LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › iMatica Listed by rhysida Ransomware Group

HIGH severityUnverified claimHow we verify

iMatica Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 27, 2023
iMatica Listed by rhysida Ransomware Group

Reported June 27, 2023.

HIGH
Severity
June 27, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The iMatica Listed by rhysida Ransomware Group (reported June 27, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In late June 2023, the Spanish business-software firm iMatica appeared on a ransomware leak site operated by the group known as rhysida. The listing asserted that internal files had been taken in an attack and made available for download. For employees, clients, and partners whose records may sit inside those files, the practical stakes are straightforward: unknown volumes of business and personal information could now be in the hands of criminals or circulating more widely, with no public confirmation yet of exactly whose data is involved or how far it has spread.

Public detail remains limited. The number of people affected has not been disclosed, and independent verification of the group’s claims has not been published. What is known comes chiefly from the leak-site entry itself and from the company’s own description of its work.

What happened

On or around 27 June 2023, iMatica was listed by the rhysida ransomware group. According to the group’s own post, the incident involved a ransomware attack in which internal files were exfiltrated. The listing described a data catalog of 717 GB containing 568 473 files and stated that the material had been uploaded rather than sold, inviting “data hunters” to examine it. No further technical details—such as the initial access method, the precise date of intrusion, or confirmation that systems were encrypted—have been made public in the available record. The number of individuals whose information may be contained in the files is unknown.

Because the primary source is the threat actor’s own claim, the scale and contents of the alleged exfiltration should be treated as unverified until corroborated by the company or by independent investigators.

Inside rhysida

Rhysida is a ransomware operation that emerged into wider public view in 2023. Like many contemporary groups, it has typically pursued a double-extortion model: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. The group maintains a leak site on which it names victims and, in some cases, posts sample files or full archives. Its listings frequently include volume figures and file counts, as seen in the iMatica entry, and sometimes carry taunting language directed at both the victim and outside observers.

Public reporting on rhysida has linked the group to attacks across multiple sectors and countries. Its operators have generally avoided highly specific claims about individual victims beyond what appears on the leak site; any assertion that particular data from iMatica was taken therefore rests on the group’s own statement rather than on confirmed forensic findings released by the company.

About iMatica

iMatica describes itself as a firm founded in 2001 in Girona, Spain, that later expanded across the Iberian peninsula. Its core business is the implementation of enterprise resource planning (ERP) and related business-management software—systems that handle billing, accounting, inventory, and other operational processes for client companies. Organisations of this type routinely hold configuration data, client records, internal project files, and credentials or documentation needed to support those systems.

A breach at an ERP implementer is consequential because the firm sits at the intersection of its own corporate data and the operational data of the businesses it serves. Even if only internal files were taken, those files can contain client contact details, contractual information, system architecture notes, or other material that could be useful for further fraud or targeted attacks against iMatica’s customers.

The information in question

The available facts state that internal files were exfiltrated in a ransomware attack. The rhysida listing supplied volume figures—717 GB and 568 473 files—and indicated that the data had been uploaded for others to access. No itemised inventory of data types (for example, names, national identity numbers, financial records, or source code) has been published in the record provided.

Companies that implement ERP and accounting software typically store project documentation, client master data, invoices, employee records, and technical configuration files. Whether any of those categories appear in the material claimed by rhysida is unconfirmed. Readers should treat the exact contents as unknown until iMatica or a competent authority releases a verified description.

The real-world impact

For individuals whose information may be inside the files, the immediate risks are familiar: possible misuse of contact details for phishing, social-engineering attempts that reference real business relationships, or identity-related fraud if personal identifiers were present. Because the people affected remain unknown, anyone who has worked with or for iMatica—employees, contractors, or client staff—has reason to remain alert to unexpected communications that appear to draw on internal knowledge.

For the organisation itself, the consequences include the operational cost of investigation and recovery, potential contractual or regulatory obligations to notify clients, and reputational damage arising from the public listing. The fact that the group claimed the data was simply uploaded rather than held for private sale may increase the chance that copies will circulate among multiple actors, lengthening the window of exposure.

Were you affected?

If you have a past or present relationship with iMatica—as an employee, contractor, or client—monitor financial and email accounts for unusual activity and treat unsolicited messages that reference the company with caution. Change passwords on any accounts that may have been used in connection with iMatica systems, and enable multi-factor authentication where it is available. Consider placing fraud alerts with relevant credit or identity-protection services if you believe sensitive personal data could have been involved.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can indicate whether your address has surfaced elsewhere and help you prioritise further protective measures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyiMatica security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See iMatica’s full breach history →

More recent breaches

The Big Life group Listed by rhysida Ransomware GroupJuly 14, 2023IRIS Informatique Listed by rhysida Ransomware GroupJune 19, 2023Tyconz Listed by rhysida Ransomware GroupJune 18, 2023Leading Edge Speciali Listed by rhysida Ransomware GroupFebruary 6, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the iMatica Listed by rhysida Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by rhysida — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram