Ransomware victim disclosure
← All victimsISTS (International Scholarship and Tuition Services)
listed as ISTS · Claimed by Play · listed 4 months ago
Status timeline
- ListedFeb 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Play
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 4, 2026
About the victim
AI dossier — public-source company profileISTS (operating via applyists.com) is a 100% women-owned company founded in 1985 that specializes in comprehensive educational assistance program management, including scholarship administration, tuition reimbursement, student loan repayment, childcare reimbursement, and grants and fellowships programs. Based in the United States, the company serves a diverse portfolio of clients including Fortune 500 companies, corporate foundations, state agencies, and public charities. ISTS provides end-to-end administration backed by a proprietary technology platform for program sponsors.
- Industry
- Educational Assistance Program Management
- Employees
- 51-200
- Founded
- 1985
Attack summary
Severity: high — ISTS handles large volumes of student and applicant PII (names, educational records, financial awards data) on behalf of Fortune 500 companies and foundations; data_published status confirms exfiltration and release of likely sensitive personal and financial records at meaningful scale, though no exact data volume was specified.The Play ransomware group has listed ISTS with a disclosed status of 'data_published', indicating that data claimed to have been exfiltrated from the company has been released. No specific data size or ransom amount was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Scholarship applicant records
- Student personal information
- Tuition reimbursement program data
- Client organization data
- Employee records
- Financial/awards distribution data
What the group claims
United States
The leak post
captured from the group's site| Play ransomware HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RaaS, read the FAQ page.WE NEVER WRITES FIRST, IF SOMEONE WRITES TO YOU, THEY ARE SCAMMERS.we'll buy your access: 75tkvxemb6zpyk3fbl3mwm32jklc2sdjacb3kazrioamopbfn2w2z5qd.onionIf we have not responded to you by email within 12 hours, please leave your contact information on the website in the contact tab. | | --- | | EMA Engineering & Consulting👁️ views: 321added: 2026-05-07publication date: 2026-05-11 | Accessoires Outillage Ltee👁️ views: 280added: 2026-05-07publication date: 2026-05-11 | K & E Distributing👁️ views: 282added: 2026-05-07publication date: 2026-05-11 | | Sokolin👁️ views: 7261 | Barnes Solicitors LLP👁️ views: 7182 | Witt UK Group👁️ views: 8181 | | Valley Plating Inc👁️ views: 8198 | Dock Pros👁️ views: 8179 | Kivells👁️ views: 8150 | | Specflue👁️ views: 8137 | Weber Kracht & Chellew👁️ views: 8180 | Lucky Look👁️ views: 8285 |
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

