LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MDB Listed by rhysida Ransomware Group

HIGH severityUnverified claimHow we verify

MDB Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 26, 2025
MDB Listed by rhysida Ransomware Group

Reported April 26, 2025.

HIGH
Severity
April 26, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

MDB was listed by the rhysida ransomware group on April 26, 2025, after internal files were taken during an attack. If you have any connection to MDB, review your accounts and watch for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to list organisations on dark-web leak sites as part of double-extortion campaigns, claiming they have stolen data and will publish it unless demands are met. These listings form part of a broader pattern in which threat actors target mid-sized firms across Europe, using the threat of public exposure to pressure victims. Against that backdrop, the Italian company MDB has appeared on a listing associated with the Rhysida ransomware group.

Public reporting on 26 April 2025 stated that MDB had been listed by Rhysida. The group claims internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed. For individuals or partners who may have dealt with the firm, the listing raises questions about what information could be at risk and what practical steps to take.

Breaking down the breach

According to the available record, MDB was listed by the Rhysida ransomware group on or around 26 April 2025. The report states that internal files were exfiltrated in a ransomware attack. No confirmed figure has been given for the number of people affected, and the precise date of the intrusion, the initial access method, and the volume of data taken have not been made public. The listing itself is a claim by the group; independent confirmation of the full scope of the incident has not been provided in the source material. Public detail on timing, scale and technical method therefore remains limited.

The group behind it: rhysida

Rhysida is a ransomware operation that has been active in the public domain since 2023. The group typically employs a double-extortion model: it encrypts systems and simultaneously steals data, then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. Rhysida has previously listed organisations across multiple sectors and countries, often using the same pattern of claiming data exfiltration and setting a countdown for publication. Its operators have been observed using common ransomware tooling and negotiating through dedicated chat portals. In this case the group claims that MDB’s internal files were taken; no further specific statements by Rhysida about this victim beyond the listing itself are recorded in the available facts.

MDB and its sector

MDB Srl was founded in 1977 by Mario Di Biase in Abruzzo, Italy. Beyond that founding information, public detail on the company’s precise business activities is limited in the source material. Organisations of this type—long-established Italian limited companies—commonly hold internal operational records, employee information, supplier and customer correspondence, and financial documentation. A ransomware incident involving such a firm can therefore affect not only the company itself but also anyone whose data appears in those internal files. The consequence of a listing is that partners, staff or clients may face secondary risks if the claimed data is later released or sold.

What data was at risk

The available facts state that internal files were exfiltrated. No more granular inventory of data types—such as names, contact details, financial records or authentication credentials—has been disclosed. Organisations of MDB’s profile typically maintain personnel files, commercial contracts, invoices and internal communications. Because the exact contents remain unconfirmed, it is not possible to state with certainty which categories of personal or business information were involved. Readers should treat the exposure as potential rather than proven until further verified details emerge.

The real-world impact

For individuals whose information may have been present in the internal files, the practical risks include phishing attempts that reference genuine company details, identity-related fraud if personal data was included, and unwanted contact from criminals who obtain the material. For MDB itself the impact can include operational disruption, reputational damage, regulatory scrutiny under European data-protection rules, and the cost of investigation and remediation. Because the number of affected people is unknown and the precise data set is unconfirmed, the scale of these effects cannot yet be quantified. The listing alone, however, is sufficient to create ongoing uncertainty for anyone who has had a relationship with the company.

What to do if you're exposed

If you have reason to believe your information may have been held by MDB, begin by monitoring financial and email accounts for unusual activity and treat any unexpected messages that reference the company with caution. Change passwords on related accounts and enable multi-factor authentication where available. Consider placing fraud alerts with relevant credit agencies if personal identifiers could have been involved. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; such a scan provides an additional, independent signal of whether your details have circulated. Keep records of any suspicious contact and report confirmed fraud to the appropriate authorities.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMDB security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See MDB’s full breach history →

More recent breaches

ZCORP Listed by rhysida Ransomware GroupAugust 27, 2025Clarity Ventures Listed by rhysida Ransomware GroupApril 2, 2025Cheyenne & Arapaho Tribes Listed by rhysida Ransomware GroupFebruary 17, 2026Phoenix Art Museum Listed by rhysida Ransomware GroupFebruary 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the MDB Listed by rhysida Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by rhysida — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram