Ransomware victim disclosure
← All victimsMinistry of Education and Science of Ukraine
listed as mon.gov.ua · Claimed by Freecivilian · listed 3 years ago
Status timeline
- Listed
Dec 31, 2022
- Data leaked
At a glance
- Group
- Freecivilian
- Status
- Data leaked
- Country
- Ukraine
- Sector
- Government
- Listed on leak site
- Dec 31, 2022
About the victim
AI dossier — public-source company profileThe Ministry of Education and Science of Ukraine (mon.gov.ua) is the central executive body responsible for forming and implementing state policy in the fields of education, science, and innovation across Ukraine. It oversees primary, secondary, vocational, and higher education institutions throughout the country. The ministry operates under the Cabinet of Ministers of Ukraine and is headquartered in Kyiv.
- Industry
- Government – Education & Science Ministry
- Address
- 10 Peremohy Avenue, Kyiv, Ukraine
- Employees
- 1001-5000
- Founded
- 1917
Attack summary
Severity: high — The target is a national government ministry handling sensitive administrative, personnel, and citizen-related data. Freecivilian has a documented history of publishing Ukrainian government data; the 'data_published' status confirms actual exfiltration and public release, likely including PII and sensitive government records, though the exact volume and content are unconfirmed from available evidence.The Freecivilian group claims to have compromised and published data belonging to the Ukrainian Ministry of Education and Science; the disclosed status indicates data has been published, though no ransom was demanded and specific exfiltration or encryption details are absent from the captured post.
Data the group says was taken
AI dossier — extracted from the leak post- Government ministry records
- Employee/staff data
- Internal communications
- Education policy documents
- Citizen-facing administrative data
Sources
- Victim sitemon.gov
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
