Omydoo Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Omydoo was listed by the fog ransomware group on February 13, 2025, with internal files reported as having been exfiltrated. The number of individuals affected has not been disclosed; anyone connected to the organisation should review their exposure and take appropriate protective steps.
On 13 February 2025, the French company Omydoo appeared on a ransomware leak site operated by the group known as fog. The listing asserts that internal files were taken during a ransomware attack. Public detail remains limited: the number of people whose information may be involved is unknown, and the precise contents of the files have not been independently confirmed. For employees, clients, and partners of a firm that implements management software for small and medium-sized businesses, the practical stakes are straightforward. Any internal material that leaves an organisation’s control can later surface in unwanted places, creating lasting inconvenience or risk even when the full scale of the incident is still unclear.
What is known so far is that fog claims responsibility for an attack that involved both ransomware and data exfiltration. Beyond that claim and the date it was reported, much of the picture has not been filled in by official statements or independent verification. The absence of confirmed numbers or a detailed inventory of files does not remove the need for caution; it simply means affected individuals must rely on general protective steps until more information emerges.
Inside the incident
According to the available record, Omydoo was listed by the fog ransomware group on or around 13 February 2025. The group’s claim states that internal files were exfiltrated as part of a ransomware attack. No further technical details—such as the initial access method, the duration of the intrusion, the volume of data taken, or whether systems were encrypted—have been publicly disclosed. The number of people affected is listed as unknown. No independent confirmation of the group’s assertions has been reported, so the listing itself remains an unverified claim at this stage.
Ransomware incidents of this type typically follow a double-extortion pattern: data is copied out of the network and then encryption is applied, after which the attackers threaten to publish the material if a payment is not made. In this case, only the claim of exfiltration of internal files has been recorded. Timing beyond the reporting date, the exact scope of systems involved, and any subsequent publication of the files are all undisclosed.
The group behind it: fog
Fog is a ransomware operation that has appeared on public leak sites in recent years. Like many contemporary groups, it is known for combining data theft with encryption and for posting victim names on dedicated leak portals to increase pressure. Public reporting on fog has described the use of common initial-access techniques, the deployment of ransomware payloads, and the subsequent listing of organisations that refuse or fail to negotiate. The group’s listings are claims made by the actors themselves; they are not independent confirmations that every stated detail is accurate.
In the present case, fog’s leak-site entry simply names Omydoo and asserts that internal files were taken. No additional statements attributed to the group about this specific victim—such as ransom demands, file samples, or deadlines—appear in the available facts. Background knowledge of fog’s general methods therefore supplies context, but it does not expand the Reported Facts of this particular incident.
Omydoo and its sector
Omydoo is a French company that specialises in implementing integrated management software solutions for small and medium-sized enterprises, primarily using the open-source ERP platform Odoo. Firms of this kind help clients manage core business processes—accounting, inventory, customer relations, human resources, and related operations—by configuring, customising, and supporting the software. As a result, such organisations routinely handle both their own internal corporate data and, in the course of projects, sensitive information belonging to the SMEs they serve.
A breach involving a company in this sector is consequential because the data it holds can extend beyond its own staff to the commercial and personal records of client businesses. Even when only “internal files” are mentioned, the practical reach of an incident can include project documentation, configuration details, correspondence, and any client material stored during implementation work. Public detail does not confirm which of these categories, if any, were involved here; the sector context simply explains why the listing has drawn attention.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as employee records, client databases, financial documents, source code, or credentials—has been disclosed. Organisations that implement ERP systems for SMEs typically maintain project files, internal administrative records, and sometimes copies or extracts of client data needed for configuration and support. Whether any of those categories were among the files claimed by fog remains unconfirmed.
Because the exact contents have not been published or independently verified, it is not possible to state with certainty what personal or commercial information may have left Omydoo’s systems. Readers should treat the exposure as limited to the description given: internal files whose precise nature is still unknown.
The real-world impact
For individuals whose data may be among the internal files, the concrete risks include potential misuse of contact details, business correspondence, or any personal identifiers that happened to be stored in project or administrative documents. Even incomplete or older files can be combined with information from other sources to support phishing, social-engineering attempts, or identity-related fraud. The absence of a confirmed headcount means the circle of potentially affected people cannot yet be drawn with precision; it may include current and former employees, contractors, and staff at client SMEs.
For Omydoo itself, the incident carries operational and reputational consequences common to ransomware events: possible disruption of services, the cost of investigation and recovery, and the need to notify partners or regulators if personal data is later confirmed to have been involved. Because the group’s claims have not been independently verified and the full scope remains undisclosed, the organisation’s exact exposure is still an open question. Affected parties are left to manage uncertainty rather than a fully mapped set of risks.
Were you affected?
If you have worked with Omydoo as an employee, contractor, or client, treat the possibility of exposure seriously even while details remain limited. Change passwords on any accounts that may have been linked to the company, enable multi-factor authentication wherever it is available, and watch for unexpected messages that reference the firm or its projects. Monitor financial and identity accounts for unusual activity. Because the number of people affected and the exact data types are still unknown, these steps are precautionary rather than a response to confirmed personal compromise.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such a check will not prove or disprove involvement in this specific incident, but it can indicate whether your information has surfaced elsewhere and help you prioritise further protective measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
VISEO Listed by fog Ransomware GroupADULLACT Listed by fog Ransomware GroupThe 19 biggest gitlabs Listed by fog Ransomware GroupMelexis Listed by fog Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Omydoo Listed by fog Ransomware Group →
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.