LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › PIBOR ISO SA Listed by akira Ransomware Group

HIGH severityUnverified claimHow we verify

PIBOR ISO SA Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 17, 2025
PIBOR ISO SA Listed by akira Ransomware Group

Reported March 17, 2025.

HIGH
Severity
March 17, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

PIBOR ISO SA was listed by the Akira ransomware group on March 17, 2025, after internal files were exfiltrated in a ransomware attack; the exact date of the intrusion has not been established. Individuals who may have had dealings with the company should check for any follow-up notices and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 17 March 2025, the Swiss precision-engineering firm PIBOR ISO SA appeared on a leak site operated by the ransomware group known as akira. Public reporting so far confirms only that the group claims to have exfiltrated internal files during a ransomware attack; the number of people affected remains unknown, and independent verification of the intrusion has not been published.

The listing matters because PIBOR ISO SA supplies components to the high-precision watch industry. Any confirmed compromise of its corporate systems could expose business partners, employees and customers to secondary fraud or competitive harm, even while the full scope of the incident stays unconfirmed.

Breaking down the breach

According to the available record, PIBOR ISO SA was listed by akira on 17 March 2025. The group states that internal files were taken as part of a ransomware attack. No public timeline of the intrusion, no confirmed method of initial access, and no independent count of systems or records involved have been released. The sole concrete claim attached to the listing is that the attackers are prepared to publish more than 32 GB of material they describe as essential corporate documents. Whether that volume exists, whether it has been released, and whether the company has paid or negotiated remain undisclosed.

Who is akira?

Akira is a ransomware operation that emerged in early 2023 and has since targeted organisations across manufacturing, professional services and other sectors. Public technical reporting characterises the group as using double-extortion tactics: encrypting systems while simultaneously copying data for later publication or sale if a ransom is not paid. The group typically posts victim names and sample file lists on a dedicated leak site, then escalates pressure by threatening full dumps. Its operators have been observed using common initial-access vectors such as compromised credentials and unpatched remote-access services, though the precise vector used against any single victim is rarely confirmed in open sources. Claims made on the leak site about a particular organisation, including the volume or sensitivity of stolen data, remain unverified assertions until corroborated by the victim or by independent forensic analysis.

About PIBOR ISO SA

PIBOR ISO SA is a Swiss company active in the design and manufacture of precision watch components. Public descriptions of the firm note that it covers more than fifty specialised trades within that niche and positions itself among the established suppliers to the luxury and technical watchmaking sector. Organisations of this type routinely hold engineering drawings, production schedules, supplier and customer contracts, financial records and contact details for staff and business partners. A breach at such a firm is consequential because the watch-component supply chain is tightly interconnected; disruption or data exposure can affect not only the company itself but also downstream brands that rely on its parts and on the confidentiality of shared technical and commercial information.

The information in question

The facts supplied name the exposed material only as “internal files exfiltrated in a ransomware attack.” The group’s own listing elaborates that it claims to hold more than 32 GB of documents, including financial data such as audits, payment details and reports; contact numbers and e-mail addresses of employees and customers; internal corporate correspondence; and corporate licences, agreements and contracts. These categories are presented solely as the group’s assertion. No independent inventory has been published, so the exact contents, the presence or absence of personal data, and the completeness of any archive remain unconfirmed. Companies in precision manufacturing typically store engineering files, quality records and commercial contracts; whether any of those specific classes appear in the claimed dump cannot be verified from the public record.

The real-world impact

For individuals whose contact details or correspondence may have been taken, the principal risks are targeted phishing, social-engineering attempts that reference genuine business relationships, and possible identity-related fraud if personal identifiers were present. For the organisation, the risks include competitive disadvantage if technical or commercial documents surface, contractual disputes with partners, and the operational cost of containment, notification and recovery. Because the number of affected people is unknown and the precise data set is unconfirmed, the scale of these risks cannot yet be quantified. Secondary effects—such as supply-chain partners reviewing their own exposure—may still arise even if the full dump is never released.

If your data was in this claimed breach

If you have done business with, or worked for, PIBOR ISO SA, treat the possibility of exposure as real until proven otherwise. Practical first steps include:

Public detail remains limited; further clarity will depend on any official statement from the company or on independent analysis of material that may eventually be published.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPIBOR ISO SA security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See PIBOR ISO SA’s full breach history →

More recent breaches

FELA (EVYTRA) Listed by akira Ransomware GroupNovember 20, 2025Vardeco Listed by akira Ransomware GroupAugust 13, 2025J. SCHNEEBERGER Maschinen AG Listed by akira Ransomware GroupApril 25, 2025Bauer-Walser AG Listed by akira Ransomware GroupApril 8, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the PIBOR ISO SA Listed by akira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by akira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram