Ransomware victim disclosure
← All victimsDaegu University
listed as dg.ac.kr · Claimed by AuditTeam · listed 2 hours ago
Status timeline
- ListedSep 16, 2026
- Data leakeddate unknown
At a glance
- Group
- AuditTeam
- Status
- Data leaked
- Country
- South Korea
- Sector
- Education
- Listed on leak site
- Sep 16, 2026
About the victim
AI dossier — public-source company profileDaegu University (dg.ac.kr) is a South Korean university based in Daegu. The institution operates as an accredited higher education provider in the region.
- Industry
- Higher Education
Attack summary
Severity: high — Confirmed exfiltration of data from a higher education institution with public disclosure. Educational institutions hold PII at scale (student records, staff data, research information). The group explicitly states complete data archive publication, indicating material data exposure.AuditTeam claims to have acquired data from the university and published sample artifacts as proof of breach. The group states that a complete data archive is now publicly available following expiration of an unspecified remediation window.
Data the group says was taken
AI dossier — extracted from the leak post- University records
- Institutional data
What the group claims
No data breaches
The leak post
captured from the group's site[[ DATA EXPOSURE LOGS ]](http://6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion/) ### [ EVIDENCE OF ACQUISITION (SAMPLE) ] Sample data artifacts have been published to validate our audit findings. Copy the links below to verify. ### [ PUBLIC TRANSPARENCY ARCHIVE ] The remediation window has expired. The complete acquired data archive is now public.
Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

