LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Peraso Listed by rhysida Ransomware Group

HIGH severityUnverified claimHow we verify

Peraso Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 21, 2025
Peraso Listed by rhysida Ransomware Group

Reported October 21, 2025.

HIGH
Severity
October 21, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Peraso was listed by the Rhysida ransomware group on October 21, 2025, following the theft of internal files. Individuals connected to the company should review any notifications and take steps to protect their information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People connected to Peraso may now face uncertainty about whether their personal or professional information sits among files claimed to have been taken in a ransomware incident. Public reporting on 21 October 2025 shows the company listed by the rhysida ransomware group, which states that internal files were exfiltrated. The number of people affected remains unknown, and exact details of what was taken have not been confirmed beyond that description. For anyone who has worked with, supplied, or otherwise shared data with Peraso, the practical concern is straightforward: once internal material leaves an organisation’s control, it can be used for further fraud, social engineering, or other misuse long after the initial event.

This article sets out only what is known from the public listing and established background on the actor and sector. No assumption is made that every claim is verified; the listing itself is treated as an assertion by the group.

Inside the incident

On 21 October 2025 Peraso appeared on a leak site operated by the rhysida ransomware group. The group claims that internal files were exfiltrated during a ransomware attack. No further technical detail—such as the precise date of intrusion, the method of access, the volume of data, or any ransom demand—has been publicly disclosed in the available record. The number of individuals whose information may be involved is listed as unknown. Public sources do not confirm whether Peraso has verified the claim, negotiated, or recovered systems. In short, the incident is known primarily through the group’s listing and the statement that internal files were taken; everything else remains undisclosed.

Who is rhysida?

Rhysida is a ransomware operation that has been active in public reporting since mid-2023. Like many contemporary groups, it typically follows a double-extortion model: encrypting systems while also copying data and threatening to publish it if payment is not made. The group maintains a leak site where it names organisations and, in some cases, posts sample files or full archives. Public analyses describe rhysida as opportunistic rather than highly targeted, often exploiting known vulnerabilities, weak remote-access credentials, or unpatched systems. Prior listings have included entities across healthcare, education, government, and technology sectors. The group’s claims on its leak site are not independently verified at the moment of posting; they function as pressure tactics. In the present case, the listing of Peraso is therefore recorded as a claim by rhysida that internal files were exfiltrated, not as confirmed fact from the victim or independent investigators.

Peraso and its sector

Peraso is a semiconductor company focused on wireless communications technology, particularly millimetre-wave solutions used in high-speed data links, fixed wireless access, and related applications. Organisations of this type typically hold a mix of proprietary technical designs, employee records, customer and partner contact information, supply-chain data, financial records, and internal communications. Because semiconductor and wireless-technology firms sit at the intersection of commercial intellectual property and critical infrastructure components, a breach can affect not only the company itself but also partners who rely on its products or share sensitive project details. The sector is accustomed to protecting trade secrets and compliance-related data; any unauthorised removal of internal files therefore carries both commercial and personal-data consequences. Public knowledge of Peraso’s business does not, however, reveal what specific systems or repositories may have been involved in this incident.

What data was at risk

The only description provided in the public record is that internal files were allegedly exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of personal identifiers have been released. Organisations in the semiconductor and wireless-technology sector commonly store employee names, contact details, payroll and benefits information, contractor agreements, customer lists, technical specifications, source-code repositories, and correspondence with suppliers. Any of these categories could theoretically be present among “internal files,” yet none can be stated as fact for this incident. The exact contents remain unconfirmed. Readers should therefore treat the exposure as potentially broad while recognising that public detail is limited to the group’s claim of exfiltration.

What's at stake

For individuals, the primary risks are identity-related fraud, targeted phishing that references real internal details, and the long-term circulation of any personal data that may have been included. Even if the bulk of the material is technical or commercial, employee or partner records can still enable social-engineering attacks that appear legitimate. For Peraso the stakes include possible disruption of operations, loss of proprietary information, regulatory scrutiny if personal data of employees or customers is involved, and reputational effects among customers and investors. Because the scale and precise contents are unknown, the full extent of harm cannot yet be measured. The incident also illustrates the wider pattern in which ransomware groups publicise claims to increase pressure, leaving affected parties and the public with incomplete information for extended periods.

If your data was in this claimed breach

If you have a past or present relationship with Peraso—employment, contracting, partnership, or customer status—treat the possibility of exposure seriously until more detail emerges. Monitor financial and email accounts for unusual activity, enable multi-factor authentication wherever available, and be cautious of unsolicited messages that reference company projects or internal names. Change passwords on any accounts that may have been reused or shared in a work context. Consider placing fraud alerts with credit bureaus if you believe personal identifiers could be involved. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; such a check provides one concrete data point while official confirmation remains limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPeraso security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Peraso’s full breach history →

More recent breaches

JASCO Applied Sciences Listed by rhysida Ransomware GroupJuly 21, 2025Collge Superieur De Montreal Listed by rhysida Ransomware GroupNovember 24, 2025St. Joseph's Healthcare Hamilton Listed by rhysida Ransomware GroupNovember 22, 2025Furuno Electric Listed by rhysida Ransomware GroupOctober 13, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Peraso Listed by rhysida Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by rhysida — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram