Ransomware victim disclosure
← All victimsMedical University of the Americas
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedJun 21, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- Nevis
- Sector
- Healthcare
- Listed on leak site
- Jun 21, 2023
About the victim
AI dossier — public-source company profileMedical University of the Americas (MUA) is a Caribbean medical school located on the island of Nevis, with over 25 years of experience training physicians. It offers MD and BSc/MD programs accredited by the Accreditation Commission on Colleges of Medicine (ACCM), with clinical rotations conducted in the U.S. and Canada. Its graduates practice primarily in the U.S. and Canada, and it participates in U.S. Title IV federal student aid programs.
- Industry
- Medical Education & Higher Education
- Address
- Nevis, Saint Kitts and Nevis, Caribbean
Attack summary
Severity: critical — MUA is a medical university whose systems likely contain regulated PII at scale, including student personal and financial records, medical education records potentially tied to U.S. federal student aid (Title IV), and faculty/staff data. The 'data_published' status confirms exfiltration and public release, meeting the threshold for critical severity.The Snatch ransomware group claims to have attacked MUA and has published data ('data_published' status), suggesting exfiltration of institutional data. The leak post does not specify encryption or provide details on data volume, but disclosure status indicates data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- Student records
- Admissions data
- Financial aid information
- Faculty and administration records
- Academic records
What the group claims
Newly Reduced Tuition Makes MUA Accessible and Affordable. It is a great time to get started on your medical education! At MUA we recently lowered our tuition, which made us MUA the most affordable Caribbean medical school that is approved to participate in U.S. Federal
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

