mccn.org Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
mccn.org was listed by the safepay ransomware group on 6 June 2025, with internal files reported to have been exfiltrated in the attack; the actual date of the intrusion remains unknown. Individuals connected to the organisation should check any official notices and monitor their accounts for unusual activity.
On June 6, 2025, the organisation behind mccn.org was listed by the ransomware group known as safepay. Public reporting indicates that internal files were exfiltrated as part of a ransomware attack, though the number of people affected remains unknown and further details about the incident have not been disclosed.
The listing itself is a claim published by the group on its leak site. No independent confirmation of the full scope has been made public, leaving those connected to the organisation with limited verified information about what occurred and what data may have been involved.
What happened
According to available records, mccn.org was listed by the safepay ransomware group on June 6, 2025. The only data type named as exposed is internal files said to have been exfiltrated during a ransomware attack. No public details have been released about the method of intrusion, the precise timing of the compromise, the volume of data taken, or any ransom demand. The number of individuals potentially affected is listed as unknown. Beyond the group's claim that it holds exfiltrated internal files, the incident remains sparsely documented in open sources.
Who is safepay?
Safepay is a ransomware operation that has been active in recent years and is known for double-extortion tactics. Groups of this type typically gain access to a network, steal data, encrypt systems, and then threaten to publish the stolen material on a dedicated leak site if a ransom is not paid. Safepay maintains such a site where it posts victim names and, in some cases, sample files. Like other ransomware actors, it has targeted organisations across multiple sectors. In this instance, the group claims to have listed mccn.org and to have exfiltrated internal files; those assertions have not been independently verified in the public record.
Who is mccn.org?
mccn.org is the online presence of an educational institution focused on nursing and healthcare training. Organisations of this kind typically manage student records, faculty and staff information, academic files, clinical placement data, and administrative documents. Because they handle personal and sometimes sensitive health-related or educational information, a compromise can affect students, employees, alumni, and partner clinical sites. A ransomware incident involving such an entity raises concerns about the confidentiality of those records and the continuity of academic and clinical operations.
What data was at risk
The only category named in connection with the incident is internal files exfiltrated in a ransomware attack. Exact contents have not been disclosed. Institutions like mccn.org commonly hold student application and enrollment data, grades, contact details, employee personnel files, financial aid information, and operational documents. Whether any of those specific categories were among the files claimed by safepay is unconfirmed. Public detail on the precise nature and volume of the material remains limited.
Why it matters
When internal files leave an organisation's control, the people whose information appears in those files face practical risks. Contact details can be used for phishing or social-engineering attempts. Academic or employment records can be leveraged for identity-related fraud. Even if the full contents stay unpublished, the mere fact of exfiltration creates uncertainty for students, staff, and partners who must decide how to monitor their accounts and communications. For the organisation itself, a ransomware event can disrupt teaching schedules, clinical placements, and administrative services while also requiring costly recovery and notification efforts. Because the scale of this incident is still unknown, the concrete impact on individuals cannot yet be measured, but the potential for ongoing secondary misuse of any exposed data is real.
Were you affected?
If you have a connection to mccn.org—as a current or former student, employee, or partner—consider taking basic protective steps. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and treat unsolicited messages that reference the organisation with caution. Change passwords on any accounts that may have reused credentials associated with the institution. Because the exact data involved has not been confirmed, these measures remain precautionary rather than responses to a verified personal exposure. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets elsewhere.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
artcitydental.com Listed by safepay Ransomware Groupsmilecenterutah.com Listed by safepay Ransomware Grouphoodriverdentist.com Listed by safepay Ransomware Groupglendaleobgyn.com Listed by safepay Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the mccn.org Listed by safepay Ransomware Group →
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.