Ransomware victim disclosure
← All victimsGruppo Spaggiari Parma S.p.A
Claimed by Xpl0Itrs · listed 22 hours ago
Status timeline
- ListedAug 23, 2026
Current state: Listed for ransom
At a glance
- Group
- Xpl0Itrs
- Status
- Listed for ransom
- Country
- Italy
- Sector
- Education Technology
- Listed on leak site
- Aug 23, 2026
- Data size
- 6.1TB
- Records
- 15+ million documents
About the victim
AI dossier — public-source company profileGruppo Spaggiari Parma S.p.A is an Italian education technology company that develops and operates school management and digital learning platforms. Their product suite includes ClasseViva (teaching management), Segreteria Digitale (administrative systems), and various ancillary tools for Italian schools. The company serves as a critical infrastructure provider to Italian schools.
- Industry
- Education Technology
Attack summary
Severity: critical — Exfiltration of 6.1TB of PII affecting 15+ million individuals (per attacker claims), including children, from a critical school infrastructure platform. The scale, sensitivity (minors' data), and regulated context (GDPR-covered EU education sector) meet critical thresholds even without independent verification of the breach itself.xpl0itrs claims to have exfiltrated 6.1TB of data from Spaggiari's systems, including personal information of students and adults. The group alleges the company has publicly denied the breach severity and is prioritizing reputation management over disclosure to affected parties; the attackers threaten to leak or sell the data if contact/negotiation does not occur.
Data the group says was taken
AI dossier — extracted from the leak post- Personally identifiable information (PII) of students and adults
- School administrative records
- Platform user data
What the group claims
Ransomware group xpl0itrs claims to have stolen 6.1TB of PII from Spaggiari, an Italian edtech company providing electronic registers and school management platforms. The company has publicly denied the attack. The group threatens to leak or sell the data privately if no contact is made.
The leak post
captured from the group's site# PSA regarding Gruppo Spaggiari Parma S.p.A Since being listed, Spaggiari has released their own article regarding our attack (which you can view at https://www.spaggiari.eu/news/comunicazione-ufficiale-sull-attacco-informatico-alla-piattaforma-bergantini). They are claiming their analysts found the 'rumors' to be false. This is a lie. We have been contacted by a journal directly at the heart of Italy - and we had a nice conversation with them. Their article is going to disprove Spaggiari's response. On top of their actual response, they have also employed a PR company to write an article (https://www.orizzontescuola.it/attacco-informatico-a-bergantini-spaggiari-rassicura-le-scuole-registro-elettronico-e-gestioni-mai-coinvolti-i-dati-sono-al-sicuro/) to perpetuate this idea of security. Dear Spaggiari, how can you justify putting profits before children? How can you justify denying the existence of 6.1TB of stolen PII? We don't want to leak this data, partly because it's so big, but also because we understand the severity. We both know the severity yet they don't want the public to know the severity. We don't want to leak this, but we absolutely will, and the ignorance gives us mo…
Data the group says was taken
- PII
- personal documents
Screenshot of the leak post

Sources
Source
Indexed 22 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

