Ransomware victim disclosure
← All victims51Talk Online Education
listed as 51talk.com · Claimed by lockbit3 · listed 1 year ago
Status timeline
- Listed
Mar 18, 2025
- Data leaked
At a glance
About the victim
AI dossier — public-source company profile51Talk is a global online English education platform for children aged 3-15, offering one-on-one lessons with native English-speaking teachers. The company is listed on NYSE American (ticker: COE) and has been operating for over 10 years with a presence in multiple countries across Asia and beyond.
- Industry
- Online Education & Language Learning
- Address
- 60 Paya Lebar Road #12-03 Paya Lebar Square, Singapore 409051
- Founded
- 2011
Attack summary
Severity: high — Confirmed exfiltration of significant operational and staff data from a publicly-traded education company serving minors; exposure of employee records and internal operational databases poses privacy and security risks. Data published status confirms breach validation.LockBit3 claims to have exfiltrated multiple database backup files totalling approximately 12GB, including activity logs, staff records, and operational task data from 51Talk's systems.
Data the group says was taken
AI dossier — extracted from the leak post- Activity logs (backup)
- Staff/employee records (backup)
- Operational data (backup)
- Task management data (backup)
The group's post references roughly 4 backup files advertised proof files.
What the group claims
A lot of interesting info: 1G - 51TalkActivity_backup_2025_01_25_030001_1281267.bak 1G - 51TalkNewStaff_backup_2025_01_25_030001_1281267.bak 1G - 51TalkOA_backup_2025_01_25_030001_1437541.bak 9G - 51TalkOAtask_backup_2025_01_25_030001_1281267.bak...
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
