On December 07, 2024, Brazilian natural-stone company Uniamarmores appeared on the leak site operated by the funksec ransomware group. The listing states that internal files were exfiltrated during a ransomware attack. The exact number of records exposed remains unknown, and the leak-site page does not detail which specific documents or data types were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch uniamarmores
Get alerted the next time uniamarmores files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about uniamarmores’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The funksec leak site, accessible via the onion address hosted on ransomware.live, publicly named Uniamarmores and asserted that the company’s internal files had been stolen. No sample data appears to have been published at the time of the initial listing, and the disclosure does not specify the volume of information involved or name the precise systems that were compromised. The entry simply confirms a successful ransomware deployment followed by data exfiltration. Public reporting on funksec indicates the group follows a double-extortion model: encrypting victim systems while simultaneously threatening to release stolen files unless a ransom is paid.
Why This Matters for You and Your Family
Even when a breach targets a business, ordinary customers, suppliers, and employees can be affected. If you have purchased marble or stone products from Uniamarmores, worked with the company, or had your contact details stored in its files, your personal information may now sit in an attacker-controlled archive. Internal files frequently contain invoices, contracts, shipping addresses, phone numbers, email accounts, and sometimes copies of identification documents. Once that material leaves the company’s control, it can be traded, sold, or used to launch further attacks against you and your household.
The Doxxing and Identity-Chain Risk
Ransomware leaks rarely stop at one company. A single exposed email or phone number can be correlated with gaming usernames, social-media handles, and family addresses to build a complete identity chain. Attackers then target linked accounts — including children’s gaming profiles — to escalate pressure or commit identity theft. Credential leaks of this kind frequently cascade into account takeovers across unrelated services. Continuous monitoring that maps these connections is essential because the data rarely surfaces in public breach lists immediately.