The Getz Group (getz.com.hk) Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Getz Group (getz.com.hk) was listed by the fog ransomware group on October 24, 2024 after internal files were exfiltrated. Individuals should check whether their information was involved and take protective steps if necessary.
On 24 October 2024, The Getz Group, operating at getz.com.hk, appeared on a ransomware leak site operated by the group known as fog. The listing claims that internal files were taken in a ransomware attack and that roughly 45 GB of material was involved. The number of people whose information may have been caught up in the incident remains unknown, and public detail about exactly what was taken is limited. For employees, business partners, customers or others who have dealt with the organisation, the practical stakes are straightforward: personal or commercial data that was held internally could now sit outside the company’s control, raising the usual risks of misuse, fraud attempts or unwanted contact.
What is known so far comes almost entirely from the group’s own claim. No independent confirmation of the full scope has been published, and the organisation has not released a detailed public accounting in the material available for this report. That leaves those potentially affected with incomplete information and the need to take basic protective steps while more facts emerge.
Inside the incident
According to the listing reported on 24 October 2024, fog claims to have carried out a ransomware attack against The Getz Group and to have exfiltrated internal files amounting to 45 GB. The number of people affected is listed as unknown. No further technical detail—such as the initial access method, the precise date the intrusion began, whether encryption was deployed alongside the theft, or any ransom demand—has been disclosed in the available record. The incident is therefore known publicly only through the group’s leak-site claim and the high-level description of “internal files” and a 45 GB volume. Whether the company has verified the claim, contained the intrusion, or notified regulators or individuals is not stated in the facts provided.
Who is fog?
Fog is a ransomware group that has operated in the double-extortion model common among contemporary ransomware actors: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group maintains a leak site on which it posts the names of organisations it claims to have compromised, often accompanied by sample files or volume figures intended to pressure victims. Public reporting on fog has described it as targeting a range of sectors and geographies, typically using standard ransomware tooling and initial-access techniques such as compromised credentials or unpatched services. Its listings are claims made by the group itself; they are not independent confirmations that every detail is accurate or that every listed organisation has suffered the full extent of the asserted breach. In this case, the appearance of The Getz Group on the site is therefore treated as an unverified claim by fog that internal files were exfiltrated.
About The Getz Group (getz.com.hk)
The Getz Group is a commercial organisation whose public-facing presence is the website getz.com.hk. Companies of this type typically operate in distribution, trading or related business services and maintain internal systems that hold employee records, customer or supplier information, contracts, financial data and operational documents. A breach involving internal files at such an organisation is consequential because those files often contain personal data of staff and contacts, commercial terms, and other material that can be used for fraud, competitive intelligence or further social-engineering attacks. Even when the precise contents remain unconfirmed, the mere fact that an organisation of this kind has been listed raises legitimate concern for anyone who has shared personal or business information with it.
What was likely exposed
The facts name the exposed material only as “internal files exfiltrated in ransomware attack,” with a reported volume of 45 GB. No more granular list of data types—such as names, contact details, financial records, health information or credentials—has been disclosed. Organisations similar to The Getz Group commonly hold employee personal data, client and supplier records, invoices, contracts and internal correspondence. It is therefore possible that some combination of those categories was among the taken files, but that remains unconfirmed. Readers should treat any specific claim about particular data elements as speculative until the company or an independent investigation provides further detail.
The real-world impact
For individuals whose data may have been included, the concrete risks include phishing or social-engineering attempts that reference real internal details, identity-fraud efforts if personal identifiers were present, and the longer-term possibility that the material circulates further among other criminal actors. For the organisation itself, the impact can include operational disruption, regulatory notification obligations, contractual liability to partners, and reputational damage. Because the number of people affected is unknown and the exact contents unconfirmed, the scale of these risks cannot yet be quantified. The absence of public confirmation also means that affected parties may not receive timely notice, leaving them to rely on general vigilance and monitoring of their own accounts and credit files.
Were you affected?
If you have worked for, supplied, or done business with The Getz Group, treat the possibility of exposure as real until more information appears. Change passwords on any accounts that reused credentials shared with the company, enable multi-factor authentication wherever available, and watch for unexpected messages that appear to come from the organisation or its partners. Monitor financial accounts and credit reports for unusual activity. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Keep records of any suspicious contact and report confirmed fraud to the relevant authorities. Further official statements from the company, if issued, should be reviewed carefully for concrete guidance on next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Ouro Verde (ouroverde.net.br) Listed by fog Ransomware GroupOmniRide (omniride.com) Listed by fog Ransomware GroupMetroline (metrolinedirect.com) Listed by fog Ransomware GroupWaters Truck and Tractor (waterstruck.com) Listed by fog Ransomware GroupLatest breaches
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.