Sarcoma ransomware group claims 377 GB stolen from PCB maker Unimicron
- Organization
- Unimicron Technology
- Exploit
- Ransomware
- Industry
- Manufacturing
Unimicron Technology, a Taiwanese manufacturer and one of the largest producers of high density interconnect printed circuit boards and semiconductor carriers, confirmed that it was hit by a ransomware attack on January 30, 2025. The company disclosed the incident in a filing on February 1 and said it had brought in an external cyber forensics team to examine the intrusion and strengthen its defenses.
Unimicron described the anticipated impact as limited. Security Affairs reported that the attack affected Unimicron Technology (Shenzhen) Corp., a subsidiary in China, while SecurityWeek's account referred to the company's IT systems without naming a specific unit. As of the February reporting, Unimicron had confirmed the attack but had not confirmed that any data was stolen, saying it would continue to strengthen security controls across its network and information infrastructure.
On February 11 the Sarcoma ransomware operation named Unimicron on its leak site, publishing screenshots of documents it said came from the company and claiming to hold 377 GB of SQL files and other material. The group threatened to release the full set unless a payment was made. Security Affairs reported a deadline of February 20, while SecurityWeek said the listing gave less than a week to pay.
Sarcoma had appeared only a few months earlier, in October 2024, and by February 2025 had listed roughly 70 victims while using the mix of encryption and data theft common to double extortion crews. Unimicron supplies components used in mobile devices, automotive electronics and computing hardware, which drew attention to the potential supply chain consequences.