Ransomware victim disclosure
← All victimsAKTO
Claimed by Nitrogen · listed 1 year ago
Status timeline
- ListedMar 31, 2025
- Data leakeddate unknown
At a glance
- Group
- Nitrogen
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 31, 2025
About the victim
AI dossier — public-source company profileAKTO is a French OPCO (Organisme Paritaire Collecteur Agréé) — a joint collection body specializing in corporate training and employment services. It provides workforce development solutions, skills assessments, training financing, and HR services across multiple industry sectors, supporting companies and employees in France.
- Industry
- Professional Training & Employment Services (OPCO)
Attack summary
Severity: high — AKTO handles sensitive HR, payroll, and personal employee data across many French companies and individuals. As a training/employment services provider managing training funds and employee development records, exfiltration of such data affects regulated employment and training information at scale, suggesting high severity despite lack of explicit proof count or ransom demand.Nitrogen claims to have attacked AKTO, a French training and employment services organization. The group's post indicates data exfiltration, though specific details on data types or volume are not provided in the available excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Employee records
- Company training data
- HR/payroll systems
- Beneficiary client information
What the group claims
A French company specializing in digital learning and training solutions. It focuses on providing tools and services to improve corporate training, ensuring that companies can effectively upskill their employees.
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

