LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MESHWORKS Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

MESHWORKS Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 25, 2024
MESHWORKS Listed by sarcoma Ransomware Group

Reported October 25, 2024.

HIGH
Severity
October 25, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

MESHWORKS was listed by the sarcoma ransomware group on 25 October 2024, with internal files reported to have been exfiltrated. Individuals connected to the organisation are advised to check whether their data was exposed and to take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 25 October 2024, the Australian industrial manufacturer MESHWORKS was listed on the leak site operated by the ransomware group known as sarcoma. The group claims to have conducted a ransomware attack that involved the exfiltration of internal files, presenting an 8 GB archive as evidence of the intrusion. Public detail remains limited: the number of people affected is unknown, and no independent confirmation of the full scope or method has been released. The listing matters because MESHWORKS supplies steel wire welded mesh used across mining, construction, rural, fabrication, safety, storage, temporary fencing and materials-handling sectors, meaning any compromise of its internal systems could affect commercial partners, employees and operational continuity.

What is known so far rests almost entirely on the group’s own claim and the sparse accompanying description. No official statement from MESHWORKS detailing the incident has been incorporated into the available record, so the precise timeline, initial access vector and extent of encryption or disruption stay undisclosed.

What happened

According to the sarcoma listing dated 25 October 2024, MESHWORKS suffered a ransomware attack in which internal files were exfiltrated. The group published a claim that an 8 GB archive containing files had been taken. Beyond that assertion, public information does not specify when the intrusion began, how long the attackers remained inside the network, whether systems were encrypted, or whether a ransom demand was issued or paid. The number of individuals whose data may have been involved is listed as unknown. The only concrete descriptors supplied are the organisation’s identity, its Australian base of operations, the claimed leak size of 8 GB, and the characterisation of the material as “Files” obtained through the ransomware attack. All other operational details remain unconfirmed.

The group behind it: sarcoma

Sarcoma is a ransomware operation that has appeared in public reporting as a double-extortion actor: it encrypts victim systems while also stealing data and threatening to publish it on a dedicated leak site if payment is not made. Like other groups in this category, sarcoma typically advertises victims with brief descriptions, sample file lists or archive sizes to pressure organisations into negotiation. The group’s listings are claims made by the attackers themselves; they are not independent verification that every asserted detail is accurate. In the MESHWORKS case, sarcoma asserts that it obtained and is prepared to release an 8 GB collection of internal files. No further statements attributed specifically to sarcoma about this victim—such as particular file names, financial demands or deadlines—appear in the available facts, so those elements cannot be treated as established.

MESHWORKS and its sector

MESHWORKS manufactures steel wire welded mesh for industrial use. Its products serve the mining, construction, rural, fabrication, safety, storage, temporary fencing and materials-handling industries. The company states that its mesh is produced in Australia from high-grade wire obtained from 100 percent recycled steel and is offered in a range of wire diameters, apertures and sheet sizes in both galvanised and bright finishes. Organisations of this type routinely maintain records of production specifications, customer orders, supplier contracts, employee information, quality-control documentation, logistics data and financial correspondence. Because the firm sits inside critical supply chains for infrastructure and resource extraction, a breach can create secondary effects for partners who rely on timely delivery of mesh products or who share commercial data with the manufacturer. The Australian location also places the incident under Australian privacy and critical-infrastructure considerations, though no regulatory findings have been published in the source material.

What data was at risk

The sarcoma listing states that internal files were exfiltrated and that the archive measures 8 GB. No further breakdown of file types, document categories or personal data fields is provided. Consequently the exact contents remain unconfirmed. Companies that manufacture industrial mesh typically hold a mixture of operational records—engineering drawings, production schedules, inventory lists—and administrative material such as employee contact details, payroll information, customer purchase orders, supplier invoices and internal email correspondence. Whether any of those categories were present in the claimed 8 GB archive cannot be verified from the published facts. The absence of a confirmed inventory means that statements about specific data elements would be speculative; only the group’s general claim of “internal files” and the stated archive size are on record.

Why it matters

For individuals whose information may have been among the internal files, the practical risks include potential misuse of contact details, employment records or other personal identifiers if those materials later appear in secondary markets or phishing campaigns. For MESHWORKS itself, the incident raises the possibility of operational disruption, loss of proprietary manufacturing know-how, and strained relationships with customers and suppliers who may question the security of shared commercial data. Even when encryption is not confirmed, the mere exfiltration claim can trigger contractual notification obligations, insurance reviews and reputational scrutiny. Because the number of people affected is unknown and the precise data types are undisclosed, the scale of individual harm cannot yet be quantified; the risk remains real but bounded by the limited public evidence. Organisations in the industrial-supply sector often process sensitive project information for mining and construction clients, so any leakage can also create downstream exposure for those third parties.

Were you affected?

If you are a current or former employee, contractor or commercial partner of MESHWORKS, treat the listing as a prompt to review your own exposure. Monitor financial and email accounts for unexpected activity, enable multi-factor authentication where available, and be alert to phishing messages that reference the company or its products. Consider changing passwords that may have been reused across work and personal services. Because the exact contents of the claimed archive are unconfirmed, there is no public list of affected individuals; the safest course is to assume that any data you shared with the organisation could be involved until further official detail emerges. Readers can also run a free exposure scan of their email address against known breach datasets to check whether their information has already surfaced in other incidents. Stay attentive to any formal notifications that MESHWORKS or Australian regulators may issue as the situation develops.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMESHWORKS security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See MESHWORKS’s full breach history →

More recent breaches

TMA Group of Companies Listed by sarcoma Ransomware GroupApril 10, 2025ADT Freight Services Australia Pty Lt Listed by sarcoma Ransomware GroupNovember 14, 2024Micon National Listed by sarcoma Ransomware GroupNovember 3, 2024CAS Software Listed by sarcoma Ransomware GroupOctober 31, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the MESHWORKS Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram