Studio Eco Perucca Listed by malas Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Studio Eco Perucca Listed by malas Ransomware Group (reported April 9, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
For clients, partners and staff connected to Studio Eco Perucca, the appearance of the firm’s name on a ransomware group’s leak site raises immediate practical questions: whether internal files containing personal or business information were taken, and what that could mean for privacy, contracts or day-to-day operations. Public detail remains limited, yet the listing itself is enough to warrant careful attention from anyone who has shared data with the organisation.
On 9 April 2023 the firm was reported as listed by the group known as malas. The available account states that internal files were exfiltrated in a ransomware attack that exploited a Zimbra vulnerability. The number of people affected is unknown, and no fuller inventory of the material has been published. What follows sets out only what has been reported, places it in context, and outlines sensible next steps.
What happened
According to the reported summary, Studio Eco Perucca was the subject of a ransomware attack in which internal files were exfiltrated. The method cited is exploitation of a Zimbra vulnerability. Zimbra is a widely used collaboration and email platform; when unpatched instances are exposed, attackers have historically used known flaws to gain initial access, move laterally and remove data before or while deploying ransomware. The listing by malas was reported on 9 April 2023. No public confirmation of the precise date of intrusion, the volume of data removed, or any ransom demand has been supplied in the available facts. The number of individuals whose information may be involved remains unknown. The group’s appearance of the victim’s name on its leak site constitutes a claim that data was taken; independent verification of the full contents has not been provided in the material at hand.
Who is malas?
Malas is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion attacks: encrypting systems while also copying data and threatening to publish it if payment is not made. Like many such actors, it typically advertises victims on a dedicated leak site, sometimes releasing sample files to pressure the organisation. Public documentation of the group describes the use of opportunistic initial-access methods, including exploitation of known software vulnerabilities, rather than highly customised zero-day campaigns in every case. Prior activity attributed to malas in open sources follows the familiar pattern of naming organisations across varied sectors and claiming exfiltration of internal documents. With respect to Studio Eco Perucca specifically, the only claim on record is the listing itself and the accompanying statement that internal files were taken via a Zimbra vulnerability; no further statements by the group about this victim are included in the facts.
About Studio Eco Perucca
Studio Eco Perucca is a professional practice whose name and positioning indicate work in the environmental, ecological or related consulting and design fields. Organisations of this type commonly handle project documentation, client correspondence, technical reports, contracts, and administrative records. They may also retain contact details, financial information and, in some cases, personal data belonging to employees, freelancers or private clients. Because such firms sit at the intersection of technical expertise and client relationships, a breach can affect both commercial confidentiality and the privacy of individuals who have dealt with the studio. The consequential nature of an incident here stems less from headline scale—which remains undisclosed—and more from the ordinary sensitivity of the records a practice of this kind must keep in order to operate.
What was likely exposed
The facts state that internal files were exfiltrated in the ransomware attack. No further breakdown of file types, record counts or specific data categories has been disclosed. In the absence of a confirmed inventory it is not possible to assert exactly what was taken. Organisations comparable to Studio Eco Perucca typically hold email archives, project files, contracts, invoices, staff records and client contact information. Any of these could, in principle, have been among the internal material removed; equally, the actual set could be narrower or differently composed. Readers should treat the precise contents as unconfirmed and avoid assuming that any particular category of personal data was or was not included.
Why it matters
When internal files leave an organisation without authorisation, the people named or described in those files face concrete risks: unwanted contact, phishing that references real projects or relationships, and, in some cases, identity-related misuse if identifiers or financial details were present. For the firm itself the consequences include potential regulatory notification duties, contractual obligations to clients, and the operational cost of investigation and remediation. Because the number of affected individuals is unknown and the exact data types remain undisclosed, the prudent stance is to assume that anyone who has corresponded with or supplied information to Studio Eco Perucca could be touched, while recognising that many may not be. The incident also illustrates a broader pattern: collaboration platforms such as Zimbra, when left unpatched, have repeatedly served as entry points for ransomware groups seeking both encryption leverage and exfiltrated data.
If your data was in this claimed breach
If you have reason to believe your information may have been held by Studio Eco Perucca, begin by treating unsolicited messages that reference the firm or its projects with caution; verify any request for personal or financial details through a separate, known channel. Monitor financial and email accounts for unusual activity and consider updating passwords on services that shared credentials or recovery addresses with the studio. Retain any official notification you receive from the organisation, as it may contain specific guidance. Finally, you can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets; such a check is a practical early step while fuller details of this incident remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Gallagher & Co Consultants Listed by malas Ransomware GroupAxon Certified Auditors Listed by malas Ransomware GroupNTD SA Listed by malas Ransomware GroupBenarIT Listed by malas Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Studio Eco Perucca Listed by malas Ransomware Group →
Publicly posted by malas — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.