Ransomware victim disclosure
← All victimsGYF
Claimed by Sarcoma · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileGYF is an Argentina-based company that designs and develops IT products and services for the financial market. No further details about its scale or operations are available from public sources. The company appears to serve financial sector clients with technology solutions.
- Industry
- Financial Technology (FinTech) IT Products & Services
Attack summary
Severity: critical — 1.5 TB of SQL database content exfiltrated and published from a company operating in the financial market sector strongly implies large-scale exposure of regulated financial data, potentially including customer PII, transactional records, and sensitive financial information.The Sarcoma ransomware group claims to have exfiltrated approximately 1.5 TB of data from GYF, with the disclosure status marked as data_published. The leaked data reportedly contains SQL database files.
Data the group says was taken
AI dossier — extracted from the leak post- SQL databases
What the group claims
Design and develop IT products and services for the financial marketGeo: Argentina - Leak size: 1.5Tb - Contains: SQL
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

