Studio Eco Perucca Listed by malas Ransomware Group
If you are a customer of Studio Eco Perucca, here’s what is being claimed, and what it would mean for you.
Studio Eco Perucca was listed on Malas's leak site. Malas claims to have stolen internal data. This is the group's claim, not a confirmed finding.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Studio Eco Perucca customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On April 9, 2023, the ransomware group known as malas added Studio Eco Perucca to its public leak site, claiming that the French design and architecture firm had been hit by a ransomware attack that used a Zimbra vulnerability for initial access and resulted in the exfiltration of internal files.
Details from the Leak Site
The listing on the malas dark-web portal, accessible via the .onion link hosted on ransomware.live, states that internal files were exfiltrated during the ransomware attack. The disclosure does not quantify the number of records affected, nor does it list specific data types such as client contracts, employee personal information, or financial records. It simply states that data was taken and that the victim has not yet met the group’s demands. The notification also indicates the breach originated through exploitation of a known vulnerability in the Zimbra collaboration suite, a common entry point that allows attackers to gain a foothold before deploying ransomware and exfiltrating files.
April 9, 2023 marks the date the listing first appeared, and the leak site continues to display Studio Eco Perucca among its defaulters. No sample data has been publicly released in the listing itself, which is typical for early-stage extortion pages that reserve full publication for later stages of the campaign.
Why This Matters for You and Your Family
When a small or mid-sized business like a design studio suffers a breach, the personal information of clients, employees, and vendors often travels with the internal files. If your name, address, email, phone number, or payment details were stored in those systems, they may now be in the hands of criminals who specialize in turning stolen data into cash. For ordinary people, this means your information could surface on additional dark-web markets, be sold to identity thieves, or be used to launch targeted phishing attacks against you or members of your household.
Even when exact record counts remain unknown, the exposure creates real risk. Families who worked with the studio, supplied services, or had employees there may find their data circulating for years. Credential reuse across personal and professional accounts makes the problem worse, as one leaked password can unlock email, banking, or social-media profiles that contain far more sensitive details.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Doxxing and Identity-Chain Risks
Exfiltrated internal files frequently contain more than just documents. They can include spreadsheets that link names to addresses, email correspondence that reveals personal relationships, and metadata that ties digital identities to real-world locations. Attackers and subsequent buyers can chain these fragments together to build detailed profiles. A seemingly harmless client list can be cross-referenced with breached gaming accounts, social-media handles, or family photos to enable swatting, harassment, or financial fraud.
Credential leaks like this one cascade into account takeovers and doxxing chains, especially when the same passwords protect both business systems and home networks. Children’s gaming accounts are particularly vulnerable because they often share family email addresses or phone numbers listed in the studio’s contact files. Once an attacker controls one account in the chain, they can reset others and deepen the compromise.
The Malas Ransomware Group’s Track Record
Public reporting attributes the malas group with emerging in late 2022 as a relatively new double-extortion operation. The actors typically gain initial access through unpatched vulnerabilities in email and collaboration platforms such as Zimbra, then deploy ransomware while simultaneously exfiltrating data for leverage. Their playbook follows the now-standard model: encrypt systems to disrupt operations, threaten to publish stolen files if the ransom is not paid, and maintain a leak site to pressure victims publicly.
Notable prior victims listed in open-source intelligence include other small-to-medium European businesses in creative, manufacturing, and professional-services sectors. The group’s extortion style relies on timed deadlines and gradual data dumps rather than immediate mass publication, giving victims a narrow window to respond before samples or full archives appear. While malas is not among the largest ransomware families, its consistent activity and focus on accessible vulnerabilities make it a persistent threat to organizations that delay patching.
What to do
- Run a DoxxScan to map every link between your emails, phone numbers, handles, and real identity so you can see exactly what this claimed breach connects to.
- Rotate any password you used at Studio Eco Perucca or related services, then enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure surfaces in hours instead of months.
- Cover the household with DoxxScan family protection that includes dependents and children’s gaming accounts which often chain back to the same contact details.
- Let remediation specialists handle data-broker takedown requests and follow-up monitoring while you focus on securing your own accounts.
The Studio Eco Perucca breach is a reminder that even specialized firms handling everyday client relationships can become gateways to personal exposure. Taking concrete steps now limits how far attackers can travel down the identity chain created by this and future incidents. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that explicitly protects children’s gaming accounts from cascading takeovers.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Everglades Boats Listed by termite Ransomware Group
Founded in 2001, Everglades Boats is a manufacturer of offshore fishing boats. The company is headqu…
holzmarkt chemnitz Listed by spacebears Ransomware Group
Holzmarkt Chemnitz is a specialized retail store for building materials and wood products, operating…
Victory Personal Care, Inc Listed by nightspire Ransomware Group
Data is not available now.…