Mozo Grau (mozo-grau.com) Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Mozo Grau (mozo-grau.com) has been listed by the fog ransomware group, with internal files reported to have been exfiltrated. The breach was disclosed on February 13, 2025; the exact date of the intrusion has not been established.
On February 13, 2025, the Spanish dental implant manufacturer Mozo Grau, which operates the website mozo-grau.com, was publicly listed by the fog ransomware group. The listing asserts that the company suffered a ransomware attack in which internal files were exfiltrated. The number of people affected remains unknown, and public detail on the incident is limited to this claim and the reported fact of internal-file theft.
Because the listing originates from a threat actor rather than an independent confirmation, the full extent of any compromise has not been verified. What is known so far is that fog has claimed responsibility for accessing and removing internal material from Mozo Grau’s systems.
Inside the incident
According to the available record, Mozo Grau was listed by fog on February 13, 2025. The only data type named as exposed is internal files said to have been exfiltrated during a ransomware attack. No figure has been given for the volume of data taken, no timeline of the intrusion has been published, and the number of individuals potentially affected is listed as unknown. The method of initial access, the duration of the attackers’ presence inside the network, and whether encryption was also deployed remain undisclosed. Public information stops at the group’s claim that internal files were removed.
Inside fog
Fog is a ransomware group that emerged in public reporting in 2024 and has since operated a double-extortion model: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group maintains a leak site on which it posts victim names and, in some cases, samples of stolen material. Fog has targeted organisations across multiple sectors, typically using common initial-access techniques such as compromised credentials or unpatched remote services, followed by lateral movement and data staging. Its listings are claims made by the group itself; they are not independent confirmations of a breach. In the present case, fog’s listing of Mozo Grau constitutes an unverified assertion that internal files were exfiltrated.
Who is Mozo Grau (mozo-grau.com)?
Mozo Grau is a Spanish company specialising in the design and manufacture of dental implants and related surgical components. Organisations of this type routinely maintain technical product data, supplier and distributor records, employee information, and commercial correspondence with clinics and laboratories. Because the firm operates in the medical-device sector, it may also hold regulatory documentation, quality-control files, and limited customer or patient-related material generated through professional channels. A breach at such an organisation is consequential because the data it holds can include both proprietary business information and personal details of staff or professional partners, any of which could be misused if they leave the company’s control.
What was likely exposed
The only data type explicitly named in the public record is “internal files” said to have been exfiltrated. No further breakdown—such as whether the material included employee records, financial documents, customer lists, or technical drawings—has been disclosed. Organisations in the dental-implant sector typically store employee personal data, commercial contracts, research and development files, and correspondence with healthcare providers. It is therefore possible that some combination of these categories was among the internal files claimed by fog, yet the exact contents remain unconfirmed. Readers should treat any more specific description as speculative until additional verified information appears.
What's at stake
For individuals whose information may have been among the internal files, the practical risks include targeted phishing, identity misuse, or unsolicited contact that leverages knowledge of their professional or personal details. Employees or business partners could face credential-stuffing attempts if login data or contact lists were taken. For Mozo Grau itself, the exposure of internal files can disrupt operations, damage commercial relationships, and create regulatory obligations under data-protection rules that apply to personal information held by Spanish companies. Because the scale of the exfiltration is unknown, the precise level of harm cannot yet be measured; the known risk is simply that material the company regarded as internal is now claimed to be outside its control.
Were you affected?
If you have a professional or personal relationship with Mozo Grau—whether as an employee, supplier, distributor, or clinic partner—monitor financial and email accounts for unexpected activity and consider changing passwords that may have been reused. Enable multi-factor authentication wherever possible. Because the number of people affected is unknown and the precise data types remain unconfirmed, the only reliable way to check whether your own email address has appeared in previously published breach collections is to run a free exposure scan. Such a scan will not confirm involvement in this specific incident, but it can alert you to other known exposures that may require attention.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
RAE (Real Academia Española) (rae.es) Listed by fog Ransomware GroupUniversity Diagnostic Medical Imaging, PC (udmi.net) Listed by fog Ransomware GroupMagnolia Manor (magnoliamanor.com) Listed by fog Ransomware GroupInelmatic Listed by fog Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Mozo Grau (mozo-grau.com) Listed by fog Ransomware Group →
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.