LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Supraterra Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

Supraterra Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 25, 2024
Supraterra Listed by sarcoma Ransomware Group

Reported December 25, 2024.

HIGH
Severity
December 25, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Supraterra was listed by the sarcoma ransomware group on 25 December 2024, after internal files were exfiltrated in an attack whose timing is not established. Individuals connected to the organisation should check whether their data has been exposed and take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 25 December 2024, the ransomware group sarcoma listed Supraterra on its leak site, claiming to have exfiltrated internal files in a ransomware attack. Public detail on the number of people affected remains unknown, yet the reported archive size of 1.1 TB containing files and SQL databases indicates a substantial volume of material may have left the organisation’s control.

For individuals whose personal or financial information could sit inside those systems—clients, partners, employees or contractors—the practical stakes are straightforward: once data is claimed by a ransomware group, it may later appear for sale, reuse or further exposure. Exact contents and confirmation of the claim have not been independently verified in the available record.

Inside the incident

According to the listing, sarcoma claims to have conducted a ransomware attack against Supraterra that resulted in the exfiltration of internal files. The group reported the incident on 25 December 2024 and described a 1.1 TB archive containing files and SQL data. No further public detail has been supplied about the precise date of intrusion, the initial access method, whether encryption was also deployed, or any ransom demand. The number of people whose data may be involved is listed as unknown. The only concrete elements available are the organisation name, the claimed leak size, the file types noted, and the geographic note that Supraterra operates in Mexico.

Who is sarcoma?

Sarcoma is a ransomware group that operates under the double-extortion model common among contemporary ransomware crews: data is stolen before systems are encrypted, and the threat of public release is used to pressure victims. Groups of this type typically maintain dedicated leak sites where they post victim names, sample files and downloadable archives once negotiations stall or deadlines pass. Public reporting on sarcoma has documented its focus on mid-sized and larger organisations across multiple sectors, with listings that often include large archives of internal documents and databases. In this case the group claims Supraterra as a victim; that claim has not been independently confirmed in the provided facts and should be treated as an unverified assertion by the actors themselves.

Who is Supraterra?

Supraterra describes itself as a real-estate development group operating under a “land bank” scheme in Mexico. It develops and conceptualises residential and mixed-use projects and positions itself as a land-reserve provider for other developers. Organisations of this kind routinely hold land-title records, client and investor contact details, financial projections, contractual documents, employee information and project-related databases. A breach at such an entity is consequential because real-estate data often includes sensitive personal identifiers, property ownership details and commercial agreements that can be exploited for fraud, identity theft or competitive intelligence. Public information beyond the organisation’s own description and the sarcoma listing is limited.

What was likely exposed

The facts name the exposed material only as “internal files exfiltrated in a ransomware attack,” with the archive described as containing files and SQL. Exact data types beyond that description are not disclosed. Real-estate development firms typically maintain customer and investor records, land and title documentation, financial ledgers, employee personnel files, email archives and project databases. Whether any of those categories were present in the 1.1 TB archive claimed by sarcoma remains unconfirmed. No specific file names, record counts or sample contents have been released in the available record, so any statement about precise personal or financial data would be speculative.

The real-world impact

If the claimed archive contains personal or financial information, affected individuals face the ordinary risks associated with large-scale data exposure: targeted phishing, identity fraud, unsolicited contact and potential misuse of property or contractual details. For Supraterra the organisational consequences can include regulatory scrutiny, contractual disputes with partners, reputational damage and the operational cost of investigation and remediation. Because the number of people affected is unknown and the exact contents unconfirmed, the scale of personal harm cannot yet be quantified. The listing itself, however, places the organisation under public pressure and may prompt further scrutiny of its security posture.

If your data was in this claimed breach

If you have had dealings with Supraterra—as a client, investor, employee or contractor—treat the possibility of exposure seriously until more detail emerges. Practical first steps include:

Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Public detail on this incident remains limited; further verified information, if it appears, should be used to refine these steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySupraterra security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Supraterra’s full breach history →

More recent breaches

Michelle Accesorios Listed by sarcoma Ransomware GroupDecember 26, 2024Chema Per Listed by sarcoma Ransomware GroupNovember 30, 2024Importadora Monterrey SRL Listed by sarcoma Ransomware GroupJuly 9, 2024Söllner Listed by sarcoma Ransomware GroupNovember 20, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Supraterra Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram