LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › mymobileforms app Listed by funksec Ransomware Group

HIGH severityUnverified claimHow we verify

mymobileforms app Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 13, 2025
mymobileforms app Listed by funksec Ransomware Group

Reported January 13, 2025.

HIGH
Severity
January 13, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

mymobileforms app has been listed by the funksec ransomware group, with internal files reported to have been exfiltrated. The incident was disclosed on January 13, 2025; users should check whether their data was involved and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On January 13, 2025, the mymobileforms app was listed by the funksec ransomware group as a victim of a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and public detail on the incident is limited to this listing and the basic description of the platform. The claim originates from the group's leak-site activity and has not been independently confirmed in the available record.

MyMobileForms is an online platform that helps users create, manage, and deploy digital forms for collecting data, allowing organizations to replace paper-based forms with mobile-friendly versions completed on smartphones, tablets, or computers. A breach involving such a service raises questions about the security of data gathered through those forms, even though exact exposure details are undisclosed.

Breaking down the breach

The incident centers on a listing by the funksec ransomware group that identifies mymobileforms app as a target. According to the reported summary, internal files were exfiltrated in a ransomware attack. No further public information is available on the precise timing of the intrusion, the method of initial access, the volume of data taken, or any ransom demand. The number of individuals potentially affected is unknown. The listing itself constitutes a claim by the group rather than verified confirmation from the organization or independent investigators. Public detail remains limited to the fact of the listing and the characterization of the data as internal files.

The group behind it: funksec

Funksec is a ransomware operation that has appeared in public threat reporting as a group that combines encryption of victim systems with data theft, a tactic commonly known as double extortion. Like many such actors, it maintains a leak site where it posts claims about compromised organizations and, in some cases, samples or larger dumps of stolen material if negotiations fail. The group typically seeks payment in cryptocurrency and pressures victims by threatening public release of exfiltrated files. Its listings are claims made by the operators themselves; they do not automatically prove the full extent of any intrusion. In this instance, funksec's listing of mymobileforms app asserts that internal files were taken, but no additional statements specific to this victim beyond that claim appear in the available facts.

mymobileforms app and its sector

MyMobileForms operates in the digital forms and data-collection software sector. Platforms of this type enable businesses, public agencies, and other organizations to design electronic forms, distribute them across devices, and gather responses that may include personal, operational, or customer information. The service is designed to replace paper processes with mobile-friendly digital workflows. Organizations that rely on such tools often process data ranging from contact details and survey responses to more sensitive operational records, depending on how clients configure their forms. A compromise of the platform itself can therefore affect not only the service provider but also the downstream users who entrust it with form data. Because the exact nature of any client data held by mymobileforms app is not detailed in public reports of this incident, the broader sector context simply underscores why listings of this kind attract attention.

What data was at risk

The available facts state that internal files were exfiltrated in the ransomware attack. No more granular inventory of file types, databases, or personal data categories has been disclosed. The number of people affected is unknown. Organizations that provide digital form platforms typically hold account credentials for administrators, configuration data for forms, and the responses submitted by end users; those responses can contain names, contact information, or other details supplied by respondents. However, none of these categories has been confirmed as present in the material claimed by funksec. Exact contents remain unconfirmed, and any assessment of specific personal data exposure would be speculative.

Why it matters

For individuals whose information may have passed through forms hosted on the platform, the primary concern is the possibility that personal details could later appear in unauthorized hands, raising risks of phishing, identity misuse, or unwanted contact. Because the scale and precise contents are undisclosed, the concrete impact on any given person cannot yet be measured. For the organization, a ransomware listing can disrupt operations, damage trust among clients who depend on the service for data collection, and trigger regulatory or contractual obligations depending on the jurisdictions and data types involved. Even when only internal files are named, the uncertainty itself can affect business continuity and customer confidence. The absence of confirmed numbers does not eliminate the need for vigilance; it simply means affected parties must proceed on the basis of limited public information.

If your data was in this claimed breach

If you have used MyMobileForms or submitted information through forms created on the platform, treat the listing as a reason to review your exposure rather than as proof of compromise. Change passwords associated with any accounts linked to the service, enable multi-factor authentication where available, and monitor financial and email accounts for unusual activity. Be alert to phishing messages that might reference the platform or claim to offer breach assistance. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Keep records of any notifications you receive from the organization itself, as official guidance will supersede general advice once it becomes available.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companymymobileforms app security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See mymobileforms app’s full breach history →

More recent breaches

extremeperformance.com Listed by funksec Ransomware GroupMarch 12, 2025isee-eg.com Listed by funksec Ransomware GroupMarch 11, 2025klabs.it Listed by funksec Ransomware GroupMarch 9, 2025mandarin.com.br Listed by funksec Ransomware GroupFebruary 28, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the mymobileforms app Listed by funksec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by funksec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram