Gitlabs: Omydoo, Ayomi, ADULLACT Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Gitlabs, Omydoo, Ayomi, and ADULLACT were listed by the fog Ransomware Group on February 13, 2025, after internal files were exfiltrated in an attack whose timing has not been established. Individuals who may have had dealings with any of the listed organisations should review the disclosed data and take protective steps.
When a ransomware group lists an organisation on its leak site, the immediate concern for anyone connected to that organisation is whether personal or professional information has been taken and what might happen next. In this case, the listing involves Gitlabs associated with Omydoo, Ayomi and ADULLACT, and the practical stakes centre on the possibility that internal material has left the organisation’s control without clear public confirmation of its full scope or the number of people touched by it.
Public reporting on 13 February 2025 indicated that the fog ransomware group had added Gitlabs: Omydoo, Ayomi, ADULLACT to its leak site and claimed to have stolen internal data. The number of people affected remains unknown, and independent verification of the group’s assertions has not been detailed in available accounts. For individuals whose work or records may intersect with these entities, the incident raises ordinary questions about exposure and next steps rather than confirmed widespread compromise.
Breaking down the breach
According to the reported summary, Gitlabs: Omydoo, Ayomi, ADULLACT was listed on the fog ransomware leak site. The group claims to have stolen internal data in what is described as a ransomware attack involving the exfiltration of internal files. The date associated with the public listing is 13 February 2025. No further details on the precise timing of any intrusion, the technical method used, the volume of data taken, or confirmation that files were actually published have been provided in the available facts. The number of people affected is listed as unknown. In short, the public record consists of the listing itself and the group’s claim of exfiltration; everything else about scale and execution remains undisclosed.
The group behind it: fog
Fog is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion style attacks: encrypting systems while also claiming to remove data and threatening to release it on a dedicated leak site if demands are not met. Like other groups of this type, fog typically advertises victims by name on its site and asserts that internal material has been taken. Public knowledge of the group’s broader activity includes listings of organisations across multiple sectors, often accompanied by sample files or countdown timers, though such practices are general patterns rather than specifics proven for every case.
In this instance the only claim that can be attributed to fog is the one recorded in the facts: that it listed Gitlabs: Omydoo, Ayomi, ADULLACT and asserts it stole internal data. No additional statements by the group about this particular victim, ransom amounts, or publication of files are contained in the provided record. The listing should therefore be treated as an unverified claim until independent confirmation appears.
Who is Gitlabs: Omydoo, Ayomi, ADULLACT?
The designation “Gitlabs: Omydoo, Ayomi, ADULLACT” points to GitLab environments linked to these three named entities. GitLab is a widely used platform for hosting source-code repositories, project management, and collaborative software development. Omydoo and Ayomi operate in technology and digital-services contexts, while ADULLACT is a French association that promotes free and open-source software for public administrations and local authorities. Organisations of this kind commonly maintain internal codebases, documentation, configuration data, and collaboration records that support software projects and administrative tools.
A breach involving such GitLab instances is consequential because the material stored there often includes proprietary or sensitive project information, credentials, and records that can affect both the organisations themselves and any partners, public bodies or end users who rely on the software or services developed through those repositories. The exact nature of the relationship among Omydoo, Ayomi and ADULLACT in this listing is not further detailed in the facts, so the public picture remains limited to the joint naming under the Gitlabs heading.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as specific file names, categories of personal data, source-code repositories, or volumes—is provided. Because the precise contents remain unconfirmed, it is not possible to assert that any particular type of record was or was not taken.
Organisations that operate GitLab environments typically hold source code, issue trackers, continuous-integration configurations, internal documentation, and sometimes credentials or access tokens. Public-sector-oriented entities such as ADULLACT may also store materials related to free-software projects used by administrations. None of these categories can be confirmed as present in the claimed exfiltration; they are simply the kinds of data such systems commonly contain. The only firmly reported description is “internal files.”
What's at stake
For people whose information or work product may reside in the affected systems, the concrete risks include potential exposure of professional correspondence, project details, or any personal data that happened to be stored alongside internal files. If credentials or access tokens were among the material, unauthorised access to other services could become possible. For the organisations, the stakes involve operational disruption, the need to assess and rotate secrets, possible regulatory notification duties, and reputational questions that arise whenever a ransomware group makes a public claim.
Because the number of people affected is unknown and the exact data types beyond “internal files” are undisclosed, the real-world impact cannot yet be quantified. The situation remains one of claimed exfiltration rather than a fully documented public dump, so the immediate consequences are uncertainty and the ordinary need for vigilance rather than confirmed mass identity theft or financial loss.
Were you affected?
If you have an account, project, or professional relationship with Omydoo, Ayomi, ADULLACT or any GitLab instance they operate, treat the listing as a signal to review your own exposure. Change passwords and enable multi-factor authentication on related accounts, monitor for unusual activity, and watch for official statements from the organisations themselves. Because the full scope is unconfirmed, assume nothing is automatically safe and nothing is automatically compromised until more detail emerges.
As a practical first step, you can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That check will not confirm or deny involvement in this specific incident, but it can surface other exposures that warrant attention while further information about the fog listing develops.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Gitlabs: Naphix, WDNA, Bayteq Listed by fog Ransomware GroupNewtown Friends School (newtownfriends.org) Listed by fog Ransomware GroupUniversity Diagnostic Medical Imaging, PC (udmi.net) Listed by fog Ransomware GroupEl Camino Real Academy (elcaminorealacademy) Listed by fog Ransomware GroupLatest breaches
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.