrusion, the initial access method, or the volume of data taken been disclosed. The only data category named is “internal files.” Whether the group has published samples, set a ransom deadline, or received payment is not stated in the available facts. The listing itself therefore stands as an unverified claim by the threat actor rather than as a confirmed corporate disclosure.

Who is sarcoma?

Sarcoma is a ransomware operation that has appeared on public leak sites in recent years. Like many contemporary groups, it typically follows a double-extortion model: encrypting systems while also copying data and threatening to release it if payment is not made. The group posts victim names and, on occasion, file samples or directories on its dark-web site to increase pressure. Public reporting has linked sarcoma to attacks across multiple sectors, though the precise technical tools, affiliates or negotiation style used in any single case are often left opaque. In the present matter the only concrete assertion is the group’s own claim that FUJIFILM’s internal files were taken; no further statements attributed specifically to this victim appear in the record.

Who is FUJIFILM?

FUJIFILM is a large Japanese multinational whose activities span imaging, materials science and healthcare. In recent years the company has expanded its pharmaceutical and life-science work, including research into liposome-based drug formulations that encapsulate approved anti-cancer agents such as gemcitabine. Public descriptions of that programme note Phase I clinical trials begun in the United States in 2017 and preclinical observations of extended survival when the formulations were combined with immune-checkpoint inhibitors. Because the firm operates across manufacturing, research and commercial channels, it necessarily maintains internal repositories of scientific data, employee information, supplier contracts and regulatory documentation. A breach that reaches those repositories therefore carries consequences beyond a single business unit.

What data was at risk

The only category explicitly named is “internal files exfiltrated in ransomware attack.” No inventory of file types, no count of records, and no confirmation of personal identifiers, health data or intellectual property have been published. Organisations engaged in pharmaceutical research and global manufacturing typically hold employee directories, clinical-trial documentation, partner agreements and proprietary process data; any of those could theoretically be present among the files sarcoma claims to possess. Until FUJIFILM or an independent source provides a verified inventory, the exact contents remain unconfirmed.

Why it matters

If personal information of employees, contractors or trial participants was among the internal files, those individuals face the ordinary risks of phishing, credential stuffing or identity misuse that follow any unauthorised disclosure. Research data, if exposed, could undermine competitive position or regulatory timelines, while contractual material might affect suppliers and customers. For the organisation itself the incident creates operational disruption, potential regulatory scrutiny and the need to verify the integrity of remaining systems. Because the scale and precise contents are still unknown, the most immediate impact is uncertainty: people who interact with FUJIFILM cannot yet know whether their own details are involved and must therefore treat the possibility seriously without assuming the worst.

What to do if you're exposed

Anyone who has a professional or personal relationship with FUJIFILM should monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and treat unsolicited messages that reference the company with caution. If you suspect your credentials or personal data may have been involved, change passwords on related services and consider placing fraud alerts with credit bureaus. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check does not confirm or rule out involvement in this specific incident, but it provides a practical starting point for personal vigilance.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyFUJIFILM security record
80/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

3 reported incidents on record.

See FUJIFILM’s full breach history →
RelatedMore incidents at FUJIFILM

More recent breaches

Maselli Misure S.p.A. Information Listed by sarcoma Ransomware GroupAugust 15, 2025TMA Group of Companies Listed by sarcoma Ransomware GroupApril 10, 2025Unimicron Listed by sarcoma Ransomware GroupJanuary 30, 2025GYF Listed by sarcoma Ransomware GroupMarch 30, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the FUJIFILM Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram