Ransomware victim disclosure
← All victimsHarvard University
Claimed by Hunters International · listed 3 months ago
Status timeline
- Listed
Feb 24, 2026
- Data leaked
At a glance
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Feb 24, 2026
- Data size
- 1.1 GB
About the victim
AI dossier — public-source company profileHarvard University is one of the world's most prestigious research universities, located in Cambridge, Massachusetts. Founded in 1636, it offers undergraduate, graduate, and professional programs across a wide range of disciplines and operates numerous research institutes and affiliated hospitals. It employs tens of thousands of faculty, staff, and researchers and maintains one of the largest academic endowments globally.
- Industry
- Higher Education
- Address
- Massachusetts Hall, Cambridge, MA 02138, United States
- Employees
- 10000+
- Founded
- 1636
Attack summary
Severity: high — Data has been confirmed as published (disclosed status: data_published) following exfiltration from a major research university that handles large volumes of PII, research data, financial records, and potentially regulated academic or medical research data. While the 1.1 GB size is relatively modest, the sensitivity of the institution and confirmed publication elevates severity to high.Hunters International claims to have exfiltrated approximately 1.1 GB of compressed data from Harvard University and has published the data following an apparent refusal to pay a ransom. The post implies the group made prior contact with the university and is retaliating against advice given to Harvard not to pay.
Data the group says was taken
AI dossier — extracted from the leak post- Exfiltrated university data (1.1 GB compressed)
- Potentially sensitive institutional or personal records
What the group claims
Size: 1.1GB (compressed) | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
