LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Machu Picchu Foods Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

Machu Picchu Foods Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 24, 2025
Machu Picchu Foods Listed by sarcoma Ransomware Group

Reported June 24, 2025.

HIGH
Severity
June 24, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Machu Picchu Foods was listed by the sarcoma ransomware group on June 24, 2025, after internal files were exfiltrated in a ransomware attack. The number of individuals affected has not been disclosed; anyone who had dealings with the company should review their accounts and monitor for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target manufacturers and food producers worldwide, using data theft and public leak-site listings as leverage. In this environment, even mid-sized specialty firms can find themselves named on criminal forums, with limited public detail available about what was taken or how the intrusion occurred.

On 24 June 2025, the ransomware group sarcoma listed Machu Picchu Foods, a Peruvian cocoa and chocolate manufacturer, claiming to have exfiltrated internal files. The listing states a 68 GB archive of files. The number of people affected remains unknown, and independent confirmation of the breach has not been publicly detailed beyond the group’s claim.

What happened

According to the sarcoma leak-site listing reported on 24 June 2025, Machu Picchu Foods was the victim of a ransomware attack in which internal files were exfiltrated. The group claims the material consists of a 68 GB archive containing files. No further public information has been released about the date of intrusion, the initial access method, whether systems were encrypted, or whether any ransom demand was paid. The scale of impact on individuals is undisclosed; the record simply notes that the number of people affected is unknown. All specifics beyond the group’s listing remain unconfirmed by independent sources.

Inside sarcoma

Sarcoma is a ransomware operation that follows the now-common double-extortion model: operators encrypt victim systems and simultaneously steal data, then threaten to publish the material on a dedicated leak site if payment is not made. Like other groups of this type, sarcoma typically posts victim names, claimed data volumes, and sample files to pressure organisations. Public reporting on the group has documented its focus on corporate networks across multiple sectors and geographies, with listings that often include archive sizes measured in tens of gigabytes. In this case, the group claims Machu Picchu Foods as a victim and asserts possession of a 68 GB archive of files; those assertions have not been independently verified in the available record.

Who is Machu Picchu Foods?

Machu Picchu Foods describes itself as a leading manufacturer in Peru of single-origin cocoa and chocolates. Its products are positioned in the premium chocolate market for their fine and aromatic flavour profile, and the company emphasises sustainable, organic and allergen-free production. As a food manufacturer handling agricultural supply chains, production records, quality-control data and commercial relationships, the organisation would typically hold operational, supplier and possibly customer or employee information. A breach at such a firm is consequential because it can expose internal business processes, trade-related documents and any personal data tied to staff or partners, while also risking reputational harm in a market that values provenance and quality assurances.

The information in question

The sarcoma listing states that internal files were exfiltrated and that the material comprises a 68 GB archive containing files. No more granular inventory—such as specific document types, databases or categories of personal data—has been disclosed in the public record. Organisations of this kind commonly maintain production schedules, supplier contracts, quality and certification records, financial documents, and employee or contact information. Whether any of those categories appear in the claimed archive is unconfirmed; the exact contents remain unknown beyond the group’s general description of “files.”

What's at stake

For individuals whose information may have been present, the practical risks include potential misuse of contact details, identity-related fraud if personal identifiers were included, or targeted phishing that leverages knowledge of the company’s operations. Because the number of affected people and the precise data types are undisclosed, the scope of personal exposure cannot be quantified from public sources. For the organisation itself, the listing creates operational and reputational pressure: competitors or counterparties may scrutinise the claim, customers may seek reassurance about product integrity and data handling, and any subsequent public release of files could reveal proprietary processes or commercial relationships. Recovery also involves technical remediation, legal notification obligations under applicable privacy rules, and the longer-term cost of restoring trust.

If your data was in this claimed breach

If you have a past or present connection to Machu Picchu Foods—as an employee, supplier, customer or partner—treat the possibility of exposure seriously even though the exact contents are unconfirmed. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and be alert to phishing messages that reference the company or its products. Consider placing fraud alerts with credit bureaus if you believe personal identifiers may have been involved. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official statements from the company, if issued, should be followed for any specific guidance or support channels.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMachu Picchu Foods security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Machu Picchu Foods’s full breach history →

More recent breaches

Harinera del Valle Listed by sarcoma Ransomware GroupAugust 6, 2025Strand Ag Supply Listed by sarcoma Ransomware GroupJune 4, 2025Buford Ranches Listed by sarcoma Ransomware GroupJune 4, 2025FAKO-M Getränke Listed by sarcoma Ransomware GroupApril 20, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Machu Picchu Foods Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram