Ransomware victim disclosure
← All victimsMinistry of Communities, Territories and Infrastructure Development of Ukraine
listed as minregion.gov.ua · Claimed by Freecivilian · listed 3 years ago
Status timeline
- Listed
Dec 31, 2022
- Data leaked
At a glance
- Group
- Freecivilian
- Status
- Data leaked
- Country
- Ukraine
- Sector
- Government
- Listed on leak site
- Dec 31, 2022
About the victim
AI dossier — public-source company profileminregion.gov.ua is the official domain of Ukraine's Ministry of Communities, Territories and Infrastructure Development (formerly the Ministry of Regional Development, Construction and Housing). The ministry is a central executive body responsible for regional development policy, construction regulation, housing, urban planning, and infrastructure across Ukraine. It operates at the national level and oversees significant public administration and territorial governance functions.
- Industry
- Government – Regional Development & Infrastructure Ministry
Attack summary
Severity: critical — The victim is a national-level Ukrainian government ministry handling sensitive infrastructure, territorial, and administrative data. A confirmed data publication by a threat actor targeting a wartime government ministry constitutes a critical disclosure, involving potential exposure of regulated government PII, sensitive infrastructure planning data, and national security-adjacent administrative records.The Freecivilian group claims to have published data exfiltrated from the Ukrainian ministry's systems; no ransom demand was stated and the disclosure status is listed as data_published, indicating stolen data has been released publicly.
Data the group says was taken
AI dossier — extracted from the leak post- Government administrative records
- Ministry correspondence and documents
- Infrastructure and regional development data
- Employee or personnel records
- Internal policy and planning documents
Sources
- Victim siteminregion.gov
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
