Ransomware victim disclosure
← All victimsIlumno
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 17, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Jan 17, 2026
About the victim
AI dossier — public-source company profileIlumno is a Latin American education technology and managed services company that has operated for approximately 15 years, supporting prestigious higher education institutions across Latin America with student growth, virtual education, and learning management services. The company serves more than 200,000 active students and partners with universities to improve admissions, retention, and online program delivery. It is part of a larger global group with a mission to expand access to quality higher education.
- Industry
- Higher Education Technology & Managed Services
- Employees
- 201-500
- Founded
- 2009
Attack summary
Severity: high — Data has been confirmed published by the ransomware operator. Ilumno handles records for over 200,000 higher-education students, meaning significant PII (student personal and academic data) is likely at stake, along with institutional and financial records.Qilin claims to have attacked Ilumno and the disclosure status is 'data_published', indicating data has been exfiltrated and published; however, the truncated leak post does not specify the exact nature or volume of data stolen or whether encryption also occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Student records
- Employee/HR data
- Financial/administrative data
- Institutional partner data
- Learning management system data
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

