www.humac.dk Listed by kraken Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On 2 April 2025, the ransomware group Kraken listed Danish retailer www.humac.dk, claiming to have exfiltrated internal files in a recent attack. An undisclosed number of people may be affected; individuals are advised to check their accounts and monitor for unusual activity.
On April 2, 2025, the Danish Apple reseller www.humac.dk appeared on a leak site operated by the ransomware group known as kraken. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further technical details about the intrusion have not been disclosed.
The listing itself is a claim by the group. What is confirmed so far is limited: the organisation was named, the date of the report is recorded, and the description of the material points to internal files taken during a ransomware incident. For customers, staff and partners of a long-established Apple dealer, even this level of disclosure raises practical questions about what may now be circulating.
Inside the incident
According to the available record, www.humac.dk was listed by the kraken ransomware group on April 2, 2025. The report characterises the event as a ransomware attack in which internal files were allegedly exfiltrated. No public figure has been given for the volume of data, the precise date of the intrusion, the entry method, or the number of individuals whose information may be involved. Those elements remain undisclosed.
Ransomware incidents of this type typically involve encryption of systems combined with theft of data before the encryption stage, after which the operators threaten to publish the material. In this case the public record stops at the leak-site listing and the statement that internal files were taken. No independent confirmation of the full scope or of any subsequent publication has been supplied in the facts at hand.
The group behind it: kraken
Kraken is a ransomware operation that maintains a public leak site on which it names organisations it claims to have compromised. Like other groups in this category, it typically follows a double-extortion model: systems are encrypted and data is copied, after which the operators demand payment and threaten to release the stolen material if the demand is not met. Listings on such sites are claims made by the group; they are not independent verification that every file described has been published or that every assertion is accurate.
Public reporting on kraken over time has associated the name with attacks on commercial and mid-sized organisations across several countries. The group’s communications and site postings generally emphasise the volume or sensitivity of the data it says it holds, while offering little technical transparency that outsiders can immediately verify. In the present case the only specific claim recorded is that www.humac.dk was listed and that internal files were exfiltrated. No further statements attributed to kraken about this particular victim appear in the available facts.
Who is www.humac.dk?
Humac was established in 1989 and has sold and serviced Apple products in Denmark ever since. Its own description frames the business as bringing “the HUman and MAC’s together.” As an authorised Apple reseller and service provider, the company operates retail and support channels that handle product sales, repairs, warranties and customer accounts.
Organisations of this kind routinely process customer contact details, purchase and service histories, payment-related records, staff information and internal operational documents. A breach at such a firm is consequential because the data it holds is both commercially sensitive and personally identifiable, and because customers often reuse the same contact details across other services. The company’s long market presence means a large cumulative customer base may be affected even if the exact numbers remain unknown.
What was likely exposed
The facts state that internal files were exfiltrated in the ransomware attack. No further breakdown of file types, databases or categories of personal data has been provided. Exact contents are therefore unconfirmed.
Companies that sell and service consumer electronics typically retain customer names, addresses, email addresses, phone numbers, order and repair records, warranty information and, in some cases, limited payment or identity documents required for financing or returns. Employee records, supplier contracts, internal correspondence and system configuration files are also common. Whether any of these categories were among the internal files taken in this incident cannot be established from the public record; the only confirmed description is “internal files.”
Why it matters
For individuals, the practical risk is that contact details, purchase histories or other personal information could be used for targeted phishing, social-engineering calls or identity-related fraud. Even incomplete records can be combined with data from other sources to increase credibility of scams. For the organisation, the incident creates operational disruption, potential regulatory notification duties under European data-protection rules, and reputational pressure while the full extent of the exfiltration remains unclear.
Because the number of people affected is unknown and the precise data types beyond “internal files” are undisclosed, the scale of individual exposure cannot yet be quantified. That uncertainty itself is a source of concern for anyone who has done business with the firm.
If your data was in this claimed breach
If you have been a customer, employee or partner of Humac, treat any unexpected messages that reference recent purchases, repairs or account details with caution. Prefer official channels listed on the company’s own website when verifying communications. Consider changing passwords on accounts that used the same email address you supplied to Humac, and enable multi-factor authentication where available. Monitor financial statements for unfamiliar activity.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such checks do not confirm or rule out involvement in this specific incident, but they provide a practical starting point for assessing wider exposure.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
www.optyma.co.uk Listed by kraken Ransomware Groupwww.floralimited.com Listed by kraken Ransomware Groupwww.prival.com Listed by kraken Ransomware Groupwww.selt-sistemi.com Listed by kraken Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the www.humac.dk Listed by kraken Ransomware Group →
Publicly posted by kraken — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.