LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › carc.gov.jo Listed by funksec Ransomware Group

HIGH severityUnverified claimHow we verify

carc.gov.jo Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 9, 2025
carc.gov.jo Listed by funksec Ransomware Group

Reported January 9, 2025.

HIGH
Severity
January 9, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

carc.gov.jo was listed by the funksec ransomware group on January 09, 2025, after internal files were exfiltrated in a ransomware attack. The number of individuals affected is not yet known; anyone who has interacted with the organisation should monitor accounts and follow any guidance it may issue.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On January 09, 2025, the website carc.gov.jo, which belongs to Jordan’s Civil Aviation Regulatory Commission, was listed by the ransomware group funksec. Public reporting indicates that the group claims to have carried out a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and further operational details have not been disclosed.

This listing places a national aviation regulator among the organisations whose systems have been claimed as compromised by a ransomware actor. Because the commission oversees safety, security and regulatory standards for civil aviation in Jordan, any confirmed exposure of its internal material would carry implications for both institutional operations and public confidence in the sector.

Breaking down the breach

According to available information, carc.gov.jo was listed by funksec on or around January 09, 2025. The reported summary characterises the incident as a ransomware attack in which internal files were allegedly exfiltrated. No confirmed figures have been released for the volume of data taken, the precise date of initial access, the method of intrusion, or the number of individuals whose information may have been involved. Public detail on whether systems were encrypted, whether a ransom demand was issued, or whether any recovery has occurred is limited. The listing itself constitutes a claim by the group rather than an independently verified confirmation of every asserted detail.

In the absence of official statements from the organisation or from Jordanian authorities detailing forensic findings, the known facts remain confined to the reported listing and the description of internal-file exfiltration. Timing beyond the January 09, 2025 report date, scale, and technical vectors are undisclosed.

The group behind it: funksec

Funksec is a ransomware group that has operated a public leak site on which it lists organisations it claims to have compromised. Like other actors in this category, it typically combines data theft with encryption pressure, threatening to publish stolen material if payment is not made. Public reporting on the group has noted its relatively recent emergence and its practice of posting victim names alongside purported samples or descriptions of taken data. The group’s listings are claims; they do not by themselves constitute proof that every asserted detail is accurate or that the full scope of any given intrusion matches the group’s statements.

In this instance, funksec’s listing of carc.gov.jo is presented as an unverified claim that internal files were exfiltrated during a ransomware attack. No additional statements attributed specifically to the group about this victim—beyond the fact of the listing and the characterisation of the attack—appear in the available record. Established patterns associated with the group include opportunistic targeting across sectors and the use of leak-site pressure, but those general tactics do not supply missing specifics about the Jordanian incident.

carc.gov.jo and its sector

Carc.gov.jo is the online presence of the Civil Aviation Regulatory Commission of Jordan. The commission is responsible for regulating civil aviation activities inside the country, setting and enforcing safety and security standards, overseeing air navigation and airport requirements, and developing regulatory frameworks intended to support safe and efficient aviation services. Organisations of this type routinely handle technical standards documentation, licensing and certification records, inspection reports, correspondence with operators and international bodies, and internal administrative material.

A breach affecting a national aviation regulator is consequential because the sector underpins passenger transport, cargo movement, and national connectivity. Even when the precise contents of any stolen material remain unconfirmed, the potential exposure of regulatory or operational information can raise questions about continuity of oversight functions and about the security posture of systems that support safety-critical domains.

What data was at risk

The facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No further breakdown—such as categories of personal data, financial records, technical schematics, or employee information—has been disclosed. The number of people affected is listed as unknown.

Organisations performing civil-aviation regulation typically maintain records that can include personnel details, operator licensing data, inspection findings, security-related correspondence, and internal policy documents. Whether any of those categories were among the files claimed by funksec is unconfirmed. Exact contents therefore remain unconfirmed; statements about specific data types beyond the generic description of internal files would exceed the public record.

Why it matters

For individuals whose information might have been present in internal systems, the principal risks are secondary misuse of any personal or professional details that could later surface, identity-related fraud if contact or identification data were included, and the general uncertainty that accompanies an unquantified exposure. Because the scale and precise composition of the material are unknown, the concrete impact on any given person cannot yet be measured.

For the organisation itself, the incident—if the group’s claims prove accurate—raises operational and reputational considerations: potential disruption to regulatory workflows, the need to assess whether safety- or security-related material was involved, and the requirement to communicate with stakeholders and partner agencies. Aviation regulators operate in an environment where trust in the integrity of oversight processes is essential; even limited public confirmation of data theft can prompt scrutiny of cyber-defence practices across the sector. None of these consequences should be read as an established finding of negligence; they are the ordinary downstream effects that follow any credible claim of ransomware-driven exfiltration against a public regulatory body.

If your data was in this claimed breach

If you have had dealings with Jordan’s Civil Aviation Regulatory Commission—whether as staff, a licensed operator, a contractor, or a member of the public who submitted personal information—consider basic protective steps. Monitor financial and email accounts for unexpected activity, enable multi-factor authentication wherever available, and treat unsolicited messages that reference aviation licensing or official correspondence with caution. Change passwords on any accounts that reused credentials potentially stored in organisational systems. Because the exact data set remains undisclosed, these measures are precautionary rather than responses to confirmed personal exposure.

Readers can also run a free exposure scan of their email address against known breach corpora to check whether that address has already appeared in publicly documented incidents. Such checks do not prove or disprove involvement in this specific event, but they provide a practical starting point for personal vigilance while official details, if any, continue to emerge.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companycarc.gov.jo security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See carc.gov.jo’s full breach history →

More recent breaches

gstpam.org Listed by babuk2 Ransomware GroupJanuary 27, 2025pbos.gov.pk Listed by babuk2 Ransomware GroupJanuary 27, 2025rtdc.gov.mn Listed by babuk2 Ransomware GroupJanuary 27, 2025skopje.gov.mk Listed by babuk2 Ransomware GroupJanuary 27, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the carc.gov.jo Listed by funksec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by funksec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram