Ransomware victim disclosure
← All victimsIGI Global
Claimed by Akira · listed 5 months ago
Status timeline
- ListedJan 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Jan 23, 2026
- Data size
- 220 GB
About the victim
AI dossier — public-source company profileIGI Global is a US-based international academic publisher specializing in research publications across science, technology, engineering, and social sciences. The company produces peer-reviewed journals, books, and reference works disseminated to academic institutions worldwide. It is headquartered in Hershey, Pennsylvania.
- Industry
- Academic & Scholarly Publishing
- Employees
- 51-200
- Founded
- 1988
Attack summary
Severity: critical — The threat actor claims exfiltration of 220 GB of data explicitly containing regulated PII at scale — including government-issued IDs, financial payment card data, and health information — qualifying as multiple categories of sensitive/regulated data under HIPAA, PCI-DSS, and state privacy laws.Akira claims to have exfiltrated approximately 220 GB of corporate data from IGI Global, including employee personal information (passports, driver's licenses, credit card details, health information), financial records, contracts, NDAs, and confidentiality agreements, with publication of the data stated as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driver's licenses
- Credit card details
- Employee health information
- Financial records
- Contracts and agreements
- NDAs
- Confidentiality agreements
What the group claims
IGI Global is an international academic publisher committed to pr oducing the highest quality research and ensuring the timely diss emination of innovative research findings through an expeditious and technologically advanced publishing process. We will upload 220gb of corporate data soon. Employee personal in formation (passports, DLs, credit card details, health informatio n), financials, contracts and agreements, NDA, confidentiality ag reements and so on.
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

