On June 24, 2025, the Akira ransomware group listed Datrose on its leak site and announced it had exfiltrated more than 5 GB of the company’s internal files. The business outsourcing provider, which handles document management, mail services, contact center operations, accounts payable, and staffing for other organizations, saw confidentiality agreements, employee records containing SSNs, dates of birth, emails, and addresses, plus financial data including payment details and invoices exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Datrose
Get alerted the next time Datrose files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Datrose’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates Akira posted proof of the theft on its dark-web leak portal, threatening to publish the full archive unless Datrose meets an undisclosed ransom demand. The exposed material includes NDAs and a range of corporate documents that contain personal information belonging to current and former employees as well as individuals whose records Datrose processes on behalf of clients. No exact number of affected people has been released, but the volume and sensitivity of the files suggest thousands of records are at risk.
The incident follows Akira’s standard pattern of stealing data before encrypting systems, then using the threat of public release to pressure victims. Datrose has not yet issued a public statement confirming the breach or detailing what steps it has taken.
Why This Matters for You and Your Family
When a company like Datrose loses control of SSNs, dates of birth, addresses, and emails, the information can be used to open accounts in your name, file fraudulent tax returns, or impersonate you with banks and government agencies. If you or a family member ever worked for Datrose, used its staffing services, or had documents processed through its mail or contact-center operations, your data may now be in criminal hands.