Gitlabs: Chalmers tekniska högskola, Fligno, 3SS Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Gitlabs: Chalmers tekniska högskola, Fligno, and 3SS were listed by the fog Ransomware Group on 7 February 2025, with internal files reported as exfiltrated from an undisclosed number of people. Individuals connected to any of the named organisations should review the group’s claims and follow their organisation’s security guidance.
On 7 February 2025, the ransomware group known as fog listed Gitlabs: Chalmers tekniska högskola, Fligno, 3SS on its public leak site. The group claims to have stolen internal data in a ransomware attack that involved the exfiltration of internal files. The number of people affected is unknown, and further details about timing, scale, and method remain undisclosed in public reporting. The listing itself constitutes an unverified claim by the group rather than independent confirmation of compromise.
Incidents of this type matter because they can place internal organisational material at risk of wider exposure, with potential consequences for anyone whose information appears in the files. Public information about this specific event is limited to the leak-site listing and the group’s assertion that internal data was taken.
Inside the incident
Public reporting states that Gitlabs: Chalmers tekniska högskola, Fligno, 3SS appeared on the fog ransomware leak site on 7 February 2025. According to the available summary, the group claims to have stolen internal data and that internal files were exfiltrated during a ransomware attack. No confirmed figures have been released for the volume of data, the precise date of any intrusion, the initial access method, or the number of individuals whose information may be involved. The people-affected count is listed as unknown. Beyond the leak-site claim, no independent verification of the breach’s scope or technical details has been provided in the facts available.
Ransomware incidents typically involve encryption of systems combined with data theft for leverage, but the facts for this case do not describe whether encryption occurred, whether a ransom demand was made, or whether any negotiation took place. All such elements remain undisclosed.
The group behind it: fog
Fog is a ransomware group that has operated publicly since mid-2024, employing a double-extortion model in which data is first stolen and then systems are encrypted, with the threat of publication used to pressure victims. The group maintains a leak site on which it lists organisations it claims to have compromised and, in some cases, releases sample files or larger archives. Public reporting on fog has documented attacks against a range of sectors, often involving the exfiltration of internal documents, databases, and other corporate material before encryption. The group’s listings are self-reported claims; they do not automatically constitute proof that every named organisation was successfully breached or that the full volume of data asserted was taken.
In this instance, fog’s listing of Gitlabs: Chalmers tekniska högskola, Fligno, 3SS is presented solely as the group’s claim that internal data was stolen. No additional statements from the group about this specific victim—such as file counts, ransom amounts, or deadlines—are contained in the available facts, and none should be assumed.
Who is Gitlabs: Chalmers tekniska högskola, Fligno, 3SS?
The named entity appears as a combined listing that includes Chalmers tekniska högskola (Chalmers University of Technology), a major Swedish public research university focused on engineering, technology, and natural sciences, together with Fligno and 3SS. Universities of this type routinely maintain extensive digital systems for research collaboration, student administration, employee records, and project management. Software-development and technology firms such as those suggested by the additional names typically hold source code, internal documentation, client information, and operational data. The “Gitlabs” reference in the listing title points to the possible involvement of self-hosted or managed GitLab repositories, which are commonly used for version control, issue tracking, and collaborative development.
A breach affecting such an organisation is consequential because academic institutions and technology companies store both personal data belonging to students, staff, and partners and proprietary research or commercial material. Exposure can disrupt operations, compromise intellectual property, and create downstream risks for individuals whose details appear in the systems.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack and that the group claims to have stolen internal data. No further breakdown of file types, databases, or specific categories of personal information has been disclosed. Exact contents therefore remain unconfirmed.
Organisations of this kind—universities and technology firms—commonly hold employee and student records, research data, source-code repositories, internal correspondence, financial documents, and access credentials. GitLab environments in particular may contain project histories, commit logs, and configuration files. While these categories represent typical holdings, it is not established that any particular subset was present in the material the group claims to have taken. Readers should treat any assertion of specific data types beyond “internal files” as unconfirmed.
Why it matters
For individuals whose information may have been among the internal files, the primary risks include potential misuse of personal details for phishing, identity fraud, or social-engineering attempts. Even limited internal documents can contain names, email addresses, contact information, or project affiliations that enable more targeted follow-on activity. For the organisation itself, the consequences can include operational disruption, loss of confidentiality around research or commercial work, regulatory notification obligations, and the need to investigate and remediate affected systems.
Because the number of people affected is unknown and the precise data set is undisclosed, the full extent of individual impact cannot yet be quantified. The incident nonetheless illustrates the broader pattern in which ransomware groups use leak sites to amplify pressure, leaving organisations and the people connected to them to manage uncertainty until more definitive information emerges.
If your data was in this claimed breach
If you have a connection to Chalmers tekniska högskola, Fligno, 3SS, or related GitLab environments—whether as a student, employee, contractor, or collaborator—consider practical steps. Monitor official communications from the organisation for any confirmation or guidance. Review account security on systems you use with them, enable multi-factor authentication where available, and remain alert to unexpected messages that reference internal projects or personal details. Change passwords on any accounts that may have shared credentials with the affected environment. Keep records of any suspicious contact that appears linked to the incident.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Such checks provide an additional layer of visibility while official details about this particular listing remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Newtown Friends School (newtownfriends.org) Listed by fog Ransomware GroupEl Camino Real Academy (elcaminorealacademy) Listed by fog Ransomware GroupGitlabs: Next TI, VISEO, Hochschule Trier Listed by fog Ransomware GroupGreencastle-Antrim Senior High School (gcasd.org) Listed by fog Ransomware GroupLatest breaches
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.