Ransom! Thermofin

The threat actor sarcoma claims to have encrypted 2.9 TB of Thermofin’s data, including files, SQL databases, and Exchange archives, potentially disrupting their operations. This cyberattack has impacted Canada.

Incident Details

  • Victim: Thermofin
  • Country: CA
  • Actor: sarcoma
  • Source:
  • Discovered: 2025-09-23 06:21:47.769269
  • Published: 2025-09-23 06:21:44.904056

Information

  • Thermofin specializes in high-performance cooling solutions for industries such as industrial refrigeration and air conditioning.
  • Their product range includes evaporators, air coolers, heat pumps, and hybrid chillers, serving both commercial and industrial clients.
  • Founded in 2002, Thermofin has expanded its production capabilities and created new jobs over the years.
  • The company emphasizes quality management and technical expertise in its operations.
  • Thermofin aims for sustainable growth and employee development.
  • The ransomware attack involved a leak of 2.9 TB of archive data containing files, SQL databases, and Exchange information.

Disclaimer: This post is based on public claims made by the ransomware group "sarcoma". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live