nosm.ca Listed by dispossessor Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The nosm.ca Listed by dispossessor Ransomware Group (reported May 17, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On May 17, 2023, the Northern Ontario School of Medicine University, known online as nosm.ca, was listed by the ransomware group dispossessor. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.
The listing places a Canadian public medical university that trains physicians and supports care across Northern Ontario’s urban, rural, and remote communities into the scope of a claimed data-theft incident. What is confirmed so far is limited to the group’s claim and the description of internal files taken during the attack.
Inside the incident
According to available information, nosm.ca appeared on dispossessor’s listings on May 17, 2023. The reported summary describes the event as a ransomware attack in which internal files were allegedly exfiltrated. No public figure has been given for the volume of data, the duration of unauthorized access, the initial intrusion method, or whether systems were encrypted in addition to the theft of files. The number of individuals whose information may be involved is listed as unknown.
Because the primary public signal is the group’s own listing, the incident should be treated as a claimed compromise pending any fuller confirmation or detailed disclosure from the institution. Timing beyond the reported listing date, the precise scale of the intrusion, and technical indicators of how access was gained have not been made public in the material available.
Who is dispossessor?
Dispossessor is a ransomware group known for double-extortion operations: operators seek to encrypt victim environments while also copying data, then pressure the organization by threatening to publish the stolen material on a leak site if demands are not met. Like other groups in this category, dispossessor has used dedicated sites to name victims and, in some cases, to stage sample files or larger archives as proof of access.
Public tracking of the group has associated it with opportunistic targeting across sectors rather than a single industry focus. Claims posted on such sites are assertions by the actors themselves; they are not independent verification that every listed organization suffered the full scope of impact the group describes. In this case, the facts state that nosm.ca was listed and that internal files were exfiltrated in a ransomware attack; no additional victim-specific statements from the group beyond that listing are provided in the record.
Who is nosm.ca?
Northern Ontario School of Medicine University is a public medical university in the Canadian province of Ontario. Its mandate includes educating doctors and contributing to health care in Northern Ontario’s urban, rural, and remote communities. Institutions of this type typically operate campuses, clinical training partnerships, research activities, and administrative systems that support students, faculty, staff, and affiliated clinical sites.
A breach affecting a medical education and regional care-oriented university is consequential because such organizations routinely handle sensitive personal, academic, and health-related information, as well as operational records tied to training and community health initiatives. Disruption or exposure can affect not only the institution’s internal operations but also trust among students, educators, and the communities it serves.
What data was at risk
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as categories of personal data, student records, employee information, clinical or research files, or financial documents—has been disclosed in the available record. The number of people affected is unknown.
Organizations of this kind commonly hold student and applicant records, employee and faculty data, research materials, administrative correspondence, and sometimes information linked to clinical training or community health programs. Those are typical holdings for a public medical university; they are not confirmed contents of this incident. Exact file types, whether any regulated health information was included, and whether data were later published remain unconfirmed in the public facts provided.
Why it matters
When internal files leave an educational and health-oriented institution without authorization, affected individuals can face risks that include targeted phishing, identity misuse, or exposure of personal and professional details. Even when the precise data set is unknown, the combination of a university environment and a medical training mission means the potential sensitivity of records is higher than for many purely commercial breaches.
For the organization, a claimed ransomware incident with exfiltration can mean operational disruption, investigative and recovery costs, regulatory notification duties under Canadian privacy rules, and lasting questions from students, staff, and partner communities about how information is protected. Because the headcount of affected people is unknown and the file inventory is not public, the full human and institutional impact cannot yet be measured from open sources alone.
If your data was in this claimed breach
If you are a student, applicant, employee, faculty member, or partner who has dealt with Northern Ontario School of Medicine University, treat the incident as a prompt to tighten ordinary account hygiene. Use unique passwords, enable multi-factor authentication where available, and watch for unexpected messages that reference the school or request credentials or payments. Monitor financial and academic accounts for unfamiliar activity and consider credit or fraud alerts if you believe sensitive identifiers may have been involved.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Keep records of any suspicious contact, and follow official notices from the university should it issue guidance or confirmation about affected populations. Public detail on this listing remains limited; measured personal precautions are still warranted until clearer inventories are available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
chs.ca Listed by lockbit3 Ransomware Groupindependenceia.org Listed by dispossessor Ransomware Groupcsagh.org Listed by lockbit3 Ransomware Groupontariopork.on.ca Listed by dispossessor Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the nosm.ca Listed by dispossessor Ransomware Group →
Publicly posted by dispossessor — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.