uniamarmores Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
uniamarmores was listed by the funksec ransomware group on December 07, 2024, after internal files were exfiltrated in a ransomware attack. Anyone connected to the organisation should verify whether their information was exposed and take appropriate protective steps.
When a company that handles business records, contracts and operational data appears on a ransomware group's listing, the people connected to it face a practical problem: their personal or professional information may have been copied and could later be misused. For uniamarmores, a natural-stone firm whose internal files were claimed to have been taken, the stakes are concrete even if the full picture remains incomplete. Customers, suppliers, employees and partners may need to watch for unusual contact, phishing attempts or identity-related fraud until more is known.
Public reporting on 7 December 2024 stated that the ransomware group funksec had listed uniamarmores. The number of people affected is unknown, and the only data type named is internal files said to have been exfiltrated in a ransomware attack. Exact contents, timing of the intrusion and confirmation of the claim have not been independently verified in the available record.
Breaking down the breach
According to the reported information, uniamarmores was listed by the funksec ransomware group on or around 7 December 2024. The listing asserts that internal files were exfiltrated as part of a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the precise date the intrusion began or was discovered. The method of initial access, any encryption of systems, and whether a ransom demand was made or paid remain undisclosed. The available facts describe only the claim of exfiltration of internal files; they do not confirm independent verification of the breach or its full scope. People affected are listed as unknown.
The group behind it: funksec
Funksec is a ransomware operation that became publicly visible in late 2024. Like many contemporary groups, it is associated with double-extortion tactics: encrypting systems while also claiming to steal data and threatening to publish it if a ransom is not paid. The group maintains a leak site where it posts victim names and, in some cases, samples or larger data sets. Public reporting has noted that funksec has marketed itself as using artificial-intelligence tools to assist in code development and operations, though independent technical analysis of those claims varies. The group has listed multiple organisations across different sectors. In this instance, the listing of uniamarmores should be treated as a claim by the group rather than as independently confirmed fact; the facts provided do not state that the victim has verified the intrusion or the data theft.
uniamarmores and its sector
Uniamarmores is a company that specialises in the extraction, processing and distribution of natural stone products, particularly marble. It sources materials, applies finishing technology and supplies residential and commercial projects, including to an international clientele. Firms in this sector typically maintain records of customers and project specifications, supplier and logistics contracts, employee information, financial and invoicing data, and internal operational documents. Because natural-stone businesses often work with architects, builders and property owners, a compromise can touch both commercial relationships and the personal data of individuals who have dealt with the company. A breach at such an organisation is consequential because the data can be used for targeted fraud, competitive intelligence or further social-engineering attacks against partners and clients.
What data was at risk
The facts name only “internal files” as having been exfiltrated in a ransomware attack. No further breakdown—such as whether those files included customer lists, employee records, financial documents, contracts or technical drawings—has been disclosed. Organisations of this type commonly hold contact details, project files, purchase orders, payroll or HR records, and correspondence. Because the exact contents remain unconfirmed, it is not possible to state which specific categories of personal or business information were involved. Readers should treat any more detailed claims circulating online as unverified unless corroborated by the company or by independent investigation.
The real-world impact
For individuals whose details may appear in the taken files, the practical risks include phishing emails that reference real projects or invoices, attempts to reset accounts using known personal information, and, in some cases, identity fraud if government or financial identifiers were present. Suppliers and clients may face business-email compromise attempts that exploit knowledge of ongoing contracts. For the organisation itself, consequences can include operational disruption if systems were encrypted, legal and regulatory obligations to notify affected parties where required by law, reputational harm, and the cost of investigation and remediation. Because the number of people affected is unknown and the precise data types are not detailed, the scale of these risks cannot yet be quantified. The absence of confirmed public notification does not eliminate the possibility that some individuals have already been contacted by fraudsters using information from the alleged leak.
Were you affected?
If you have done business with uniamarmores, worked for the company, or supplied it, treat the listing as a reason for caution rather than proof that your data is already public. Monitor bank and credit accounts for unexpected activity, be sceptical of unsolicited messages that mention marble projects, invoices or deliveries, and enable multi-factor authentication on email and financial accounts. Consider placing a fraud alert with credit bureaux if you believe sensitive identifiers may have been involved. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; such a scan will not prove or disprove involvement in this specific incident, but it can show whether your address has surfaced elsewhere and help you prioritise password changes and monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ibram.org.br Listed by funksec Ransomware Groupshoppingcentropioneer.com Listed by funksec Ransomware Groupasiapacfish.org Listed by funksec Ransomware Groupagti.eng.br Listed by funksec Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the uniamarmores Listed by funksec Ransomware Group →
Publicly posted by funksec — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.