Ransomware victim disclosure
← All victimsCMD Outsourcing Solutions
Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Apr 7, 2026
About the victim
AI dossier — public-source company profileCMD Outsourcing Solutions is a U.S.-based business process outsourcing firm specializing in multi-channel customer service solutions for higher education institutions. The company provides support services to university departments including Financial Aid, Admissions, Bursar, Registrar, and Housing. Its client base appears focused exclusively on the higher education sector.
- Industry
- Higher Education BPO & Customer Service Outsourcing
Attack summary
Severity: critical — The threat actors claim possession of highly regulated PII at scale — including SSNs, government-issued ID scans, and medical files — affecting employees of a firm serving numerous higher education institutions, representing confirmed exfiltration of sensitive personal and financial data subject to HIPAA, FERPA, and state privacy regulations.Akira claims to have exfiltrated corporate data from CMD Outsourcing Solutions, including scanned employee identity documents (passports, driver's licenses, SSNs), medical files, financial records, and NDAs, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Driver's licenses
- Social Security Numbers (SSNs)
- Employee medical files
- Financial records
- Non-disclosure agreements (NDAs)
- Corporate documents
What the group claims
CMD Outsourcing Solutions specializes in multi-channel customer s ervice solutions tailored for higher education institutions, exte nding support to departments such as Financial Aid, Admissions, B ursar, Registrar, and Housing. We will upload corporate data soon. Scanned employee documents (p assports, DLs, SSNs, medical files and so on), financial files, N DAs, etc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

