Coop UQAM Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Coop UQAM has been listed by the Rhysida ransomware group after internal files were exfiltrated in an attack. The incident was disclosed on 29 April 2025; anyone connected to the organization should check for official updates and change any exposed credentials.
Ransomware groups continue to target educational and cooperative institutions that sit at the intersection of student life, campus commerce and personal membership data. In that landscape, listings on criminal leak sites have become a routine way for attackers to pressure organisations and signal that stolen material may be published. On 29 April 2025, Coop UQAM appeared on such a listing attributed to the Rhysida ransomware group, which claimed to have exfiltrated internal files during a ransomware attack. Public detail remains limited; the number of people affected is unknown, and no independent confirmation of the full scope has been released. For members, students and staff who rely on the cooperative’s services, the listing nonetheless raises concrete questions about what may have been taken and what practical steps they should take.
This article sets out only what is known from the reported facts, places the claim in the context of Rhysida’s established methods, and explains why a breach at a university-linked cooperative can matter even when exact data types and victim counts stay undisclosed.
Breaking down the breach
According to the reported information, Coop UQAM was listed by the Rhysida ransomware group on 29 April 2025. The group’s claim is that internal files were exfiltrated in a ransomware attack. No public figure has been given for the number of people affected, and the precise method of initial access, the volume of data taken, and any ransom demand remain undisclosed. The listing itself constitutes an unverified claim by the threat actor; independent confirmation of the intrusion or of the contents of any stolen material has not been provided in the available facts.
What is stated is that the incident involved ransomware and the exfiltration of internal files. Beyond that single characterisation, timing details such as when the intrusion began, how long attackers remained inside the network, or whether systems were encrypted as well as data stolen are not part of the public record. Readers should therefore treat the episode as a claimed compromise whose full technical and operational contours have not been released.
The group behind it: rhysida
Rhysida is a ransomware operation that has been publicly documented since 2023. Like many contemporary groups, it typically employs a double-extortion model: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if payment is not made. The group has previously listed organisations across education, healthcare, government and commercial sectors, using the visibility of those listings to increase pressure. Its operators have been observed using common initial-access techniques such as phishing, exploitation of exposed remote services and abuse of legitimate remote-management tools, though the specific vector used against any individual victim is rarely confirmed in open sources.
In this case the facts state only that Coop UQAM was listed and that the group claims internal files were exfiltrated. No additional statements attributed to Rhysida about this particular victim—such as sample files, ransom amounts or deadlines—appear in the reported information. The listing should therefore be read as the group’s assertion rather than as independently verified fact.
Coop UQAM and its sector
Coop UQAM is described as one of the largest school-based cooperatives in Quebec. It is located in the heart of the Université du Québec à Montréal (UQAM) campus in downtown Montreal and primarily serves university customers while also allowing individuals and businesses to become members and use its services. University cooperatives of this type commonly operate bookstores, supply shops, food services and membership programmes that sit close to student and staff daily life.
Because such organisations handle membership records, purchase histories, campus-related transactions and, in many cases, contact and payment details, they form part of the broader educational and campus-services sector that ransomware groups have repeatedly targeted. A breach claim against a cooperative of this size is consequential not only for the organisation’s operations but for the large community of students, faculty, staff and external members who interact with it regularly.
What data was at risk
The reported facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No further breakdown—such as membership databases, financial records, employee files or customer contact lists—is provided. Exact contents therefore remain unconfirmed.
Organisations of this kind typically hold membership information, transaction and purchase data, staff and volunteer records, and operational documents related to campus retail and services. Whether any of those categories were among the files Rhysida claims to have taken cannot be established from the available information. Readers should not assume specific data types were compromised; they should simply recognise that internal files of an unspecified nature are alleged to have left the organisation’s control.
What's at stake
For individuals, the principal risks associated with any exfiltration of internal cooperative files include potential exposure of personal contact details, membership identifiers or transaction history if such records were among the stolen material. That exposure can enable targeted phishing, social-engineering attempts that reference campus life, or identity-related fraud. Because the number of people affected is unknown and the precise data types are undisclosed, the scale of personal impact cannot yet be measured.
For Coop UQAM itself, a ransomware incident that includes data theft can disrupt day-to-day retail and membership operations, impose recovery and forensic costs, and damage trust among the university community it serves. Even when encryption is reversed or systems are restored, the possibility that internal files remain in criminal hands creates an ongoing residual risk of later publication or resale. These consequences are real but, on present information, unquantified.
Were you affected?
If you are a member, student, staff member or customer of Coop UQAM, treat the listing as a prompt for ordinary caution rather than confirmed personal compromise. Monitor financial and membership accounts for unexpected activity, be alert to phishing messages that reference the cooperative or UQAM, and consider changing passwords used for any Coop UQAM-related services, especially if those passwords were reused elsewhere. Enable multi-factor authentication wherever it is offered.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention. Public detail on the Coop UQAM listing remains limited; further official statements from the organisation, if released, will be the most reliable source of additional guidance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Collge Superieur De Montreal Listed by rhysida Ransomware GroupPhoenix Art Museum Listed by rhysida Ransomware GroupYOKOSUKA GAKUIN Listed by rhysida Ransomware GroupSt. Joseph's Healthcare Hamilton Listed by rhysida Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Coop UQAM Listed by rhysida Ransomware Group →
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.