On March 25, 2025, the Akira ransomware group listed AAYLEX ONE S.A. on its leak site and began publishing more than 19 GB of the company’s internal files. The documents include corporate licenses, agreements, contracts, NDAs, employee and customer contact numbers and email addresses, and employees’ medical documents. Anyone whose personal details appear in those files — employees, their family members, or customers — now faces heightened risk of identity theft, phishing, and doxxing.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Aaylex One S.A.
Get alerted the next time Aaylex One S.A. files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Aaylex One S.A.’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates the incident is a classic ransomware attack in which the threat actors gained access, exfiltrated data, and then encrypted systems. The Akira leak page, tracked by ransomware.live, shows the group gave AAYLEX ONE S.A. — a poultry producer operating under the Cocorico brand — a short window to negotiate before public release of the archive. Available reporting describes the exposed material as sensitive corporate records mixed with personal employee and customer information. Exact number of individuals affected remains unknown, but the volume and variety of records suggest thousands of records containing names, phone numbers, email addresses, and medical details may now be circulating among criminal networks.
Why This Matters for You and Your Family
When a company you work for or do business with loses control of your contact details and medical records, the fallout lands directly on your doorstep. Employee medical documents combined with email addresses and phone numbers give attackers the raw material for convincing phishing campaigns, insurance fraud, or blackmail attempts. Your family can be pulled in through shared addresses, children’s school records, or simply because the same phone number appears on a spouse’s or teenager’s account. Once your information is loose, it rarely stays contained to one incident.
The Doxxing and Identity-Chain Risks
Credential leaks like this one rarely stop at the initial breach. Attackers chain exposed email addresses and phone numbers to usernames on social media, gaming platforms, and shopping sites. A single match can link your work identity to your personal handles, home address, and family members’ accounts. Public reporting shows these chains frequently lead to account takeovers on email, banking, or children’s gaming profiles. The medical documents add another dangerous layer: health details can be used for targeted social engineering or sold on underground forums to fraud rings. Children’s gaming accounts are especially vulnerable because kids often reuse passwords or email addresses tied to a parent’s breached work record.