Ransomware victim disclosure
← All victimsLRN
Claimed by Hunters · listed 2 years ago
Status timeline
- ListedAug 3, 2024
- Data leakeddate unknown
At a glance
- Group
- Hunters
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Aug 3, 2024
About the victim
AI dossier — public-source company profileLRN is a software and training company providing ethics and compliance solutions to organizations worldwide. They offer platforms (Catalyst suite) and training programs covering anti-bribery, anti-harassment, anti-money laundering, code of conduct, data privacy, and regulatory compliance. The company serves 2,500+ organizations globally.
- Industry
- Ethics & Compliance Software / Training Services
Attack summary
Severity: high — LRN operates an ethics and compliance platform serving 2,500+ organizations, meaning exfiltrated data likely includes sensitive client information, regulatory compliance records, and potentially personally identifiable information of employees across many organizations. Confirmed dual encryption and exfiltration elevates risk despite lack of specific data inventory details in the post.The hunters group claims to have both encrypted LRN's systems and exfiltrated data from the company. The specific nature and scope of exfiltrated data is not detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Customer/client data
- Training and compliance program materials
- Code of conduct information
- Business systems data
What the group claims
Country : United States of America - Exfiltraded data : yes - Encrypted data : yes
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

