Skip to content
Leak-site post naming GYF, captured by ThreatCluster

GYF

sarcoma

Ransomware leak-site victim intelligence

Data size
1.5Tb
Views
49,594
Posted
Mar 30, 2026
Country
Argentina
Industry
Business Services

Summary

Written by ThreatClusterfrom victim profile, leak post

The group sarcoma claims 1.5 TB of data exfiltrated from GYF, a firm operating at gyf.com.ar in Argentina. The leak states the data includes HR and recruitment records, internal documentation and source code. The leak post is published on the group's site.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

What was taken

Design and develop IT products and services for the financial market

Data categories
SQL

Also stated on the leak page

Fields this group publishes that do not map to a standard column. Labels are the site's own.

Contains
SQL
Download Link
e2hziphckfndi5osd3dr24qbs5gccsk4ebsmx5l4udf54qgbsw5vl3qd.onion

Leak-site images (1)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture