marcom-inc.ca Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
marcom-inc.ca has been listed by the safepay ransomware group, which claims to have exfiltrated internal files in a ransomware attack; the incident was disclosed on 30 March 2025. Individuals who have interacted with marcom-inc.ca are advised to review any notices from the organisation and consider protective steps such as monitoring accounts and changing passwords.
On March 30, 2025, the Canadian firm marcom-inc.ca was listed by the ransomware group known as safepay. Public reporting indicates that internal files were exfiltrated during a ransomware attack, though the number of people affected remains unknown and further technical details have not been disclosed. The listing itself is a claim published by the group on its leak site.
For an organisation that supplies safety training to businesses in construction, transportation and manufacturing, any unauthorised access to internal systems raises practical questions about the security of operational records, client information and compliance materials. Exact contents of the taken files have not been confirmed beyond the description of internal files.
What happened
According to available public information, marcom-inc.ca appeared on a safepay leak-site listing dated March 30, 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No official confirmation from the company itself has been included in the provided record, and the scale of the incident—how many systems were involved, whether encryption occurred alongside theft, or the precise timeline of access—has not been disclosed. The number of individuals whose data may have been involved is listed as unknown. In short, the public record consists of the group’s claim of a ransomware incident that included data theft of internal files, without independent verification of volume, method or full impact at the time of reporting.
Inside safepay
Safepay is a ransomware operation that has been observed using double-extortion tactics: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. Like many contemporary groups, it maintains a dark-web leak site where it posts victim names and, in some cases, samples of stolen material to pressure payment. Public reporting on safepay describes a relatively recent entrant that follows the common ransomware-as-a-service model, in which affiliates conduct intrusions and share proceeds with operators who supply the encryption tools and infrastructure. Typical entry points for such groups include compromised credentials, unpatched remote-access services or phishing, though the specific vector used against any given victim is rarely confirmed in open sources. The group’s listings should be treated as claims rather than independently Reported Facts; they serve the dual purpose of advertising the group’s activity and increasing pressure on the named organisation. No statements attributed specifically to safepay about the contents or value of marcom-inc.ca’s files beyond the general assertion of internal-file exfiltration appear in the available record.
Who is marcom-inc.ca?
Marcom Inc., operating under marcom-inc.ca, is a Canadian company that provides safety-training solutions to other businesses. Its offerings include digital, online and DVD-based courses available in multiple languages, together with tools for compliance tracking, reporting and customisable content. The programmes target sectors such as construction, transportation and manufacturing—industries in which workplace safety regulations are strict and training records often form part of regulatory or contractual obligations. Organisations of this type typically maintain databases of client companies, employee training histories, course materials, billing information and internal operational documents. A breach involving such a provider can therefore affect not only the firm’s own staff and systems but also the compliance posture of the many businesses that rely on its training products. Because safety-training records can be required for audits, insurance or legal defence after workplace incidents, any compromise of integrity or confidentiality carries operational consequences beyond pure data loss.
What data was at risk
The public facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown—such as whether the files included customer lists, employee personal information, financial records, training databases or proprietary course content—has been disclosed. Organisations that deliver compliance and safety training commonly hold names, contact details, employment or contractor identifiers, course completion certificates, payment data and internal correspondence. They may also store customised training modules developed for specific clients. Because the exact inventory of the taken material remains unconfirmed, it is not possible to state with certainty which of these categories, if any, were involved. Readers should treat any more detailed claims circulating online as unverified unless corroborated by the company or by independent forensic reporting.
What's at stake
For individuals whose information may have been among the internal files, the primary risks are identity-related misuse, targeted phishing that references legitimate training or employment details, and potential exposure of personal contact or employment data. For client companies that use marcom-inc.ca’s services, the concern centres on the integrity of training records that may be needed for regulatory compliance or insurance purposes, as well as the possibility that proprietary operational information shared during custom course development could surface. For marcom-inc.ca itself, the incident raises questions of operational continuity, potential contractual liabilities toward clients, and the cost of investigation, remediation and notification. Because the number of affected people is unknown and the precise data types remain limited to the description “internal files,” the full scope of these risks cannot yet be quantified. The absence of Reported Details does not eliminate the possibility of harm; it simply means that affected parties must proceed on the basis of prudent caution rather than precise knowledge.
If your data was in this claimed breach
If you have done business with marcom-inc.ca—whether as an employee, contractor, client contact or trainee—consider taking a few measured steps. Monitor financial and email accounts for unexpected activity, and treat unsolicited messages that reference safety training or compliance records with heightened scepticism. Change passwords on any accounts that may have shared credentials with systems used for training access, and enable multi-factor authentication where available. If you receive notification from the company, follow its instructions for credit monitoring or other protective services it may offer. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. Keep records of any correspondence related to the incident, and report confirmed misuse of your personal information to the appropriate Canadian privacy or consumer-protection authorities. Public detail remains limited; further clarity will depend on additional statements from the organisation or independent investigators.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ggw.net Listed by safepay Ransomware Groupuwock.ca Listed by safepay Ransomware Groupprecisionaluminum.ca Listed by safepay Ransomware Groupstudioelad.it Listed by safepay Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the marcom-inc.ca Listed by safepay Ransomware Group →
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.