h2o.ai Listed by linkc Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
h2o.ai was listed by the linkc ransomware group on January 29, 2025, with internal files reported as exfiltrated. Individuals should check whether their information was involved and take protective steps.
On January 29, 2025, the artificial intelligence company h2o.ai was listed by the ransomware group known as linkc. Public reporting indicates that the group claims to have carried out a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and independent confirmation of the full scope has not been detailed in available records.
The listing matters because h2o.ai operates in a sector that routinely handles sensitive technical assets and customer-related material. Any confirmed exposure of such material could create lasting risks for the organisation and for individuals whose information may have been involved, even while many operational details stay undisclosed.
Breaking down the breach
According to the available facts, h2o.ai appeared on a linkc listing dated January 29, 2025. The group describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. No public confirmation has established the precise method of initial access, the duration of any intrusion, or the total volume of data taken. The number of individuals affected is listed as unknown. The only concrete claims about content come from the group’s own summary of what it says it discovered during its operation.
Those claims include unanonymized customer datasets intended for AI training; full source code from a Git repository covering programs for driverless systems, GPT models and other components; a substantial amount of internal information such as contracts, customer personal data, project costs and project documentation; and backup copies of employee email accounts that contain customer correspondence. Because these details originate from the threat actor’s leak-site statement, they remain unverified claims rather than independently audited findings. Timing beyond the reported listing date, exact file counts and any ransom demand figures are not provided in the public record.
Who is linkc?
linkc is a ransomware group that publicly lists organisations it claims to have compromised, typically as part of a double-extortion model in which data is first stolen and then used as leverage. Like other actors in this category, the group posts victim names and sample descriptions on dedicated leak sites to pressure organisations into negotiations. Public knowledge of ransomware operations of this type shows that such groups commonly target entities holding valuable intellectual property or customer records, then advertise the alleged haul to increase urgency.
No verified statements from linkc beyond the listing and the four-point summary of claimed data have been recorded for this specific incident. Typical tactics associated with similar groups include network intrusion, data staging and exfiltration prior to any encryption, followed by public naming if demands are unmet. Prior activity by linkc is documented mainly through its pattern of leak-site postings rather than through detailed technical disclosures about every campaign. In this case the group asserts it obtained the materials listed; those assertions have not been independently confirmed in the facts provided.
h2o.ai and its sector
h2o.ai is an organisation focused on artificial-intelligence and machine-learning platforms. Companies in this sector develop tools for data analysis, model training and automated decision systems, often working with large volumes of customer-supplied datasets, proprietary algorithms and internal project records. Such firms commonly maintain source-code repositories, contractual documents, cost analyses and correspondence that support commercial AI deployments.
A breach affecting an AI platform provider is consequential because the materials typically held can include both commercial intellectual property and personal or business data belonging to customers. Exposure of training datasets, model code or project documentation can undermine competitive positions and create secondary risks for the organisations and individuals who supplied the original information. The sector’s reliance on large-scale data processing means that any successful exfiltration can have effects that extend beyond the primary victim.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack. The threat actor’s own summary claims four categories: unanonymized customer datasets intended for AI training; full source code of programs from a Git repository, including code for driverless systems, GPT models and others; a substantial amount of internal information comprising contracts, customer personal data, project costs and project documentation; and backup copies of employee email accounts containing customer correspondence.
These items are presented as the group’s assertions. Organisations of this kind typically store source code, training data, contractual records and internal communications, so the claimed categories align with materials an AI firm would be expected to hold. However, the exact contents, file volumes and whether every listed item was in fact taken remain unconfirmed beyond the leak-site claims. No independent inventory or forensic summary has been supplied in the available record, and the number of people whose data may appear in any of the files is unknown.
What's at stake
For individuals whose information may appear in customer datasets, contracts or email correspondence, the practical risks include potential misuse of personal details, targeted phishing that references genuine project or account information, and longer-term identity or privacy concerns if unanonymized records circulate. Because the scale of affected people is unknown, the breadth of any personal impact cannot yet be quantified.
For h2o.ai itself, the stakes centre on the possible loss of proprietary source code, project documentation and commercial contracts. Disclosure of such material can erode competitive advantage, complicate customer relationships and create regulatory or contractual obligations to notify affected parties. Even if encryption or other disruption occurred, the primary documented claim is exfiltration, so the enduring risk is the continued availability of the stolen files rather than temporary operational outage. Reputational and legal consequences may follow once the claims are more fully assessed, but those outcomes remain prospective rather than established.
What to do if you're exposed
Anyone who has done business with h2o.ai or supplied data for AI training should treat the possibility of exposure seriously until more definitive information appears. Practical first steps include monitoring financial and email accounts for unusual activity, enabling multi-factor authentication wherever available, and being alert to phishing messages that reference genuine projects or contacts. If you have reason to believe your personal data was among the materials, consider placing fraud alerts with credit bureaus and reviewing privacy settings on related services.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach datasets. Such a check provides an early indicator but does not replace official notifications from the organisation itself. Continue to watch for any formal statements from h2o.ai that clarify the scope and offer specific guidance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Network Technology Services of New Jersey Listed by linkc Ransomware GroupStrongLink Listed by linkc Ransomware GroupSajet Products Listed by linkc Ransomware GroupLuminex Software Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the h2o.ai Listed by linkc Ransomware Group →
Publicly posted by linkc — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.