LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Geass Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

Geass Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 29, 2025
Geass Listed by sarcoma Ransomware Group

Reported March 29, 2025.

HIGH
Severity
March 29, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Geass was listed by the sarcoma ransomware group on March 29, 2025, with an undisclosed number of internal files reportedly exfiltrated. Individuals connected to the organisation should check whether their data was exposed and take appropriate steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or professional details sit inside dental-industry systems may now face uncertainty after a ransomware group publicly listed Geass. When internal files leave an organisation that supplies implants and digital dentistry tools, the practical risk is that contact information, treatment-related records or business data could circulate beyond the company’s control. Public detail remains limited, yet the listing itself is enough to warrant careful attention from anyone who has dealt with the firm.

On 29 March 2025 the group known as sarcoma claimed responsibility for a ransomware attack on Geass and advertised an archive of material taken from the company. The number of individuals affected is unknown, and independent confirmation of the full scope has not been published. What is clear is that the claim involves the exfiltration of internal files, raising concrete questions for patients, dental professionals and the organisation itself.

Breaking down the breach

According to the public listing, sarcoma asserts that it conducted a ransomware attack against Geass and removed internal files. The group describes the material as a 156 GB archive containing files and SQL data. The listing was reported on 29 March 2025. No further technical details—such as the initial access method, the precise date of intrusion, or whether encryption of production systems occurred—have been disclosed in the available record. The number of people whose information may be involved is likewise unknown. The only concrete elements supplied by the claim are the organisation name, the stated archive size, and the presence of files and SQL content.

Because the information originates from a threat-actor leak site, it remains an unverified claim unless corroborated by the victim or independent investigators. At present, public reporting has not confirmed or denied the group’s assertions beyond the fact of the listing itself.

The group behind it: sarcoma

Sarcoma is a ransomware operation that follows the now-common double-extortion model: encrypting systems while simultaneously copying data and threatening to publish it if a ransom is not paid. Groups of this type typically maintain dedicated leak sites where they post victim names, sample files and downloadable archives to increase pressure. Public reporting over recent years has documented sarcoma’s activity against organisations across multiple sectors and geographies, with listings that frequently advertise large data volumes and mixed file types.

In this instance the group claims to have listed Geass and to hold a 156 GB archive. No additional statements attributed specifically to sarcoma about Geass—beyond the listing details already noted—appear in the public record. As with other ransomware claims, the listing should be treated as an assertion by the actors rather than established fact until independently verified.

Geass and its sector

Geass is an Italian company based in Pozzuolo del Friuli that supplies dental implants and CAD-CAM technology aimed at restorative and aesthetic dentistry. It also maintains a platform used by dental professionals. Organisations of this kind sit at the intersection of medical-device manufacturing, clinical support and digital design services. They routinely handle technical product data, professional account information, and, in many cases, patient-related records generated during treatment planning or implant procedures.

A breach affecting such a firm is consequential because the dental sector processes sensitive health-adjacent information and maintains commercial relationships with clinics and laboratories. Even when the exact contents of an archive remain unconfirmed, the potential presence of internal files and database material raises the possibility that both professional and patient data could be involved. Italy’s healthcare and medical-device environment is subject to strict data-protection rules, so any unauthorised disclosure carries regulatory as well as personal implications.

What was likely exposed

The available facts state that internal files were exfiltrated in a ransomware attack and that the claimed archive contains files and SQL data totalling 156 GB. No more granular inventory—such as specific categories of personal data, patient identifiers or financial records—has been disclosed. Organisations operating in dental implants and CAD-CAM typically store product designs, manufacturing records, professional contact lists, order histories and, depending on their service model, clinical or patient-linked information. Whether any of those categories actually appear in the archive remains unconfirmed. Readers should therefore treat the precise contents as unknown pending further public disclosure or official statements.

What's at stake

For individuals, the primary risks are misuse of contact details, possible exposure of health-related or treatment-planning information, and the secondary harms that can follow—phishing, identity fraud or unwanted contact. Dental professionals who use Geass platforms may face disruption to their own records or commercial relationships. For the organisation, the stakes include operational interruption, potential regulatory scrutiny under European data-protection rules, reputational damage among clinics and patients, and the cost of investigation and remediation. Because the number of affected people is unknown and the exact data types are not fully catalogued, the scale of these risks cannot yet be quantified, but the combination of a large claimed archive and the sensitive nature of dental-industry data makes the incident material for anyone connected to the company.

What to do if you're exposed

If you have been a patient, a dental professional, or a business partner of Geass, treat the listing as a prompt for basic protective steps rather than as confirmed personal compromise. Practical first actions include:

These measures do not eliminate risk, but they reduce the chance that any leaked material can be used against you while further facts emerge.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyGeass security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Geass’s full breach history →

More recent breaches

Unimed do Brasil Listed by sarcoma Ransomware GroupOctober 15, 2025Inox Laghi Listed by sarcoma Ransomware GroupAugust 27, 2025Maselli Misure S.p.A. Information Listed by sarcoma Ransomware GroupAugust 15, 2025Sanderling Healthcare Listed by sarcoma Ransomware GroupJuly 23, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Geass Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram