FUJIFILM Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On April 05, 2025, FUJIFILM was listed by the sarcoma ransomware group, which claims to have exfiltrated internal files. Individuals are advised to check whether their information may have been exposed and to take any recommended protective steps.
On 5 April 2025 the ransomware group sarcoma listed FUJIFILM on its leak site, claiming it had exfiltrated internal files during a ransomware attack. The number of people whose information may be involved remains unknown, and public detail about the precise contents of those files is limited. For anyone who works with, supplies, or receives services from FUJIFILM, the listing raises ordinary but serious questions about whether personal, contractual or research-related data could now be in unauthorised hands.
Because the claim has not been independently confirmed in the available record, the practical stakes rest on the possibility rather than on proven exposure. Organisations of FUJIFILM’s size and sector routinely hold employee records, partner details and proprietary research; any of those categories, if present among the internal files, could create lasting inconvenience or risk for the individuals concerned.
Breaking down the breach
According to the public listing, sarcoma asserts that it conducted a ransomware attack against FUJIFILM and successfully removed internal files. The incident was reported on 5 April 2025. No figure for the number of people affected has been released, nor has any detailed timeline of the intrusion, the initial access method, or the volume of data taken been disclosed. The only data category named is “internal files.” Whether the group has published samples, set a ransom deadline, or received payment is not stated in the available facts. The listing itself therefore stands as an unverified claim by the threat actor rather than as a confirmed corporate disclosure.
Who is sarcoma?
Sarcoma is a ransomware operation that has appeared on public leak sites in recent years. Like many contemporary groups, it typically follows a double-extortion model: encrypting systems while also copying data and threatening to release it if payment is not made. The group posts victim names and, on occasion, file samples or directories on its dark-web site to increase pressure. Public reporting has linked sarcoma to attacks across multiple sectors, though the precise technical tools, affiliates or negotiation style used in any single case are often left opaque. In the present matter the only concrete assertion is the group’s own claim that FUJIFILM’s internal files were taken; no further statements attributed specifically to this victim appear in the record.
Who is FUJIFILM?
FUJIFILM is a large Japanese multinational whose activities span imaging, materials science and healthcare. In recent years the company has expanded its pharmaceutical and life-science work, including research into liposome-based drug formulations that encapsulate approved anti-cancer agents such as gemcitabine. Public descriptions of that programme note Phase I clinical trials begun in the United States in 2017 and preclinical observations of extended survival when the formulations were combined with immune-checkpoint inhibitors. Because the firm operates across manufacturing, research and commercial channels, it necessarily maintains internal repositories of scientific data, employee information, supplier contracts and regulatory documentation. A breach that reaches those repositories therefore carries consequences beyond a single business unit.
What data was at risk
The only category explicitly named is “internal files exfiltrated in ransomware attack.” No inventory of file types, no count of records, and no confirmation of personal identifiers, health data or intellectual property have been published. Organisations engaged in pharmaceutical research and global manufacturing typically hold employee directories, clinical-trial documentation, partner agreements and proprietary process data; any of those could theoretically be present among the files sarcoma claims to possess. Until FUJIFILM or an independent source provides a verified inventory, the exact contents remain unconfirmed.
Why it matters
If personal information of employees, contractors or trial participants was among the internal files, those individuals face the ordinary risks of phishing, credential stuffing or identity misuse that follow any unauthorised disclosure. Research data, if exposed, could undermine competitive position or regulatory timelines, while contractual material might affect suppliers and customers. For the organisation itself the incident creates operational disruption, potential regulatory scrutiny and the need to verify the integrity of remaining systems. Because the scale and precise contents are still unknown, the most immediate impact is uncertainty: people who interact with FUJIFILM cannot yet know whether their own details are involved and must therefore treat the possibility seriously without assuming the worst.
What to do if you're exposed
Anyone who has a professional or personal relationship with FUJIFILM should monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and treat unsolicited messages that reference the company with caution. If you suspect your credentials or personal data may have been involved, change passwords on related services and consider placing fraud alerts with credit bureaus. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check does not confirm or rule out involvement in this specific incident, but it provides a practical starting point for personal vigilance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Maselli Misure S.p.A. Information Listed by sarcoma Ransomware GroupTMA Group of Companies Listed by sarcoma Ransomware GroupUnimicron Listed by sarcoma Ransomware GroupGYF Listed by sarcoma Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the FUJIFILM Listed by sarcoma Ransomware Group →
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.