Professional TestingCorporation (PTC) Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Professional TestingCorporation (PTC) has been listed by the Akira ransomware group, with internal files reported exfiltrated in the attack. The incident came to light on May 22, 2025; affected individuals should check the organisation’s notices and change passwords or monitor accounts if advised.
On May 22, 2025, the ransomware group known as akira listed Professional Testing Corporation (PTC) on its leak site, claiming to have exfiltrated internal files during an attack. Public detail on the incident remains limited: the number of people affected is unknown, and independent confirmation of the breach has not been provided in available records. For anyone who has worked with PTC as an employee, contractor, client, or test-taker, the practical stakes are immediate—personal and professional records may now sit outside the organisation’s control, raising the risk of identity misuse, targeted fraud, or unwanted disclosure of sensitive material.
Because PTC operates in testing and assessment services, the data it routinely handles can include identifiers, medical or accommodation details, contractual terms, and client project information. Even without a confirmed headcount or full inventory of what was taken, the mere claim of exfiltration means affected individuals should treat the possibility of exposure as real until proven otherwise.
What happened
According to the available record, Professional Testing Corporation (PTC) was listed by the akira ransomware group on May 22, 2025. The listing asserts that internal files were exfiltrated in a ransomware attack. The group further claims it intends to upload approximately 5 GB of corporate data. No public information confirms the precise date of initial access, the method of intrusion, whether systems were encrypted, or whether any ransom demand was paid or refused. The number of people affected is listed as unknown. Beyond the group’s own statement, independent verification of the scale or success of the claimed data theft has not been supplied in the facts at hand.
Who is akira?
Akira is a ransomware operation that has been active in recent years and is documented in open-source reporting for using a double-extortion model: encrypting systems while also stealing data and threatening to publish it if payment is not made. The group typically posts victim names on a dedicated leak site, often accompanied by sample file lists or volume claims, to increase pressure. Prior activity attributed to akira has targeted organisations across multiple sectors, including professional services, manufacturing, and education-related entities. These tactics are well-established public knowledge; however, any specific assertion that akira made about PTC—such as the volume of data or the categories of files—must be treated as the group’s unverified claim rather than confirmed fact.
Who is Professional TestingCorporation (PTC)?
Professional Testing Corporation (PTC) is described in the available summary as an established global leader in testing and assessment services. Organisations of this type design, administer, and score professional certification exams, licensure tests, and other high-stakes assessments for industries ranging from healthcare and finance to technical trades. In the ordinary course of business they hold candidate registration data, examination results, accommodation or medical documentation, employee records, client contracts, and project files. A breach involving such an organisation is consequential because the data often combines personal identifiers with professional credentials and confidential commercial information, creating both individual privacy risks and potential competitive or regulatory exposure for the firm and its clients.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. The akira group claims it will upload about 5 GB of corporate data and lists the following categories: employee personal documents, medical records, confidentiality agreements, contracts, client information, detailed financial data, and project data. These categories are presented solely as the group’s assertion; the exact contents of any stolen files remain unconfirmed by independent sources. Organisations that provide testing and assessment services typically retain precisely these kinds of records—employee HR files, candidate medical or disability accommodations, signed non-disclosure agreements, client engagement contracts, financial ledgers, and project documentation. Whether any or all of those materials were in fact allegedly taken from PTC cannot be verified from the public record alone.
What's at stake
For individuals whose information may be involved, the concrete risks include identity theft, phishing campaigns that reference real employment or testing history, and the possible public release of medical or financial details. Employees could face exposure of personal documents and medical records; clients and candidates could see contracts, project data, or assessment-related information surface. For PTC itself, the stakes include regulatory notification obligations, potential contractual liability to clients, reputational damage within the certification community, and the operational cost of investigation and remediation. Because the number of affected people is unknown and the precise file inventory is unconfirmed, both individuals and the organisation must operate under the assumption that sensitive material may already be outside their control.
Were you affected?
If you have ever been employed by PTC, sat an examination it administered, or done business with the company as a client or vendor, treat the possibility of exposure seriously. Practical first steps include:
- Monitor bank, credit-card, and credit-report activity for unexpected inquiries or accounts.
- Enable multi-factor authentication on email and financial accounts and change passwords that may have been reused.
- Watch for phishing messages that reference testing, employment, or contracts with PTC.
- Request free credit freezes or fraud alerts from the major credit bureaus if you believe personal identifiers were involved.
- Document any suspicious contact and report it to the appropriate authorities if fraud occurs.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Public detail on this incident remains limited; further official statements from PTC or law-enforcement agencies, if released, should be reviewed carefully for confirmation of scope and recommended actions.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Taylor Clay Products Listed by akira Ransomware GroupAlliance Roofing Listed by akira Ransomware GroupAmerican Beauty School Listed by akira Ransomware GroupIGI Global Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.