LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ministry of Education Listed by N0n Ransomware Group

HIGH severityUnverified claimHow we verify

Ministry of Education Listed by N0n Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 18, 2026
Ministry of Education Listed by N0n Ransomware Group

Reported September 18, 2026.

HIGH
Severity
September 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ministry of Education was listed by the N0n ransomware group on September 18, 2026; the group claims it obtained data belonging to an undisclosed number of individuals. Anyone who may have records with the Ministry should check for unusual activity and consider steps to protect their personal information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as N0n has listed Argentina’s Ministry of Education on its leak site, with the listing dated September 18, 2026. The group claims it will publish material tied to ministry systems if no settlement is reached. Public detail is limited: the number of people who might be affected is unknown, and the listing does not give a confirmed inventory of personal records. The ministry has not publicly confirmed the claim as of writing.

For students, families, teachers, and anyone who has used national education platforms, the practical stake is straightforward. If systems that handle scholarships, certificates, school materials, or related services were involved, personal and administrative information could be at risk of misuse. Nothing in the public listing proves that any individual’s file is already circulating; the responsible response is to treat the claim as unverified and to take measured precautions while official information remains scarce.

What the listing says

According to the N0n listing, the target is described as a government education body in Argentina. The group states that, if no settlement is reached, it will publish what it describes as the complete network-security configuration of the ministry network; about 1.08 million connection records said to relate to systems including the national library (BNM), a school-book selection platform, scholarship systems (becasprogresar), titulosvalidez, certificadosinfd, and sitrared; and material it characterises as evidence of a Monero cryptocurrency miner operating inside the ministry network. The listing also asserts that the ministry network is under a total blackout until settlement.

Timing beyond the reported listing date of September 18, 2026, the method of any intrusion, and independent verification of scale or impact are undisclosed in the material provided. People affected are listed as unknown. Data types are not disclosed as a confirmed personal-data inventory; the bullet points above are the group’s own description of what it says it holds or will publish. Those descriptions should be read as attacker claims, not as an audited breach report.

Who is N0n?

N0n is known publicly as a ransomware and extortion-style actor that pressures organisations by threatening to release stolen material on a leak site. Groups in this category typically combine system disruption with public listings designed to force payment, and they often advertise technical artefacts, internal documents, or large file sets to increase leverage. How N0n operates in general—leak-site pressure, claims of network access, and timed publication threats—is part of the well-documented pattern of modern ransomware crews.

For this specific listing, only what appears on the group’s site about the Ministry of Education should be attributed to N0n. The group claims access and threatens publication of configuration data, connection records tied to named education-related systems, and alleged miner evidence. Those claims have not been confirmed by the ministry or by an independent authority in the facts available here. Leak-site posts can be exaggerated, incomplete, recycled, or false; a listing establishes that a claim was made, not that every detail is accurate.

Who is Ministry of Education?

A national ministry of education is the central government body responsible for education policy, oversight of schools and related programmes, and often the digital platforms that support students, teachers, and administrative processes. In Argentina, such a ministry sits at the intersection of public administration and services that millions of people may touch over a lifetime of schooling, certification, and financial support for study.

Organisations in this sector typically run or oversee systems for enrolment-related processes, credentials, scholarships, libraries, and other education infrastructure. A credible compromise of that environment would matter because the data and services involved are tied to identity, eligibility for benefits, academic records, and trust in public institutions. A leak-site listing alone does not prove that those systems were compromised; it does explain why the claim draws attention and why people connected to education services watch for official updates.

What data was at risk

The facts do not name reportedly exposed personal data types. The listing’s marketing language focuses on network-security configuration, a large volume of connection records linked to named platforms, and alleged evidence of cryptocurrency mining—not a verified catalogue of names, national ID numbers, or full student files. Exact contents remain unconfirmed.

If files or logs from education and scholarship-related systems were taken, ministries and similar bodies typically hold or process information such as identity and contact details, academic or administrative identifiers, scholarship or benefit-related data, and technical logs that can reveal who connected to which service and when. Connection records can sometimes be sensitive in aggregate even when they are not full profile dumps. None of that should be read as a statement that those categories were actually exfiltrated in this case; it is conditional context for what is often at stake in this sector when a claim of this kind appears.

The real-world impact

For individuals, the conditional risks are familiar: if personal or account-related data were involved, possible outcomes include targeted phishing that references education or scholarship services, attempts to reset accounts, fraud against benefit programmes, or long-term misuse of identity details. Connection logs, if genuine and detailed, could help an attacker understand usage patterns of public platforms. Configuration data, if real, is more an operational concern for defenders than a direct consumer dossier, but it can aid further intrusion attempts in other incidents.

For the organisation, an extortion listing creates reputational and operational pressure regardless of eventual verification. The group’s claim of a “total blackout until settlement” is an assertion of disruption; whether services were actually interrupted, and to what extent, is not independently established in the facts given. Staff, partner schools, and the public may face uncertainty until authorities or the ministry communicate clearly. A listing does not by itself establish negligence, security culture, or engineering failure; it establishes that an extortion crew chose to name the ministry and to describe certain materials.

What to do now

Treat the N0n listing as an unverified claim. Prefer official notices from the Ministry of Education or relevant Argentine authorities over screenshots and leak-site text. If you use ministry-linked services—scholarships, certificates, library or school platforms—watch for unusual emails or messages that pressure you to click, pay, or hand over codes. Use unique passwords and multi-factor authentication where those services offer them. If you suspect account misuse, change passwords from a device you trust and contact the service’s official support channels.

If personal data were involved, monitor bank and benefit-related accounts for unexpected activity and be cautious with unsolicited calls or messages that reference education records. Keep expectations realistic: people affected are unknown, and data types are not confirmed. As a simple extra check, you can run a free exposure scan of your email to see whether your address has already appeared in known breach datasets, then tighten security on any accounts that reuse that address or password.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyMinistry of Education security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Ministry of Education’s full breach history →

More recent breaches

Precision Facades Ltd Listed by N0n Ransomware GroupSeptember 29, 2026Dediserve Ltd Listed by N0n Ransomware GroupSeptember 28, 2026AstraZeneca Türkiye Listed by N0n Ransomware GroupSeptember 18, 2026Konnatus (usucapião legal services) Listed by N0n Ransomware GroupSeptember 18, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Ministry of Education Listed by N0n Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by n0n — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram