RADIX Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
RADIX was listed by the sarcoma ransomware group on June 16, 2025, after internal files were exfiltrated in a ransomware attack affecting an undisclosed number of individuals. Anyone connected to RADIX should verify whether their information was involved and follow any guidance the organisation issues.
People connected to Swiss health-promotion work may now face uncertainty over whether internal records linked to their organisations or communities have been taken. On 16 June 2025 the ransomware group sarcoma listed RADIX on its leak site, claiming to have exfiltrated internal files. The number of individuals affected remains unknown, and public detail about the precise contents is limited, yet any exposure of material held by a health-education foundation carries practical consequences for privacy and trust.
Because RADIX works with municipal and cantonal authorities as well as organisational decision-makers, the incident raises questions for anyone whose professional or personal data might have been stored in those internal systems. Until more is confirmed, the prudent course is to treat the listing as an unverified claim and to take basic protective steps.
Inside the incident
Public reporting states that RADIX was listed by the sarcoma ransomware group on 16 June 2025. The group claims that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the duration of unauthorised presence, the volume of data taken, or any ransom demand—have been disclosed in the available record. The number of people affected is listed as unknown. Confirmation that the listing corresponds to a successful intrusion has not been independently verified in the facts provided; the leak-site entry itself remains a claim by the group.
Inside sarcoma
Sarcoma is a ransomware operation that has appeared in public reporting since roughly 2023–2024. Like many contemporary groups, it typically employs a double-extortion model: encrypting systems while also copying data and threatening to publish it if payment is not made. Victims are commonly listed on a dedicated leak site, often accompanied by sample files or countdown timers. The group has been observed targeting organisations across multiple sectors and geographies rather than specialising in a single industry. Public knowledge of its tooling and infrastructure is still developing; operators frequently rebrand or share affiliates, which can make attribution fluid. In the present case the only specific assertion about RADIX is the leak-site listing itself; no additional statements by the group about this victim are recorded in the facts.
RADIX and its sector
RADIX is a Swiss non-profit foundation operating under private law. It traces its origins to 1972, when the Swiss Foundation for Health Education was established; that body merged in 1992 with the RADIX Community Health Promotion Association. Its stated purpose is to encourage municipal and cantonal authorities, as well as decision-makers in other organisations, to treat health promotion as a continuous responsibility and to put concrete measures in place. Strategic oversight rests with a Foundation Board that appoints an Executive Board responsible for day-to-day operations. The organisation is based in Switzerland.
Entities of this kind routinely hold internal administrative records, correspondence with public bodies, programme documentation, and sometimes contact or participation data related to health-promotion initiatives. A breach affecting such material can therefore touch both the foundation’s own staff and the wider network of partners and communities it serves. Because health-related work often involves sensitive personal or organisational information, any compromise carries elevated stakes for confidentiality and institutional credibility.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as employee records, partner contact lists, financial documents, or programme participant data—has been publicly named. Organisations engaged in health education and community promotion typically maintain correspondence, project files, internal policies, and databases of contacts among authorities and partner groups. Whether any of those categories were among the files claimed by sarcoma remains unconfirmed. Readers should therefore treat the precise contents as undisclosed rather than assume specific data types may have been exposed.
Why it matters
For individuals whose information may have been stored in RADIX systems, the primary risks are misuse of personal or professional contact details, targeted phishing that leverages knowledge of health-promotion work, and longer-term identity or reputational harm if sensitive correspondence surfaces. For the foundation itself, the incident can disrupt operations, strain relationships with municipal and cantonal partners, and require costly recovery and notification efforts. Even when the scale is unknown, the mere claim of exfiltration can erode confidence among the authorities and organisations RADIX seeks to influence. Because the number of affected people is unreported, the full human and institutional impact cannot yet be quantified.
If your data was in this claimed breach
If you have had dealings with RADIX or its partner networks, begin by monitoring accounts for unusual activity and enabling multi-factor authentication wherever possible. Be alert to phishing messages that reference health-promotion programmes or Swiss public-health topics. Consider placing fraud alerts with credit agencies if financial identifiers could have been involved, though no such data types have been confirmed. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; that step provides an early indication of wider exposure without cost. Official notifications, if any are issued by RADIX or Swiss authorities, should be followed carefully once they become available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
B&J Rocket Sales Listed by sarcoma Ransomware GroupUnimed do Brasil Listed by sarcoma Ransomware GroupF1-Generation Listed by sarcoma Ransomware GroupSanderling Healthcare Listed by sarcoma Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the RADIX Listed by sarcoma Ransomware Group →
Publicly posted by sarcoma — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.