IAD GmbH Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
IAD GmbH was listed by the sarcoma ransomware group on September 17, 2025, after internal files were exfiltrated in a ransomware attack. Anyone connected to the company should check whether their data has been exposed and take appropriate protective steps.
IAD GmbH, a German provider of training, certification and related professional services, was listed by the sarcoma ransomware group on or around 17 September 2025. Public reporting indicates that the group claims to have exfiltrated internal files during a ransomware attack, with a stated leak size of 43 GB containing files, SQL data and Exchange material. The number of people affected remains unknown, and independent confirmation of the full scope is limited.
The listing matters because organisations of this type routinely handle personal, professional and operational records. Until more detail emerges, anyone who has interacted with IAD GmbH—clients, candidates, staff or partners—has reason to treat the claim seriously and to take basic protective steps.
Inside the incident
According to the available record, sarcoma listed IAD GmbH as a victim and asserted that internal files had been taken in a ransomware attack. The group described a 43 GB archive that includes files, SQL databases and Exchange content. The date associated with the public report is 17 September 2025. No further technical details—such as the initial access method, the precise timeline of encryption or exfiltration, or any ransom demand—have been disclosed in the facts provided. The number of individuals whose data may be involved is listed as unknown. Public detail beyond the group’s own claim and the high-level description of the archive is therefore limited.
Ransomware incidents of this kind typically involve both encryption of systems and the theft of data for leverage. In this case the facts explicitly note exfiltration of internal files, but they do not confirm whether systems were encrypted, whether a ransom was paid, or whether the data has been released beyond the listing itself. All such points remain unconfirmed.
The group behind it: sarcoma
Sarcoma is a ransomware operation that follows the now-common double-extortion model: operators encrypt victim systems and simultaneously steal data, then threaten to publish the material on a dedicated leak site if payment is not made. Like other groups in this category, sarcoma typically advertises victims on its site with brief descriptions of the stolen volume and file types, using the listing as pressure. Public reporting on sarcoma has documented a pattern of targeting organisations across multiple sectors and geographies, often focusing on mid-sized entities that hold operationally sensitive or personal data.
In the present case the group claims that IAD GmbH’s data was taken and that the archive measures 43 GB and contains files, SQL and Exchange material. That claim has not been independently verified in the available facts; it should be treated as an assertion by the threat actor rather than established fact. No statements attributed to sarcoma beyond the listing itself are recorded here.
IAD GmbH and its sector
IAD GmbH operates in Germany and offers training and certification services, including in-house Pearson VUE test centres in Erfurt, Jena, Leipzig, Marburg and Nordhausen. Additional services listed in public descriptions include room and hardware rental, consulting and recruitment of skilled workers. The organisation therefore sits at the intersection of professional education, IT certification and workforce services.
Companies in this sector commonly process personal identification details, contact information, examination and certification records, scheduling data, and internal business documents. They may also hold email systems, databases of candidates or clients, and operational files. A breach involving such an organisation is consequential because the data can be used for identity misuse, targeted phishing, or disruption of certification and recruitment processes that many individuals and employers rely upon.
What data was at risk
The facts state that internal files were exfiltrated and that the claimed archive contains files, SQL and Exchange material. No more granular inventory—such as specific categories of personal data, employee records, or client lists—has been disclosed. The exact contents therefore remain unconfirmed.
Organisations that run training centres, certification programmes and recruitment services typically hold names, contact details, identification or registration numbers, examination results, email correspondence, and internal administrative databases. Exchange content would ordinarily include email messages and calendars; SQL databases could store structured records of candidates, bookings or staff. Because the precise composition of the 43 GB archive has not been independently detailed, it is not possible to state which of these categories, if any, were actually present. Readers should assume that any information previously shared with IAD GmbH could theoretically be involved until clearer confirmation appears.
The real-world impact
For individuals, the primary risks are secondary misuse of personal or professional data: phishing emails that appear to come from a trusted training or certification body, attempts to reset accounts using known details, or social-engineering approaches that reference genuine interactions with IAD GmbH. If email or contact data were among the material, spam and credential-stuffing attempts may increase. For the organisation itself, the incident can disrupt operations, damage trust with clients and partners, and create regulatory notification obligations under European data-protection rules.
Because the number of people affected is unknown and the full data inventory is unconfirmed, the scale of individual harm cannot yet be quantified. The practical consequence is that anyone who has sat exams, booked services, worked with, or otherwise supplied information to IAD GmbH should treat the possibility of exposure as real and act accordingly, without assuming the worst or the best.
Were you affected?
If you have dealt with IAD GmbH—whether as a candidate, client, employee or partner—begin with basic hygiene: change passwords for any accounts that may have reused credentials linked to the organisation, enable multi-factor authentication wherever available, and treat unexpected emails or calls that reference training, certification or recruitment with extra caution. Monitor financial and identity accounts for unusual activity. Public detail on this incident remains limited, so continued attention to official statements from IAD GmbH or relevant authorities is advisable.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step does not confirm or rule out involvement in this specific incident, but it provides a practical way to see whether your address has surfaced elsewhere and to prioritise further protective measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Söllner Listed by sarcoma Ransomware GroupPaul Hildebrandt Listed by sarcoma Ransomware GroupMACMA Werbeartikel oHG Listed by sarcoma Ransomware GroupPfullendorfer Tor-Systeme Listed by sarcoma Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the IAD GmbH Listed by sarcoma Ransomware Group →
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.