On December 17, 2023, Japanese glass manufacturer AGC Inc. (agc.com) appeared on the leak site of the Black Basta ransomware group. The listing states that attackers exfiltrated 1.5 TB of internal files during a ransomware incident. The company has not yet published a formal breach notification quantifying how many individuals are affected or detailing exactly which records reached the threat actors.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch agc.com
Get alerted the next time agc.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about agc.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The Black Basta portal lists AGC under its .com domain and describes the stolen material as “Internal files exfiltrated in ransomware attack.” Sample folders referenced include user personal folders, Technology, Human Resources, Finance, and additional corporate directories. The disclosure does not specify the exact number of employee or customer records involved, nor does it list particular document types such as passports, tax forms, or medical information. The posting simply states that data was taken and is held for extortion purposes.
Why This Matters for You and Your Family
When a global manufacturer like AGC suffers a breach, the personal folders of its employees, contractors, and business partners are often among the first items taken. If you or a family member ever worked at AGC, supplied the company, or had your information stored in its HR or finance systems, your details may now sit on a criminal server. Even without an exact headcount, the 1.5 TB volume signals that thousands of records are likely exposed. Once files leave the victim’s control, they can be traded, sold, or used to launch follow-on attacks against you personally.
The Doxxing and Identity-Chain Risk
Stolen internal folders frequently contain spreadsheets that link names, email addresses, phone numbers, dates of birth, and sometimes Social Security numbers or passport copies. Threat actors chain this information with data from previous breaches to build complete identity profiles. A single leaked work email can expose your home address, family member names, and even children’s school details when cross-referenced across public records and other stolen databases. These chains frequently lead to account takeovers on personal email, banking, and social media. Credential leaks like this one cascade into gaming-account takeovers when the same password protects a child’s Roblox, Fortnite, or Steam profile tied to the family address.