Ransomware victim disclosure
← All victimsColegio María Inmaculada (CMI)
Claimed by medusalocker · listed 15 days ago
Status timeline
- Listed
May 5, 2026
- Data leaked
At a glance
- Group
- medusalocker
- Status
- Data leaked
- Country
- CR
- Sector
- Education
- Listed on leak site
- May 5, 2026
About the victim
AI dossier — public-source company profileColegio María Inmaculada (CMI) is a Catholic school located in Moravia, Costa Rica, operating under the domain mariainmaculada.ed.cr. It provides primary and/or secondary education in the Costa Rican school system. The public website was not accessible at time of analysis, returning only a 'Coming Soon' placeholder page.
- Industry
- Primary & Secondary Education (Catholic School)
- Address
- Moravia, San José, Costa Rica
Attack summary
Severity: high — Data is stated as published (data_published) following compromise of multiple internal servers including a domain controller, implying credential and directory data exfiltration from an educational institution likely holding student and staff PII. The involvement of a DC suggests broad network access and potential exposure of regulated personal data for minors.MedusaLocker claims to have compromised the school's internal network infrastructure, identifying multiple servers (CMI-DC01, CMI-APP, CMI-HTTP2, main-server1/2) and the local domain cmi.local. The post is listed under 'data_published' status, suggesting exfiltration occurred, though no specific data categories or volume are described in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Active Directory domain data (cmi.local)
- Domain controller contents (CMI-DC01)
- Application server data (CMI-APP)
- Web server data (CMI-HTTP2)
- General server data (main-server1, main-server2)
What the group claims
Catholic school in Moravia, Costa Rica. Domain cmi.local / mariainmaculada.ed.cr. Servers: CMI-DC01, CMI-APP, CMI-HTTP2, main-server1/2.
The leak post
captured from the group's siteFile Manager File Manager home page BARAAAI Data is being prepared for publication. BAPAMAI Data is being prepared for publication. BAUARAI Data is being prepared for publication. BAVADAI Data is being prepared for publication. BAVACAI Data is being prepared for publication. BAVAQAI Data is being prepared for publication. Raycolighting DEMO 3137 S Alameda Street, Los Angeles, CA 90058, USA $10 000 Organization with 2 emails extracted. Domain: raycolighting.com baralai Data is being prepared for publication. CEAGESP / Netfeirasp DEMO São Paulo, Brazil $20 000 Brazilian produce wholesale market network. Domain netfeirasp.ceagesp (CEAGESP). Also demarchibrasil.com.br accounts. Colegio María Inmaculada (CMI) DEMO Moravia, San José, Costa Rica $50000 Catholic school in Moravia, Costa Rica. Domain cmi.local / mariainmaculada.ed.cr. Servers: CMI-DC01, CMI-APP, CMI-HTTP2, main-server1/2. Académie de Montpellier / CSJM DEMO Béziers, Occitanie, France $15000 French public school network. Domain CSJM.BEZIERS, part of Académie de Montpellier (ac-montpellier.fr). Occitanie region (laregion.fr). Teacher and admin staff credentials. Palmers Relocations DEMO Victoria, Australia $63 000 Australian …
Sources
Source
Indexed 15 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
