Ransomware victim disclosure
← All victimsMacphie Ltd
listed as macphie.com · Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedApr 19, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United Kingdom
- Listed on leak site
- Apr 19, 2024
About the victim
AI dossier — public-source company profileMacphie Ltd is an internationally renowned family-owned food ingredient manufacturer based in Scotland. They produce cake mixes, savoury sauces, and other food ingredients supplied to major food brands. The company operates in the foodservice and bakery solutions sector.
- Industry
- Food Ingredients & Bakery Solutions Manufacturing
- Address
- Glenbervie, Stonehaven AB39 3YG, Scotland
Attack summary
Severity: high — Confirmed exfiltration of significant business data (600 GB) including financial, HR, and accounts information from a mid-to-large manufacturing company. The exposure of financial and HR data represents material business sensitivity, though no regulated PII (medical, government) is explicitly mentioned.BlackBasta claims to have exfiltrated approximately 600 GB of data including accounts, financial records, HR information, and personal user folders from Macphie Ltd.
Data the group says was taken
AI dossier — extracted from the leak post- Accounts data
- Financial records
- HR information
- Personal user folders
What the group claims
Macphie An internationally renowned family owned food ingredient manufacturer. From cake mixes to savoury sauces and everything in between, we work with a range of food brands who create amazing dishes based on our products.SITE: www.macphie.com Address : Glenbervie, Stonehaven AB39 3YG ScotlandALL DATA SIZE: ~600gb 1. Accounts data 2. Fincancial data 3. HR 4. Personal users folders & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

