nanoCAD Listed by malas Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The nanoCAD Listed by malas Ransomware Group (reported April 9, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On April 09, 2023, the ransomware group malas listed nanoCAD on its leak site, claiming a ransomware attack in which internal files were exfiltrated. Public reporting attributes the intrusion to exploitation of a Zimbra vulnerability. The number of people affected remains unknown, and independent confirmation of the full scope has not been published.
The listing itself is a claim by the group rather than a verified disclosure from the company. What is known so far is limited to the reported method, the nature of the data said to have been taken, and the date the claim appeared. For an organisation that develops computer-aided design software used in professional and industrial settings, any confirmed exposure of internal material carries potential consequences for clients, partners and staff.
What happened
According to the public report dated April 09, 2023, nanoCAD was listed by the malas ransomware group. The group claims that internal files were exfiltrated during a ransomware attack. The reported summary states that the intrusion made use of a Zimbra vulnerability. No further technical details, such as the precise timeline of initial access, the duration of the attackers’ presence, the volume of data removed, or whether encryption was also deployed, have been disclosed in the available facts. The number of individuals affected is recorded as unknown. Beyond the group’s leak-site listing and the brief reported summary, public detail on the incident remains limited.
Who is malas?
malas is a ransomware group that operates in the established pattern of double-extortion actors: after gaining access to a network, such groups commonly exfiltrate data and then threaten to publish it unless a ransom is paid. They typically advertise victims on dedicated leak sites to increase pressure. Public reporting on malas and similar groups shows they often exploit known vulnerabilities in widely deployed software, including collaboration and email platforms, to obtain initial footholds. Once inside, they move laterally, escalate privileges and stage data for removal before or alongside any encryption. The listing of nanoCAD is therefore best understood as a claim by the group; it does not by itself constitute independent verification that every asserted detail occurred exactly as described.
Who is nanoCAD?
nanoCAD is a provider of computer-aided design software used by engineers, architects and other professionals for drafting and modelling. Organisations in this sector typically maintain internal repositories of source code, design documentation, customer project files, licensing records, employee information and correspondence with partners. Because CAD tools sit inside supply chains for construction, manufacturing and infrastructure, a breach can raise concerns not only for the software maker itself but also for the confidentiality of work performed by its users. The consequential nature of an incident here stems from the sensitivity of the technical and commercial material such a company ordinarily holds, even when the precise contents of any given breach remain unconfirmed.
What was likely exposed
The facts state that internal files were exfiltrated in the ransomware attack. No more granular inventory—such as specific categories of personal data, customer lists, source-code repositories or financial records—has been named. Organisations of this type commonly store employee contact details, authentication credentials, proprietary design assets, support tickets and contractual documents. It is therefore reasonable to expect that material of those kinds could have been among the internal files, yet the exact contents remain unconfirmed. Readers should treat any assumption about particular data elements as speculative until corroborated by the organisation or by independent analysis of leaked samples.
The real-world impact
For individuals whose information may have been present in the exfiltrated files, the practical risks include targeted phishing that references internal projects or colleagues, credential stuffing if passwords or password hashes were among the material, and potential misuse of any personal contact or identity data. For nanoCAD itself, the exposure of internal files can affect intellectual-property confidentiality, customer trust and contractual obligations to protect third-party data. Because the scale of the breach and the precise data types are undisclosed, the severity for any single person or partner cannot be quantified from public facts alone. The absence of a confirmed headcount means that both employees and external users of the software should remain alert to unusual communications rather than assume they were or were not included.
Were you affected?
If you have an account, employment relationship or business connection with nanoCAD, treat unsolicited messages that reference the company or its projects with caution. Change passwords on related accounts, enable multi-factor authentication where available, and monitor financial and email accounts for unusual activity. Retain any official notifications the organisation may issue. Because the number of people affected is unknown and the full data inventory is unconfirmed, a prudent step is to check whether your email address has already appeared in other known breach data sets. You can run a free exposure scan of your email to see whether your information has surfaced in publicly indexed breach collections and then decide on further monitoring or credential changes accordingly.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Altarix Listed by malas Ransomware GroupLivitek Listed by malas Ransomware Groupmeta-spb Listed by malas Ransomware GroupAxon Listed by malas Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the nanoCAD Listed by malas Ransomware Group →
Publicly posted by malas — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.