LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Sama Listed by killsec Ransomware Group

HIGH severityUnverified claimHow we verify

Sama Listed by killsec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 26, 2025
Sama Listed by killsec Ransomware Group

Reported May 26, 2025.

HIGH
Severity
May 26, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Sama has been listed by the killsec ransomware group, with internal files reported to have been exfiltrated in an attack. The incident came to light on May 26, 2025; an undisclosed number of people may be affected, so check the company’s notices and consider changing passwords or enabling multi-factor authentication.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On May 26, 2025, the organisation Sama appeared on the leak site operated by the ransomware group killsec. The group claims to have stolen internal data in a ransomware attack. Public detail remains limited: the number of people affected is unknown, and no further confirmation of the incident has been independently verified beyond the listing itself.

For anyone connected to Sama as an employee, contractor, client or partner, the listing raises immediate questions about what may have been taken and whether personal or operational information is now at risk of wider exposure.

What happened

Sama was listed on the killsec ransomware leak site on or around May 26, 2025. According to the reported summary, the group claims to have exfiltrated internal files during a ransomware attack. No public statement from Sama confirming or denying the claim has been included in available records. The scale of any intrusion, the precise method used, the date the attack began, and whether any ransom demand was made or paid all remain undisclosed. The only concrete assertion is the leak-site listing itself and the group’s claim that internal data was stolen.

Inside killsec

Killsec is a ransomware operation that has been active in recent years and follows the now-common double-extortion model. After encrypting systems, the group typically claims to have copied data beforehand and threatens to publish it on a dedicated leak site if payment is not received. Listings on such sites are public claims made by the attackers; they do not by themselves prove that every file advertised was actually taken or that the victim has verified the breach. Killsec has previously targeted organisations across multiple sectors, using the same pattern of encryption plus data-theft threats. In this case the group’s listing of Sama should be treated as an unverified claim until independent confirmation appears.

Who is Sama?

Sama is a company that provides data-annotation and AI-training services, helping technology firms prepare large volumes of labelled data for machine-learning models. Organisations of this type routinely handle proprietary client datasets, internal project files, employee records, and contractual information. Because the work often involves sensitive or commercially valuable material, a breach at such a firm can affect not only its own staff but also the clients whose data it processes. The listing therefore carries potential consequences beyond a single corporate network.

The information in question

The only data type named in available records is “internal files” said to have been exfiltrated in the ransomware attack. Exact contents have not been disclosed. Companies performing data-annotation work typically store project files, source datasets supplied by clients, internal documentation, employee contact details, and operational records. Whether any of those categories were among the files killsec claims to hold remains unconfirmed. Public detail on the precise nature and volume of the material is limited.

The real-world impact

If internal files were indeed taken, the practical risks include possible exposure of employee personal information, client project details, or proprietary business documents. Affected individuals could face phishing attempts that reference genuine internal knowledge, or identity-related fraud if contact or identity data were present. For the organisation itself, the consequences may include operational disruption, contractual obligations to notify clients, and the longer-term task of verifying what left its systems. Because the number of people affected is unknown and the exact files remain unspecified, the full scope of harm cannot yet be measured. The listing alone is enough to warrant caution among anyone whose data Sama may have held.

Were you affected?

If you have worked with, for, or as a client of Sama, treat the claim seriously until more information emerges. Practical first steps include:

Further official statements from Sama or independent verification of the killsec claim would provide clearer guidance. Until then, the prudent course is to assume that internal material may have been copied and to act accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySama security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Sama’s full breach history →

More recent breaches

playroll Listed by killsec Ransomware GroupDecember 9, 2025caryanams Listed by killsec Ransomware GroupDecember 9, 2025KillSec 4.0 Listed by killsec Ransomware GroupOctober 4, 2025Fractalite Listed by killsec Ransomware GroupSeptember 22, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Sama Listed by killsec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by killsec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram