Ransomware victim disclosure
← All victimsEllucian
listed as Ellucian PowerCampus Warning (Contact Us) · Claimed by shadowbyt3$ · listed 6 days ago
Status timeline
- Listed
May 14, 2026
- Data leaked
At a glance
- Group
- shadowbyt3$
- Status
- Data leaked
- Country
- US
- Sector
- Education
- Listed on leak site
- May 14, 2026
About the victim
AI dossier — public-source company profileEllucian is a US-based software company that provides SaaS and ERP solutions purpose-built for higher education institutions, including student information systems, HCM, finance, recruiting, and analytics platforms. Recognized as a Leader in the Gartner Magic Quadrant for Higher Education SaaS Student Information Systems for two consecutive years, Ellucian serves colleges and universities globally. Its PowerCampus product is a student information system used by numerous higher education institutions.
- Industry
- Higher Education SaaS & ERP Software
- Employees
- 1001-5000
Attack summary
Severity: critical — The claimed breach affects multiple higher education institutions via a shared SaaS platform, with student PII and institutional records at scale potentially exposed across many schools; proof files have been published to Mega.nz and data is threatened for full public release, indicating confirmed exfiltration of regulated education data (FERPA-covered) across a supply-chain-style attack vector.The threat actor 'shadowbyt3$' claims to have exfiltrated data from multiple schools using Ellucian's PowerCampus platform, providing a Mega.nz link with sample proof files including reports dated 2025 and 2026, and threatening to publicly release all data unless Ellucian contacts them by May 20th. The post also references a Telegra.ph page listing all affected schools and instructions for accessing data via Tor.
Data the group says was taken
AI dossier — extracted from the leak post- Student records from affected institutions
- Institutional reports (2025 and 2026 samples)
- Data from multiple schools using Ellucian PowerCampus
- Tor-accessible full dataset
The group's post references roughly 2 proof files.
What the group claims
This is a warning for ellucian PowerCampus. Due to not people paying much for are breach we will give you 48 hours to contact us. If you don't it will get published instead of sold. To all researchers to verify the data is real you can go to the mega.nz leak below. Also we put 2 reports from 2025 and 2026 for a sample. Due to company not contacting us it would be great if you could let them know so there aware. You have till May 20th to contact us and reach an agreement or all data gets leaked and posted. mega.nz: https://mega.nz/folder/f8B2QKAI#WC6QVl2VmhgP_PWR6DsUUw also the link below is for all affected schools and how to access tor and download tor for companies. https://telegra.ph/All-The-affected-Schools-By-Ellucian-PowerCampus-and-how-to-download-and-use-tor-browser-05-14
Sources
- Victim siteellucian.com
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
