ransomware
Credible
South Africa (ZA)
finance
Baker Tilly Morrison Murray listed by the Sarcoma ransomware group
Baker Tilly Morrison Murray
CompanyBaker Tilly Morrison Murray
Domainbakertillymm.co.za
CountrySouth Africa (ZA)
Sectorfinance
Breach date2024-12-24
People affected200,000
Ransomware groupsarcoma
Data typesclient records, financial documents, employee information
Overview
The Sarcoma ransomware group has listed Baker Tilly Morrison Murray, a firm of registered auditors and chartered accountants in Durban, South Africa, on its leak site. The firm traces its roots back to 1914. The listing appeared on 24 December 2024.
What was published
The group claims to have exfiltrated data from the accounting firm. The archive is expected to include client financial records, audit documentation and employee information.
Risks for affected individuals
- Clients' financial data may be exposed.
- Audit records are sensitive.
- Employees' information may be included.
What remains unknown
- The volume of data exfiltrated.
- Whether the data has been published.
- The response status of the firm.
What affected people should do
Clients should monitor financial accounts and verify any unusual requests. Baker Tilly Morrison Murray should notify clients and staff, review its systems, and report the incident to South African authorities.