certifiedinfosec.com Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
certifiedinfosec.com was listed by the apt73 ransomware group on April 27, 2026, after internal files were exfiltrated. Individuals connected to the organisation should check whether their information was exposed and take appropriate protective steps.
What happened
The incident centers on a listing placed by apt73 on its leak site. The entry identifies certifiedinfosec.com and asserts that internal files were taken. No independent confirmation of the exfiltration or subsequent publication of the material has been reported. The date the listing appeared is April 27, 2026. All other details, including the volume of data and the method of access, are undisclosed.
Who is apt73?
apt73 is a ransomware group that maintains a public leak site where it lists organizations it claims to have targeted. Such groups typically encrypt systems and threaten to release stolen data if ransom demands are not met. The listing of certifiedinfosec.com constitutes the group’s claim; no additional statements or evidence from apt73 about this specific case have been verified.
certifiedinfosec.com and its sector
Certified Information Security operates as a registered trade name for Certified Tech Trainers (CTT). Organizations in this sector provide training, certification, and related services in information security. They routinely hold records on course participants, training materials, and internal administrative documents. A breach at such an entity can expose operational information even when the exact contents remain unconfirmed.
The information in question
The only data type named in the listing is internal files exfiltrated in a ransomware attack. No inventory of specific file categories, record counts, or data fields has been released. Organizations of this type commonly maintain participant details, billing records, and proprietary training content, yet the precise material involved here is unconfirmed.
The real-world impact
Because the number of individuals affected is unknown and the contents of the files have not been described, the direct consequences for any one person cannot be quantified at present. Internal files may contain operational or contact information that could be used for further targeting or social-engineering attempts. The organization faces the standard risks associated with any ransomware incident, including potential operational disruption and reputational effects.
What to do if you're exposed
Monitor accounts linked to any training or certification records you hold with the organization. Watch for unusual login attempts or unsolicited contact that references the training provider. Review bank and credit statements for unexpected activity.
- Change passwords for any accounts associated with certifiedinfosec.com or CTT.
- Enable multi-factor authentication on email and financial services.
- Run a free exposure scan of your email address against known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
westernint.com Listed by apt73 Ransomware Grouptrinitesolutions.com Listed by apt73 Ransomware Groupjgpetrucci.com Listed by apt73 Ransomware Groupservicepower.com Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the certifiedinfosec.com Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.