Ransomware victim disclosure
← All victimsYale University Press
listed as yalebooks.yale.edu · Claimed by Scarlettgroup · listed 4 hours ago
Status timeline
- ListedOct 8, 2026
- Data leakeddate unknown
At a glance
- Group
- Scarlettgroup
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Oct 8, 2026
About the victim
AI dossier — public-source company profileYale University Press is the scholarly publishing division of Yale University, operating the Yale Books website to showcase and sell academic, scholarly, and general-interest books. The platform serves the university community and the broader reading public.
- Industry
- Academic Publishing
- Founded
- 1908
Attack summary
Severity: critical — Confirmed exfiltration of PII at scale (64k+ student and employee records), financial transaction data including payment card details, and system secrets. Educational institution breach with sensitive academic materials and institutional credentials exposed.Scarlettgroup claims to have exfiltrated 64,000+ records containing personally identifiable information on students and employees, 28,000+ financial transactions (credit card type, masked PAN, expiration, billing and transaction details), application source code, course materials, instructor and student requests, exam materials with answer keys, registration forms, and system secrets/keys.
Data the group says was taken
AI dossier — extracted from the leak post- Student PII (64k+ records)
- Employee PII (64k+ records)
- Credit card transactions (28k+)
- Source code
- Course materials and assets
- Instructor requests
- Student requests
- Exam materials with answer keys
- API keys and secrets
- Registration form entries
- WPForms export data
What the group claims
Yale University Press’s Yale Books website showcases and sells scholarly, academic, and general-interest books.
The leak post
captured from the group's site[ Yale University Press’s Yale Books website showcases and sells scholarly, academic, and general-interest books. ](http://scarlettgugldabhgz3uertpnxglxytddxbd5vnoma5pihfk6k5q2sid.onion/?open=02e92f3aae2c37615f) Compromised data: 64k+ PII on all students and employees 28k+ TXNS (CC Type, masked PAN, MM/YY, Billing, Total, Date, ID) Yalebooks Source Code Course Assets Course Resources Instructor Request Student Request Exam Desk Copies (with answer keys) Secrets Keys Registration Form Entries WPForms Export & More
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

