Ransomware victim disclosure
← All victimsNational Institute of Administration (INA)
listed as National Institute of Administratio... · Claimed by killsec · listed 7 months ago
Status timeline
- Listed
Oct 23, 2025
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileThe National Institute of Administration (INA) is a Romanian public institution operating under the Ministry of Development, Public Works, and Administration. It is dedicated to the professional development and training of civil servants and public administration personnel across Romania. INA plays a central role in improving the efficiency, transparency, and effectiveness of Romanian public services.
- Industry
- Public Administration Training & Civil Service Development
- Address
- Str. Eforie nr. 5, Sector 5, Bucharest, Romania
Attack summary
Severity: high — The victim is a government-affiliated public institution handling civil servant and public administration personnel data; disclosed status is 'data_published', confirming exfiltration of data that likely includes PII of government employees and sensitive institutional records.KillSec claims to have compromised INA with data published ('data_published' status), suggesting exfiltration of data from a Romanian government-affiliated public institution; no ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Civil servant records
- Training program data
- Personnel information
- Public administration documentation
What the group claims
The National Institute of Administration (INA) is a Romanian public institution dedicated to the professional development and training of civil servants and personnel in public administration. Operating under the coordination of the Ministry of Development, Public Works, and Administration, INA plays a pivotal role in enhancing the efficiency, transparency, and effectiveness of public services across Romania.
Sources
- Victim siteina.gov.ro
Source
Indexed 7 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
