Ransomware victim disclosure
← All victimsYale University Press (Yale Books)
Claimed by Scarlettgroup · listed 4 hours ago
Status timeline
- ListedOct 9, 2026
Current state: Listed for ransom
At a glance
- Group
- Scarlettgroup
- Status
- Listed for ransom
- Country
- United States
- Sector
- Education / Publishing
- Listed on leak site
- Oct 9, 2026
- Records
- 64000+ PII records, 28000+ transactions
About the victim
AI dossier — public-source company profileYale University Press is the scholarly publishing division of Yale University, responsible for publishing and distributing academic, educational, and general-interest books. The organization operates the Yale Books platform for showcasing and selling its publications.
- Industry
- Academic Publishing
Attack summary
Severity: critical — Confirmed exfiltration of PII at scale (64k+ records) affecting students and employees, combined with partial payment card data from 28k+ transactions, API secrets, and sensitive educational/administrative records. This meets the threshold for regulated sensitive data exposure.Scarlettgroup claims to have exfiltrated 64,000+ personal records (PII) from students and employees, 28,000+ payment transaction records with partial card data (CC type, masked PAN, expiration, billing details), source code, educational course materials, instructor and student request data, exam resources with answer keys, API secrets, registration forms, and additional administrative exports.
Data the group says was taken
AI dossier — extracted from the leak post- 64k+ student and employee PII
- 28k+ transaction records with partial payment card data
- Source code
- Course materials and assets
- Course resources
- Instructor requests
- Student requests
- Exam desk copies with answer keys
- API secrets and keys
- Registration form entries
- WPForms exports
What the group claims
Yale University Press's Yale Books website showcases and sells scholarly, academic, and general-interest books.
The leak post
captured from the group's site[ Yale University Press’s Yale Books website showcases and sells scholarly, academic, and general-interest books. ](http://scarlettgugldabhgz3uertpnxglxytddxbd5vnoma5pihfk6k5q2sid.onion/?open=02e92f3aae2c37615f) Compromised data: 64k+ PII on all students and employees 28k+ TXNS (CC Type, masked PAN, MM/YY, Billing, Total, Date, ID) Yalebooks Source Code Course Assets Course Resources Instructor Request Student Request Exam Desk Copies (with answer keys) Secrets Keys Registration Form Entries WPForms Export & More
Data the group says was taken
- PII
- Credit Card Transactions
- Source Code
- Course Assets
- Course Resources
- Instructor Requests
- Student Requests
- Exam Desk Copies
- Answer Keys
- Secret Keys
- Registration Form Entries
- WPForms Export
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

