La Canastería Listed by 8base Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The La Canastería Listed by 8base Ransomware Group (reported December 25, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 25 December 2022, the ransomware group known as 8base listed La Canastería on its leak site, claiming to have exfiltrated internal files in a ransomware attack. For customers, corporate clients, suppliers and staff whose details may sit inside those files, the practical stakes are straightforward: personal or business contact information, order histories or internal correspondence could surface without clear warning, raising the usual risks of unwanted contact, phishing or misuse.
Public detail remains limited. The number of people affected is unknown, and the precise contents of the files have not been independently confirmed. What is known is the claim itself and the nature of the organisation involved.
Breaking down the breach
According to the available record, La Canastería was listed by the 8base ransomware group on 25 December 2022. The group claimed that internal files had been exfiltrated as part of a ransomware attack. No further verified particulars—such as the exact date the intrusion began, the volume of data taken, the technical method used, or any ransom demand—have been disclosed in the material at hand. The scale of impact on individuals is likewise unconfirmed. The listing itself constitutes the group’s assertion; it has not been independently verified in the facts provided.
Who is 8base?
8base is a ransomware operation that became publicly visible in 2022 and has since maintained a leak site used to name organisations it claims to have compromised. Like many contemporaneous groups, it has typically followed a double-extortion model: encrypting systems while also copying data and threatening to publish it if payment is not made. The group has listed victims across multiple sectors and geographies. Its public posts are claims; they do not, by themselves, prove the full extent or accuracy of any particular incident. In this case, the only specific assertion tied to La Canastería is the listing and the statement that internal files were exfiltrated.
Who is La Canastería?
La Canastería is described as a leading company in its national market with more than twenty years of experience. It specialises in high-quality gifts directed at both the corporate market and a specialised public. Its catalogue includes a substantial wine selection—more than 3,000 bottles—and a range of Piscos. Organisations of this type routinely hold customer and client contact details, order and delivery records, supplier information, and internal operational documents. A breach involving such a business can therefore touch both private individuals who have purchased gifts or wine and corporate buyers who maintain accounts or receive invoices. The company’s public contact channels include its website and sales email and telephone numbers, underscoring its role as a retail and corporate-gift supplier.
The information in question
The facts state only that internal files were exfiltrated in a ransomware attack. No itemised inventory of data types—such as names, addresses, payment card numbers, employee records or specific document categories—has been disclosed. Organisations in the gift, wine and corporate-gifting sector commonly store customer names and contact details, shipping addresses, purchase histories, corporate account information and internal correspondence. Whether any of those categories were present in the files claimed by 8base remains unconfirmed. Readers should treat the precise contents as unknown until corroborated by the organisation or by independent analysis of leaked material.
Why it matters
When internal files leave an organisation’s control, the people named in them can face concrete, if often mundane, harms: targeted phishing that references real orders or colleagues, unwanted marketing or social-engineering attempts, and, in some cases, identity-related fraud if enough personal identifiers are present. For corporate clients the exposure may include commercial terms or contact lists that competitors or fraudsters could exploit. For La Canastería itself, the incident carries operational and reputational costs—system restoration, customer notification, and the need to rebuild trust—regardless of whether a ransom was paid. Because the number of affected individuals is unknown and the data types are not itemised, the full scope of residual risk cannot yet be measured. That uncertainty itself is a reason for caution rather than alarm.
Were you affected?
If you have purchased from La Canastería, held a corporate account, or worked with the company, treat unsolicited messages that reference past orders or internal details with scepticism. Monitor financial and email accounts for unusual activity, and consider changing passwords on any accounts that reused credentials linked to the business. You can also run a free exposure scan of your email address to check whether it has appeared in known breach datasets. Public confirmation from La Canastería about the exact data involved would provide clearer guidance; until then, ordinary vigilance remains the most practical step.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Direct Cleaning Services Listed by 8base Ransomware GroupLebensWohnArt Listed by 8base Ransomware GroupGIOTTO - COMÉRCIO DE VESTUÁRIO, UNIPESSOAL, LDA Listed by 8base Ransomware GroupIRO PARIS Listed by 8base Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the La Canastería Listed by 8base Ransomware Group →
Publicly posted by 8base — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.