Ransomware victim disclosure
← All victimsUnknown Education Institution (440K records)
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedSep 10, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Sector
- Education
- Listed on leak site
- Sep 10, 2026
- Records
- 440000
About the victim
AI dossier — public-source company profileAn education institution handling student admissions, applications, and institutional records. The victim name '440K records' corresponds to one of several datasets listed in the breach disclosure, specifically an admissions/student database.
- Industry
- Education
Attack summary
Severity: critical — Confirmed exfiltration of 440K education records containing significant PII, student contact details, and admissions data—sensitive information about minors and applicants. Educational institution data involving minors is regulated and inherently high-sensitivity. Data is published with no removal possible.ExfilSquad claims to have exfiltrated approximately 440,000 records containing applicant and student contact information, significant PII, and admissions data. The group has published the data and explicitly states it will not be removed from public circulation.
Data the group says was taken
AI dossier — extracted from the leak post- applicant contact information
- student contact information
- significant PII
- admissions data
What the group claims
Institution with 440K records containing applicant and student contact information, PII, and admissions data.
The leak post
captured from the group's site```
______ __ _ _ _____ _
| ____| / _(_) |/ ____| | |
| |__ __ _| |_ _| | (___ __ _ _ _ __ _ __| |
| __| \ \/ / _| | |\___ \ / _` | | | |/ _` |/ _` |
| |____ > <| | | | |____) | (_| | |_| | (_| | (_| |
|______/_/\_\_| |_|_|_____/ \__, |\__,_|\__,_|\__,_|
| |
|_|
```
We have published all companies that have failed to meet an agreement with us. We'll be back soon with more breaches! Once your companys data is posted here, its NEVER leaving the public eye. Within minutes it will be copied, mirrored, archived, and shared across countless corners of the internet. Once that happens, there is no undo button. The payment we request of you is simply a rounding error compared to the legal fees, regulatory scrutiny, lost contracts, and reputational damage that follow a public data breach. Consider the cost of explaining this to your customers, your partners, your shareholders, and the press. Your customers expect you to protect their information. Your partners expect competence. Your investors expect stability. Once confidence is lost, i…Data the group says was taken
- applicant and student contact information
- PII
- admissions data
Screenshot of the leak post

Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

