LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › idom.com Listed by lynx Ransomware Group

HIGH severityUnverified claimHow we verify

idom.com Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 3, 2024
idom.com Listed by lynx Ransomware Group

Reported September 3, 2024.

HIGH
Severity
September 3, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

idom.com has been listed by the lynx ransomware group, with internal files reported exfiltrated in an attack disclosed on 3 September 2024. An undisclosed number of individuals may be affected; anyone connected to the organisation should review their exposure and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to list organisations on leak sites as a pressure tactic, often after claiming to have stolen internal files. In this climate, even limited public claims can leave employees, partners and clients uncertain about what may have been taken and how to respond.

On 3 September 2024, the organisation idom.com was listed by the lynx ransomware group. Public detail is limited: the number of people affected is unknown, and the only data type named is internal files said to have been exfiltrated in a ransomware attack. The listing itself remains an unverified claim by the group.

Inside the incident

According to the available record, idom.com appeared on a lynx leak-site listing dated 3 September 2024. The group claims that internal files were exfiltrated as part of a ransomware attack. No confirmed timeline of intrusion, no method of initial access, no ransom demand figure, and no verified volume of data have been disclosed in the public facts. The number of people affected is listed as unknown. Beyond the group’s claim of exfiltration of internal files, further operational detail has not been made public.

A partial Spanish-language summary associated with the report begins by referencing the founding of IDOM by Rafael Escolá in 1957, but does not expand into confirmed technical findings about the incident itself. Readers should treat the leak-site entry as an assertion by the threat actor rather than an independently verified disclosure.

Who is lynx?

Lynx is a ransomware operation that has appeared in public reporting as a group that encrypts systems and threatens to publish stolen data if demands are not met. Like other contemporary ransomware crews, it typically relies on double-extortion: locking systems while also claiming to have copied files for later release. Public analyses of the group describe common tactics such as initial access through compromised credentials or exposed services, followed by lateral movement and data staging before encryption. Lynx has previously listed other organisations on its leak site; those listings are likewise claims until corroborated by the victim or independent investigation.

In this case, the only specific assertion tied to idom.com is the group’s claim that internal files were exfiltrated. No further statements attributed to lynx about this particular victim appear in the provided facts.

About idom.com

IDOM is an engineering and consulting organisation whose public history traces to its founding by Rafael Escolá in 1957. Firms of this type typically work on infrastructure, industrial, energy and urban projects, handling design documents, project data, client correspondence and internal operational records. Because such organisations sit at the intersection of technical design and client relationships, a claimed breach can raise concerns for project partners, employees and any third parties whose information may have been stored in internal systems.

A ransomware listing against an engineering consultancy is consequential not only for the firm’s own continuity but also for the trust of clients who rely on the confidentiality of plans, contracts and related materials. Public facts do not establish negligence or confirm the full scope of any compromise; they simply record that the organisation was named by the group.

The information in question

The facts name only “internal files exfiltrated in ransomware attack.” No inventory of specific file types, no count of records, and no confirmation of personal data categories have been published. Organisations in the engineering and consulting sector commonly hold project documentation, employee records, client contracts, financial materials and technical drawings. Whether any of those categories were among the files claimed by lynx is unconfirmed.

Because the exact contents remain undisclosed, it is not possible to state with certainty what personal or commercial data, if any, left the organisation’s control. The group’s claim of exfiltration should be weighed against the absence of independent verification in the public record.

The real-world impact

For individuals, the practical risk depends on whether personal identifiers, contact details or credentials were among the internal files. Without confirmed data types or an affected-person count, the exposure cannot be quantified. Possible consequences in similar incidents include targeted phishing that references internal projects, attempts to reuse passwords, or social-engineering approaches aimed at employees and partners. For the organisation, a ransomware claim can disrupt operations, require forensic investigation, and trigger contractual or regulatory notification duties once the scope is better understood.

Until more detail emerges, the prudent stance is to treat the listing as a credible warning rather than a fully mapped breach. Affected parties, if any, have not been publicly enumerated.

Were you affected?

If you have a relationship with idom.com—as an employee, contractor, client or partner—consider these practical first steps:

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Public information on this incident remains limited; further Reported Details, if released by the organisation or investigators, should take precedence over the threat actor’s listing alone.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyidom.com security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See idom.com’s full breach history →

More recent breaches

Amourgis & Associates Listed by lynx Ransomware GroupDecember 25, 2024Astaphans Listed by lynx Ransomware GroupDecember 10, 2024The Wendt Agency Listed by lynx Ransomware GroupNovember 30, 2024PHG CPAs (bushman.biz) Listed by lynx Ransomware GroupNovember 24, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the idom.com Listed by lynx Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lynx — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram