LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › RISE Racing Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

RISE Racing Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 4, 2025
RISE Racing Listed by sarcoma Ransomware Group

Reported June 4, 2025.

HIGH
Severity
June 4, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

RISE Racing was listed by the sarcoma ransomware group on June 04, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; check your records and take appropriate steps if you have any connection to the organisation.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target specialised industry platforms that sit at the centre of regulated sectors, using data theft and public leak-site listings as leverage. Against that backdrop, RISE Racing, the data and systems provider for Australia’s harness racing industry, was listed by the sarcoma ransomware group on 4 June 2025. Public reporting states that internal files were exfiltrated in a ransomware attack and that a 1.6 GB archive of files was claimed on the group’s leak site. The number of people affected remains unknown, and many operational details have not been disclosed.

Because RISE Racing supports racing authorities, clubs, owners, breeders, trainers, drivers and enthusiasts, any compromise of its systems raises practical questions about the confidentiality of industry and personal information. The listing itself is a claim by the threat actor; independent confirmation of the full scope has not been published in the available record.

Inside the incident

According to the reported facts, RISE Racing was listed by the sarcoma ransomware group on 4 June 2025. The organisation is described as having suffered a ransomware attack in which internal files were allegedly exfiltrated. The leak-site entry associated with the claim references a 1.6 GB archive containing files and places the organisation in Australia. No public figure has been given for the number of individuals affected, and the precise method of initial access, the timeline of encryption or exfiltration, and any ransom demand details are undisclosed in the available information.

What is known is limited to the listing itself, the characterisation of the data as internal files taken in a ransomware incident, and the stated archive size. Whether the archive was fully released, partially released, or merely advertised remains unconfirmed beyond the group’s claim. Organisations facing such listings typically investigate containment, assess what was taken, and communicate with stakeholders; those steps, if taken, have not been detailed in the public facts provided here.

Inside sarcoma

Sarcoma is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion style attacks: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if demands are not met. Like other actors in this category, it typically advertises victims with brief descriptions, claimed data volumes, and sample file listings to increase pressure. Public knowledge of the group centres on this operational pattern rather than on any unique technical signature that has been universally confirmed across every incident.

In this case, the group’s leak-site listing of RISE Racing should be treated as an unverified claim unless and until the victim or independent investigators state the details. The facts state that internal files were exfiltrated and that a 1.6 GB archive of files was associated with the listing; they do not include further statements attributed to sarcoma about this specific victim beyond that claim. No additional quotes, ransom figures, or exclusive technical claims about RISE Racing appear in the provided record.

About RISE Racing

RISE Racing describes itself as the data and systems provider for the Australian harness racing industry. Its stated charter is to drive and deliver digital innovation for racing authorities, race clubs, owners, breeders, trainers, drivers and racing enthusiasts. In practical terms, organisations in this role commonly operate platforms that handle race administration, participant records, ownership and breeding data, club operations, and related digital services that keep the industry running day to day.

A breach involving such a provider is consequential because the organisation sits at a junction of industry and personal information. Racing authorities and clubs rely on centralised systems for integrity, scheduling and compliance; owners, breeders, trainers and drivers may have accounts, contact details, financial or licensing information, and other records tied to their participation. Even when the exact contents of a stolen archive are not fully catalogued in public reporting, the sector context makes clear why stakeholders take the incident seriously.

What was likely exposed

The facts name the exposed material as internal files exfiltrated in a ransomware attack, associated with a claimed 1.6 GB archive of files. No further breakdown of file types, databases, or specific categories of personal or commercial data has been disclosed in the available record. The number of people affected is unknown.

Organisations that provide data and systems services to a national racing industry typically hold a mix of operational documents, system configuration or backup material, participant and stakeholder records, and correspondence or administrative files. Those categories are common across similar providers; they are not confirmed as present in this particular archive. Exact contents remain unconfirmed beyond the description “internal files” and “files” in a 1.6 GB archive. Readers should treat any more granular claims as unproven unless verified by the organisation or a competent authority.

Why it matters

For individuals connected to Australian harness racing—owners, breeders, trainers, drivers, club staff or enthusiasts—the practical risk is that contact details, account identifiers, licensing or ownership information, or other records that may have been stored in internal systems could be misused for phishing, social engineering, or identity-related fraud. Even without a published headcount, the industry-wide role of the provider means a wide circle of people could theoretically be touched if personal data was among the files taken.

For RISE Racing and the authorities and clubs that depend on it, the incident raises continuity, trust and regulatory considerations. Restoring systems, determining what left the environment, and communicating accurately with stakeholders are resource-intensive. A public listing by a ransomware group can also create reputational pressure and secondary risk if stolen material is later used in further attacks against the same ecosystem. None of this establishes negligence as a proven fact; it simply describes the ordinary consequences that follow when a central industry platform is claimed as a ransomware victim.

Were you affected?

If you have an account, membership, ownership, training or other formal relationship with Australian harness racing services that rely on RISE Racing systems, treat the incident as a prompt to review your exposure. Change passwords on related accounts, enable multi-factor authentication where available, and be alert to unexpected emails or messages that reference racing, ownership, payments or account recovery—common vectors after industry breaches. Monitor financial and identity accounts for unusual activity and consider placing fraud alerts if you believe sensitive personal data may have been involved.

Public detail on exactly who was affected remains limited. You can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, and you should rely on any official notices issued by RISE Racing or Australian racing authorities for the most accurate guidance specific to this incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyRISE Racing security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See RISE Racing’s full breach history →

More recent breaches

MACMA Werbeartikel oHG Listed by sarcoma Ransomware GroupSeptember 25, 2025Miami Management Listed by sarcoma Ransomware GroupSeptember 22, 2025Kwg Listed by sarcoma Ransomware GroupSeptember 17, 2025Milberg Listed by sarcoma Ransomware GroupJuly 8, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the RISE Racing Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram