Medical University of the Americas Listed by nokoyawa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Medical University of the Americas Listed by nokoyawa Ransomware Group (reported May 20, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When a medical school appears on a ransomware group's leak site, the practical concern is straightforward: students, alumni, faculty, and staff may find that internal records about them have left the institution's control. For Medical University of the Americas, public reporting on 20 May 2023 stated that the nokoyawa ransomware group had listed the school and claimed to have exfiltrated internal files. How many people are affected remains unknown, and the precise contents of those files have not been detailed in the available record. That uncertainty itself is part of the stakes for anyone connected to the school.
What is known is limited to the listing and the claim of data theft in a ransomware attack. No confirmed count of victims, no inventory of file types beyond "internal files," and no independent verification of the group's assertions have been supplied in the public facts. People who studied or worked at the university, or who shared personal information with it, still have reason to treat the report seriously and to take basic protective steps while fuller detail is absent.
Inside the incident
On 20 May 2023 it was reported that Medical University of the Americas had been listed by the nokoyawa ransomware group. The available summary states that internal files were exfiltrated in a ransomware attack. The number of people affected is unknown. Timing of the intrusion itself, the initial access method, whether systems were encrypted, whether a ransom demand was made or paid, and whether any data was later published are all undisclosed in the facts at hand.
The listing on a ransomware leak site is a claim by the group, not an independently confirmed forensic finding. Public detail does not establish how the attackers gained entry, how long they remained inside the network, or what volume of material they removed. Until the organisation or investigators release further verified information, the incident rests on that reported listing and the stated exfiltration of internal files.
Inside nokoyawa
Nokoyawa is a ransomware operation that became publicly visible in 2022. Like many contemporary groups, it has been associated with double-extortion tactics: encrypting systems while also copying data and threatening to release it if payment is not made. The group has typically posted victim names on a dedicated leak site and has targeted organisations across multiple sectors rather than specialising in healthcare or education alone. Public reporting has linked nokoyawa to custom ransomware variants and to the use of common initial-access routes such as compromised credentials or exposed remote services, though specific tooling can vary by intrusion.
None of that general pattern proves what happened inside Medical University of the Americas. The group's listing of the school is a claim that internal files were taken; the facts do not include statements from nokoyawa beyond that listing, nor do they state that any promised leak materialised. Readers should treat the attribution as the group's assertion unless and until it is corroborated by the victim or by independent analysis.
About Medical University of the Americas
Medical University of the Americas is a private, for-profit offshore medical school located in Charlestown, Nevis. It is owned by R3 Education, Inc., which also owns St. Matthew's University and the Saba University School of Medicine. Students are drawn primarily from the United States and Canada and typically return to those countries for clinical training and licensure pathways. As a medical school, the institution sits at the intersection of higher education and healthcare training: it holds academic records, identity and contact data, financial and admissions information, and often health-related or background documentation required for clinical placements.
A breach affecting such an organisation is consequential because the population it serves—prospective and current students, graduates, faculty, and administrative staff—depends on the confidentiality of records that can affect licensing, employment, credit, and personal privacy for years. Offshore medical schools that enrol large numbers of North American students also process cross-border personal data, which can complicate notification and remediation when something goes wrong.
The information in question
The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No further breakdown—student records, employee files, financial documents, emails, or clinical-placement data—is provided. Exact contents therefore remain unconfirmed.
Organisations of this type ordinarily hold names, addresses, dates of birth, government identification numbers, academic transcripts, admissions and financial-aid files, tuition and payment records, and correspondence. They may also retain health or immunisation information required for clinical work, as well as credentials and personnel files for faculty and staff. Whether any of those categories were among the files nokoyawa claims to have taken is not established in the public record. Until a detailed disclosure appears, it is accurate only to say that internal files were reported as stolen and that the usual holdings of a medical school illustrate what could be at risk.
The real-world impact
For individuals, the concrete risks are familiar even when the file list is incomplete. Stolen academic or identity data can be used for impersonation, fraudulent loan or credit applications, or targeted phishing that references real enrolment or employment details. If financial or government identifiers were present, the window for account takeover or tax-related fraud can last well beyond the initial incident. Students and alumni who later apply for residencies, licences, or jobs may also face secondary friction if their personal information circulates in criminal markets.
For the university, the impact includes operational disruption if systems were encrypted, the cost of investigation and recovery, potential regulatory and contractual notification duties, and erosion of trust among applicants and partners. Because the number of people affected is unknown and the data types are not itemised, both the individual and institutional consequences remain partly unquantified. That does not reduce the need for caution; it simply means responses should be proportionate to what is actually known.
What to do if you're exposed
If you studied at, worked for, or applied to Medical University of the Americas, treat the report as a prompt to tighten basic defences. Monitor bank, credit-card, and credit-report activity for unfamiliar accounts or inquiries. Be sceptical of unsolicited messages that cite the school, your programme, or supposed refund or verification processes. Change passwords on accounts that reused credentials tied to university email, and enable multi-factor authentication wherever it is offered. If you later receive a formal notification from the institution naming specific data elements, follow the guidance in that notice, including any offer of credit monitoring.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That check does not confirm or deny involvement in this incident, but it can surface other exposures that deserve the same practical attention.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Canadian Nurses Association Listed by snatch Ransomware GroupGaston College Listed by snatch Ransomware GroupTampa General Hospital Listed by nokoyawa Ransomware GroupGlobal Remote Services Listed by nokoyawa Ransomware GroupLatest breaches
Publicly posted by nokoyawa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.