Ransomware victim disclosure
← All victims박문각 (Parkmungak)
listed as EduSpa · Claimed by Dragonforce · listed 2 days ago
Status timeline
- ListedAug 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Sector
- Hospitality
- Listed on leak site
- Aug 6, 2026
About the victim
AI dossier — public-source company profileParkmungak is a South Korean educational institution founded in 1972 that specializes in test preparation and professional certification training. The company offers online and offline courses for civil service exams, real estate licensing, legal professions, teaching credentials, and various professional certifications across multiple physical locations in South Korea.
- Industry
- Educational Services & Test Preparation
- Founded
- 1972
Attack summary
Severity: medium — Educational institution with large user base (3.7+ million mock exam takers recorded) handling student PII and test data; however, no proof files are advertised, no specific data categories confirmed exfiltrated, and no operational disruption stated. The disclosure status is 'data_published' but without concrete evidence shown.The dragonforce group claims to have breached Parkmungak and exfiltrated data. No specific details about encryption, operational impact, or data categories are provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- student personal information
- exam records
- course enrollment data
- user account credentials
What the group claims
Parkmungak has been operating since 1972, providing a range of services and products tailored to meet the needs of its clients. The company focuses on delivering high-quality solutions and has established a reputation for excellence in its field. With a commitment to innovation and customer satisfaction, Parkmungak aims to serve a diverse clientele. Their offerings include various services designed to enhance user experience and operational efficiency.
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

