Machu Picchu Foods Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Machu Picchu Foods was listed by the sarcoma ransomware group on June 24, 2025, after internal files were exfiltrated in a ransomware attack. The number of individuals affected has not been disclosed; anyone who had dealings with the company should review their accounts and monitor for unusual activity.
Ransomware groups continue to target manufacturers and food producers worldwide, using data theft and public leak-site listings as leverage. In this environment, even mid-sized specialty firms can find themselves named on criminal forums, with limited public detail available about what was taken or how the intrusion occurred.
On 24 June 2025, the ransomware group sarcoma listed Machu Picchu Foods, a Peruvian cocoa and chocolate manufacturer, claiming to have exfiltrated internal files. The listing states a 68 GB archive of files. The number of people affected remains unknown, and independent confirmation of the breach has not been publicly detailed beyond the group’s claim.
What happened
According to the sarcoma leak-site listing reported on 24 June 2025, Machu Picchu Foods was the victim of a ransomware attack in which internal files were exfiltrated. The group claims the material consists of a 68 GB archive containing files. No further public information has been released about the date of intrusion, the initial access method, whether systems were encrypted, or whether any ransom demand was paid. The scale of impact on individuals is undisclosed; the record simply notes that the number of people affected is unknown. All specifics beyond the group’s listing remain unconfirmed by independent sources.
Inside sarcoma
Sarcoma is a ransomware operation that follows the now-common double-extortion model: operators encrypt victim systems and simultaneously steal data, then threaten to publish the material on a dedicated leak site if payment is not made. Like other groups of this type, sarcoma typically posts victim names, claimed data volumes, and sample files to pressure organisations. Public reporting on the group has documented its focus on corporate networks across multiple sectors and geographies, with listings that often include archive sizes measured in tens of gigabytes. In this case, the group claims Machu Picchu Foods as a victim and asserts possession of a 68 GB archive of files; those assertions have not been independently verified in the available record.
Who is Machu Picchu Foods?
Machu Picchu Foods describes itself as a leading manufacturer in Peru of single-origin cocoa and chocolates. Its products are positioned in the premium chocolate market for their fine and aromatic flavour profile, and the company emphasises sustainable, organic and allergen-free production. As a food manufacturer handling agricultural supply chains, production records, quality-control data and commercial relationships, the organisation would typically hold operational, supplier and possibly customer or employee information. A breach at such a firm is consequential because it can expose internal business processes, trade-related documents and any personal data tied to staff or partners, while also risking reputational harm in a market that values provenance and quality assurances.
The information in question
The sarcoma listing states that internal files were exfiltrated and that the material comprises a 68 GB archive containing files. No more granular inventory—such as specific document types, databases or categories of personal data—has been disclosed in the public record. Organisations of this kind commonly maintain production schedules, supplier contracts, quality and certification records, financial documents, and employee or contact information. Whether any of those categories appear in the claimed archive is unconfirmed; the exact contents remain unknown beyond the group’s general description of “files.”
What's at stake
For individuals whose information may have been present, the practical risks include potential misuse of contact details, identity-related fraud if personal identifiers were included, or targeted phishing that leverages knowledge of the company’s operations. Because the number of affected people and the precise data types are undisclosed, the scope of personal exposure cannot be quantified from public sources. For the organisation itself, the listing creates operational and reputational pressure: competitors or counterparties may scrutinise the claim, customers may seek reassurance about product integrity and data handling, and any subsequent public release of files could reveal proprietary processes or commercial relationships. Recovery also involves technical remediation, legal notification obligations under applicable privacy rules, and the longer-term cost of restoring trust.
If your data was in this claimed breach
If you have a past or present connection to Machu Picchu Foods—as an employee, supplier, customer or partner—treat the possibility of exposure seriously even though the exact contents are unconfirmed. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and be alert to phishing messages that reference the company or its products. Consider placing fraud alerts with credit bureaus if you believe personal identifiers may have been involved. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official statements from the company, if issued, should be followed for any specific guidance or support channels.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Harinera del Valle Listed by sarcoma Ransomware GroupStrand Ag Supply Listed by sarcoma Ransomware GroupBuford Ranches Listed by sarcoma Ransomware GroupFAKO-M Getränke Listed by sarcoma Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Machu Picchu Foods Listed by sarcoma Ransomware Group →
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.