Ransomware victim disclosure
← All victimsCampbell University
listed as www.campbell.edu · Claimed by Incransom · listed 2 months ago
Status timeline
- ListedApr 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Apr 11, 2026
About the victim
AI dossier — public-source company profileCampbell University is a private university located in Buies Creek, North Carolina. It offers 150+ programs across 10 academic divisions, including undergraduate, graduate, and professional degrees in fields such as law, medicine, engineering, and nursing. The university is faith-inspired and serves a broad student population including veterans and international students.
- Industry
- Higher Education
- Address
- Buies Creek, NC, USA
Attack summary
Severity: critical — The group claims exfiltration of 500 GB of data from a university, including PII of students and faculty, sensitive incident records involving minors and sexual abuse allegations, and military recruitment data — constituting regulated and highly sensitive data at scale from an educational institution.The incransom group claims to have exfiltrated approximately 500 GB of data from Campbell University, asserting the stolen data includes highly sensitive personal records, alleged incidents of sexual abuse, drug use, military recruitment records, and other student/faculty personal data.
Data the group says was taken
AI dossier — extracted from the leak post- Student personal data (PII)
- Faculty personal data (PII)
- Alleged misconduct/incident records
- Military recruitment records
- Student disciplinary records
- Drug use incident records
What the group claims
In the university data leak, there will be incidents related to teachers' pedophilia, sexual abuse of students by other students, drug use, personal data, military recruitment of students, and other things 500gb
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

