MSB Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
MSB was listed by the sarcoma ransomware group on 29 September 2025, with an undisclosed number of internal files reported as exfiltrated. Individuals connected to MSB should review any notifications from the organisation and consider changing passwords or enabling additional account protections.
People and businesses that have worked with MSB General Contractors may now face questions about whether their project details, contact information, or related records have been taken. On September 29, 2025, the ransomware group sarcoma listed MSB on its leak site, claiming it had exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the full scope is limited, yet any exposure of contractor records tied to disaster recovery work carries real consequences for clients already dealing with emergencies.
The listing describes a 66 GB archive containing files and SQL data. For those whose information may be inside, the practical stakes are straightforward: possible misuse of personal or business details, disruption to ongoing recovery projects, and the need to monitor for follow-on fraud or unwanted contact.
What happened
According to the public listing, sarcoma claimed responsibility for a ransomware attack against MSB in which internal files were exfiltrated. The report is dated September 29, 2025. The group stated that a 66 GB archive of material, described as containing files and SQL data, had been taken. No confirmed figure for the number of individuals affected has been released, and further technical details such as the exact intrusion method, the date the attack began, or whether systems were encrypted remain undisclosed in the available record.
MSB is identified in the listing as a U.S.-based general contractor focused on disaster recovery services. The claim of data theft is presented by the group itself; independent confirmation of the full contents or of any subsequent public release of the archive has not been provided in the facts available here.
Inside sarcoma
Sarcoma is a ransomware operation that has appeared in public reporting as a double-extortion actor. Groups of this type typically gain access to a network, move laterally to locate valuable data, exfiltrate copies, and then threaten to publish the material on a dedicated leak site if a ransom is not paid. They often list victims with brief descriptions of the stolen data volume and file types to pressure the organisation.
Public knowledge of sarcoma’s activity shows a pattern of targeting organisations across multiple sectors and advertising the resulting archives. In this case the group claims MSB’s internal files were taken and packaged as a 66 GB archive containing files and SQL. No additional statements attributed specifically to this victim beyond the listing itself are part of the provided record, so the listing should be treated as an unverified claim until further confirmation appears.
MSB and its sector
MSB General Contractors specialises in disaster recovery services for residential and commercial clients affected by emergencies. The company provides support and solutions aimed at timely restoration of properties and operations, maintains a portfolio of completed projects, and has also engaged in humanitarian activities. It operates in the United States.
Organisations in the disaster-recovery and general-contracting sector routinely handle client contact details, project specifications, insurance-related documentation, site photographs, financial records, and internal operational files. Because these firms step in after fires, storms, floods or other crises, the data they hold often relates to people and businesses already under stress. A breach at such a firm can therefore affect not only the contractor’s own staff and partners but also homeowners, commercial property owners and community organisations that relied on the company for recovery work.
What was likely exposed
The sarcoma listing states that internal files were exfiltrated and describes a 66 GB archive containing files and SQL data. Beyond that description, the exact data types and any individual records remain unconfirmed. Public detail does not name specific categories such as customer names, addresses, payment information or employee records.
Companies of this kind typically store project files, client correspondence, scheduling and billing databases, and operational documents. SQL data often points to structured databases that may hold client or project information. Because the precise contents of the archive have not been independently verified or itemised in the available facts, it is not possible to state with certainty what personal or business information was taken. The only confirmed claim is the group’s assertion of internal files and a 66 GB collection of files and SQL.
What's at stake
For individuals and businesses that have engaged MSB, the primary risks include potential misuse of contact details, project information or any financial data that may have been present. Scammers sometimes use stolen contractor records to craft convincing phishing messages that reference real recovery work, increasing the chance that recipients will open malicious attachments or share further personal information. Identity-related fraud remains a longer-term concern if any personally identifiable information was included.
For MSB itself, the incident raises operational and reputational questions. Clients may seek reassurance about the security of their project data, and the company may face costs related to investigation, notification and remediation. Because the firm works in disaster recovery, any interruption or loss of trust can affect its ability to serve communities that need rapid assistance. The unknown number of people affected and the unconfirmed exact contents of the archive leave both the organisation and potentially impacted parties without a complete picture of exposure.
What to do if you're exposed
If you have been a client, partner or employee of MSB, treat the listing as a reason for caution rather than confirmed personal compromise. Monitor financial accounts and credit reports for unexpected activity. Be sceptical of unsolicited emails, calls or messages that reference recent disaster-recovery work or claim to come from the company; verify any such contact through known official channels. Consider placing a fraud alert with credit bureaus if you believe sensitive personal data may have been involved.
Change passwords on any accounts that reused credentials potentially stored by the firm, and enable multi-factor authentication where available. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Keep records of any suspicious contact and report clear fraud attempts to the relevant authorities. Public detail on this incident remains limited, so continued monitoring and basic hygiene remain the most practical immediate steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Söllner Listed by sarcoma Ransomware GroupgibGREINER Listed by sarcoma Ransomware GroupDMG Contractors Listed by sarcoma Ransomware GroupNorgeshus Listed by sarcoma Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the MSB Listed by sarcoma Ransomware Group →
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.