LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ministry of Foreign Affairs of Ukraine Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

Ministry of Foreign Affairs of Ukraine Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 6, 2025
Ministry of Foreign Affairs of Ukraine Listed by qilin Ransomware Group

Reported March 6, 2025.

HIGH
Severity
March 6, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ministry of Foreign Affairs of Ukraine was listed by the Qilin ransomware group on March 06, 2025, after internal files were exfiltrated in a ransomware attack. The number of individuals affected is not yet known; anyone who has interacted with the Ministry should monitor official statements and follow any guidance that may be issued.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 6 March 2025 a ransomware group known as qilin publicly listed the Ministry of Foreign Affairs of Ukraine on its leak site, claiming it had obtained and partially sold internal ministry data. For diplomats, staff, contractors and anyone whose personal details or correspondence may sit inside those files, the practical stakes are immediate: private messages, identity information and official records could be used for fraud, coercion or further targeting. The number of people affected remains unknown, and independent confirmation of the full scope is still limited.

What follows is a plain account of what has been reported, what is known about the actors involved, and the concrete steps people can take if they believe their information may have been exposed.

Inside the incident

According to the listing published by the group, the data of the Ministry of Foreign Affairs of Ukraine “ended up in our hands.” The group stated that part of the material had already been sold successfully and that the remainder included private correspondence, personal information, decrees and other internal files obtained in a ransomware attack. The listing was reported on 6 March 2025. No independent verification of the volume of data, the exact date of intrusion, or the technical method of access has been made public. The number of individuals whose records may be involved is listed as unknown. Public detail beyond the group’s own claims is therefore limited.

Who is qilin?

Qilin is a ransomware operation that functions as a ransomware-as-a-service (RaaS) group. It typically encrypts systems and simultaneously exfiltrates data so that it can threaten to publish or sell the material if a ransom is not paid—a double-extortion model used by many contemporary ransomware crews. The group has previously claimed attacks against organisations in multiple sectors and jurisdictions, often posting samples or full archives on a dedicated leak site to increase pressure. Its public statements about any given victim, including the Ministry of Foreign Affairs of Ukraine, remain claims until independently corroborated. No additional statements by qilin specifically about this incident beyond the listing summary have been included in the available facts.

Who is Ministry of Foreign Affairs of Ukraine?

The Ministry of Foreign Affairs of Ukraine is the government body responsible for the country’s diplomatic relations, consular services, international negotiations and the protection of Ukrainian interests abroad. Like any foreign ministry, it routinely handles sensitive diplomatic cables, personnel records, visa and passport-related data, correspondence with foreign governments and classified or restricted policy documents. A breach of such an institution carries consequences that extend beyond ordinary commercial data loss: it can affect the safety of staff posted overseas, the privacy of citizens seeking consular help, and the confidentiality of ongoing diplomatic work. The ministry operates in a high-threat environment, and any compromise of its internal systems is therefore of particular concern to those whose personal or professional details may be stored there.

The information in question

The group’s listing describes the material as internal files exfiltrated in a ransomware attack. It specifically names private correspondence, personal information, decrees and related records, and asserts that a portion of the data was sold. Exact file counts, the full range of data categories, and the identities of any individuals whose records appear have not been independently confirmed. Organisations of this type typically hold staff directories, contact details, travel and security clearances, diplomatic correspondence and administrative decrees; whether any or all of those categories are present in the claimed archive remains unverified. Public detail on the precise contents is therefore limited to the group’s own description.

Why it matters

For people whose data may be involved, the risks are concrete rather than abstract. Personal information can be used for identity fraud, targeted phishing or social-engineering attacks that exploit knowledge of an individual’s role or contacts. Private correspondence, if authentic, could expose sensitive discussions, travel plans or personal circumstances that adversaries might leverage. Official decrees and internal documents, if released, could reveal decision-making processes or operational details useful to hostile actors. For the ministry itself, the incident raises questions about the integrity of its systems and the potential need to notify partners, re-issue credentials or adjust diplomatic practices. Because the number of affected individuals is unknown and the full dataset has not been independently audited, the precise scale of these risks cannot yet be quantified.

What to do if you're exposed

If you have any connection to the Ministry of Foreign Affairs of Ukraine—current or former staff, contractors, family members of diplomats, or individuals who have supplied personal data for consular or official purposes—consider the following practical steps:

Official notifications, if any are issued by the ministry or Ukrainian authorities, should be followed carefully. Until fuller independent reporting emerges, the safest assumption is that any personal or correspondence data once held by the ministry could be in unauthorised hands.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMinistry of Foreign Affairs of Ukraine security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Ministry of Foreign Affairs of Ukraine’s full breach history →

More recent breaches

South Alabama Regional Planning Commission Listed by qilin Ransomware GroupOctober 2, 2025Office Of The Registrar Of Political Parties Listed by qilin Ransomware GroupSeptember 14, 2025Habitat for Humanity of Greater Sioux Falls, Inc. Listed by qilin Ransomware GroupMay 9, 2025Denton Regional Suicide Prevention Coalition Listed by qilin Ransomware GroupJanuary 31, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Ministry of Foreign Affairs of Ukraine Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram