LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › City government office in Van Listed by skira Ransomware Group

HIGH severityUnverified claimHow we verify

City government office in Van Listed by skira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 6, 2025
City government office in Van Listed by skira Ransomware Group

Reported March 6, 2025.

HIGH
Severity
March 6, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

A city government office in Van was listed by the skira ransomware group on March 06, 2025, after internal files were exfiltrated in a ransomware attack; the exact date of the intrusion has not been established. Anyone who may have interacted with the office should check for follow-up notices and change passwords or monitor accounts if advised.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Residents and employees connected to the City government office in Van may face real uncertainty after a ransomware group publicly listed the organisation as a victim. When a municipal body that handles everyday local services is named in such an incident, the practical concern is straightforward: internal files said to have been taken could include information that affects how people interact with city services, apply for permits, or manage personal records held by local government.

Public reporting places the listing on March 06, 2025. The number of people whose data may be involved remains unknown, and many operational details have not been confirmed. What is known so far is limited, yet the claim alone is enough to warrant careful attention from anyone who has dealt with the office.

Breaking down the breach

According to available information, the City government office in Van was listed by the skira ransomware group. The reported summary states that internal files were exfiltrated in a ransomware attack. No figure has been given for the volume of data, the number of systems affected, or the precise date the intrusion began. The method of initial access has not been disclosed, nor has any confirmation that encryption of systems actually occurred beyond the group’s claim of exfiltration.

The listing itself is the primary public marker of the incident. Because the group’s leak-site post is an unverified claim, it cannot be treated as independent confirmation that every asserted detail is accurate. People affected remain unknown, and no further technical indicators or official statements from the office have been included in the facts provided.

Who is skira?

Skira is a ransomware group that has operated in the public eye by maintaining a leak site where it names organisations it claims to have compromised. Like many contemporary ransomware actors, it is associated with double-extortion tactics: data is allegedly copied before systems are locked, and the threat of publication is used to pressure victims. The group has appeared in multiple listings of public-sector and private entities across different countries, typically posting short notices rather than detailed technical reports.

In this case the group claims the City government office in Van as a victim and asserts that internal files were taken. No additional statements attributed specifically to this incident—such as ransom demands, sample file lists, or deadlines—are present in the available facts. Background knowledge of the group’s general pattern does not extend to inventing claims unique to this listing.

Who is City government office in Van?

The City government office in Van, also referenced as van.bel.tr, is the municipal administrative body responsible for local governance in the city of Van, Turkey. It oversees core city functions that include urban planning, delivery of local public services, maintenance of public facilities, and related administrative work that keeps daily municipal operations running. As a local government entity it sits at the intersection of citizen services and internal record-keeping.

A breach involving such an office is consequential because municipal bodies routinely process information needed for residency matters, service applications, infrastructure projects, and staff administration. Even when the exact scope of an incident is unclear, the organisation’s role means that any compromise of internal systems can affect both residents who rely on city services and the continuity of those services themselves.

What data was at risk

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file categories, databases, or personal data fields has been disclosed. The number of people affected is listed as unknown.

Organisations of this kind typically hold a mix of administrative records, employee information, correspondence, planning documents, and data submitted by residents in the course of obtaining permits or services. Because the precise contents remain unconfirmed, it is not possible to state which specific categories were taken. Readers should treat any detailed inventory as unavailable until verified by the organisation or independent investigators.

Why it matters

For individuals, the risk is that personal or household information held by the city could surface in unwanted places, increasing the chance of targeted phishing, identity misuse, or unwanted contact. Even limited internal documents can reveal patterns of residency, service use, or financial interactions with local government that scammers later exploit.

For the organisation, the incident raises questions of operational continuity, public trust, and the cost of recovery. Municipal offices must continue delivering essential services while investigating what was accessed and whether systems remain secure. Because the scale is unknown, both residents and staff are left without clear guidance on whether their own records were among the files claimed to have been taken.

What to do if you're exposed

If you have had dealings with the City government office in Van—whether as a resident, employee, contractor, or service applicant—treat the listing as a prompt to review your own exposure. Monitor bank and credit activity for unexpected changes, be cautious of unsolicited messages that reference city services or personal details, and consider placing fraud alerts with relevant agencies if you hold Turkish identification or financial accounts. Change passwords on any accounts that reuse credentials you may have shared with municipal systems, and enable multi-factor authentication wherever it is available.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Doing so provides one concrete data point while official details remain limited. Stay alert for any formal notice from the city office itself; until then, the prudent course is heightened vigilance rather than panic.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCity government office in Van security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See City government office in Van’s full breach history →

More recent breaches

INNOVEX HOLDINGS CO., LTD Listed by skira Ransomware GroupNovember 18, 2025Dedicated Web Consultants, Inc Listed by skira Ransomware GroupMay 1, 2025Independent Title Agency, LLC Listed by skira Ransomware GroupApril 18, 2025Law Diary Listed by skira Ransomware GroupMarch 6, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the City government office in Van Listed by skira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by skira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram