LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Tlantic Listed by mallox Ransomware Group

HIGH severityUnverified claimHow we verify

Tlantic Listed by mallox Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 24, 2023
Tlantic Listed by mallox Ransomware Group

Reported June 24, 2023.

HIGH
Severity
June 24, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Tlantic Listed by mallox Ransomware Group (reported June 24, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Account credentials exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On or around June 24, 2023, the organisation Tlantic was listed by the mallox ransomware group, which claimed to have carried out a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and public detail on the incident is limited to the group's listing and the reported characterisation of the data as internal files. For anyone connected to Tlantic as an employee, partner, or customer, the listing raises ordinary questions about whether personal or business information was among what the attackers say they took.

Ransomware groups commonly publish victim names on leak sites to pressure payment. A listing is a claim, not independent confirmation of every detail. What is known so far is the reported date, the attribution to mallox, and the description of internal files as the material involved.

What happened

According to available reporting, Tlantic was listed by the mallox ransomware group on June 24, 2023. The incident is described as a ransomware attack in which internal files were allegedly exfiltrated. No public figure has been given for the number of people affected, and specifics such as the precise method of initial access, the full scope of systems involved, or any ransom demand are not disclosed in the material at hand.

The group's listing presented the matter as a completed intrusion with data removal. Independent verification of the full contents, volume, or subsequent distribution of any files is not part of the public record summarised here. Timing beyond the reported listing date, and any confirmation from Tlantic itself, are likewise undisclosed in the facts provided.

The group behind it: mallox

Mallox is a known ransomware operation that has appeared in public reporting for several years. Like many contemporary ransomware actors, it has been associated with double-extortion tactics: encrypting systems while also copying data and threatening to publish or sell it if a payment is not made. The group has typically targeted organisations rather than individuals, often through compromised credentials, exposed remote services, or other common enterprise entry points, though the exact vector in any single case varies and is frequently not confirmed publicly.

Mallox has maintained leak sites or similar channels where it names victims and, in some cases, posts samples or archives. Listings are claims made by the group. In this instance, mallox claimed Tlantic as a victim and associated the listing with exfiltrated internal files. No further statements attributed to mallox about this specific victim—beyond the fact of the listing and the internal-files description—are included in the available facts. Prior activity by the group against other organisations is documented in open sources; those earlier cases do not, by themselves, prove the details of the Tlantic matter.

About Tlantic

Tlantic is a commercial organisation. Public business directories commonly place companies of this name in technology or retail-solutions contexts, where firms typically handle operational systems, partner records, and internal business documents. Exact corporate structure, size, and geographic footprint are not detailed in the breach facts themselves.

A breach involving an organisation in this kind of sector matters because such entities often sit between suppliers, retailers, and internal staff. Even when the only confirmed description is “internal files,” those files can include material that affects employees, contractors, or counterparties. The consequence is not automatically catastrophic, but it is material enough that people with a relationship to the organisation have reason to pay attention until clearer inventories emerge.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether the files included human-resources records, customer lists, financial documents, credentials, or technical schematics—is provided. The number of people affected is unknown.

Organisations of this type commonly hold employee contact and payroll-related data, commercial contracts, operational documents, and system-related information. That is typical, not confirmed for this incident. Because the exact contents remain unconfirmed beyond the “internal files” label, no specific category should be treated as established fact. Readers should assume uncertainty rather than a complete public inventory.

What's at stake

For individuals, the practical risks depend on what was actually in the taken files. If personal data were present, possible outcomes include unwanted contact, phishing that references real internal details, or attempts to reuse passwords or identity information. If only non-personal business documents were involved, the direct risk to private individuals may be lower, while commercial confidentiality and partner trust could still be affected. None of these outcomes is confirmed; they are the ordinary range of concerns when internal files are claimed stolen.

For Tlantic, the stakes include operational disruption from the ransomware event itself, potential regulatory or contractual notification duties depending on jurisdiction and data types, and reputational questions from customers and partners. The absence of a public count of affected people and of a detailed data inventory makes it harder for outsiders to gauge scale. That uncertainty is itself part of the impact until more authoritative information appears.

Were you affected?

If you work with or for Tlantic, or have shared personal or account information with the organisation, treat the listing as a reason for basic caution. Monitor accounts for unusual activity, be wary of unexpected messages that reference internal projects or colleagues, and consider changing passwords that may have been reused across work and personal services. Official notices from Tlantic, if any are issued, should take priority over third-party claims.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or rule out involvement in this specific incident, but it is a practical way to see whether your address appears in broadly circulated breach collections and to decide on further hardening of your accounts.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyTlantic security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Tlantic’s full breach history →

More recent breaches

DUHOCAAU Listed by mallox Ransomware GroupOctober 14, 2023Kogetsu Listed by mallox Ransomware GroupAugust 1, 2023JBCC Corp Listed by mallox Ransomware GroupJune 28, 2023Share and Harris Listed by mallox Ransomware GroupJune 3, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Tlantic Listed by mallox Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by mallox — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram