LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Qeco/coeq Listed by rhysida Ransomware Group

HIGH severityUnverified claimHow we verify

Qeco/coeq Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 10, 2024
Qeco/coeq Listed by rhysida Ransomware Group

Reported September 10, 2024.

HIGH
Severity
September 10, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On 10 September 2024, the Qualifications Evaluation Council of Ontario (QECO/COEQ) was listed by the Rhysida ransomware group as having had internal files exfiltrated. Individuals whose information may have been held by the organization should check QECO’s notices and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 10, 2024, the Qualifications Evaluation Council of Ontario, known as Qeco or coeq, was listed by the rhysida ransomware group. Public reporting indicates that internal files were exfiltrated in a ransomware attack, though the number of people affected remains unknown and further details about the incident have not been disclosed. This matters because Qeco administers the evaluation of teacher qualifications used for salary purposes across Ontario’s education sector, handling records that can affect educators’ professional standing and compensation.

The listing itself is a claim by the threat actor rather than an independently verified confirmation of every asserted detail. What is established so far is limited: an organization responsible for objective qualification assessments was named on a ransomware leak site after an apparent data-exfiltration event.

What happened

According to available public information, Qeco/coeq was listed by the rhysida ransomware group on September 10, 2024. The reported summary states that internal files were exfiltrated in a ransomware attack. No further specifics have been released about the precise timing of the intrusion, the technical method used to gain access, the volume of data taken, or any ransom demand. The number of individuals whose information may have been involved is listed as unknown. Public detail is therefore limited to the fact of the listing and the description of internal-file exfiltration; claims of broader impact or specific file contents remain unconfirmed outside the group’s own assertions.

The group behind it: rhysida

Rhysida is a ransomware operation that has been publicly documented since mid-2023. The group typically employs a double-extortion model: it encrypts systems and simultaneously steals data, then threatens to publish the stolen material on a dedicated leak site if payment is not made. Rhysida has previously targeted a range of sectors, including education, healthcare, government, and private enterprise, often posting victim names and sample files to pressure organizations. Its operators are known to use standard ransomware tooling combined with data-theft techniques, and they maintain a Tor-based site where they list claimed victims. In this case, the appearance of Qeco/coeq on that site constitutes the group’s claim that it successfully exfiltrated internal files; independent verification of the full scope has not been published in the available record.

Who is Qeco/coeq?

Qeco, also referred to as coeq or the Qualifications Evaluation Council of Ontario, was founded in 1969 by the Ontario English Catholic Teachers’ Association (OECTA), the Elementary Teachers’ Federation of Ontario (then comprising FWTAO and OPSTF), and the Association des enseignantes et des enseignants franco-ontariens (AEFO). Its core function is to provide and objectively administer the evaluation of teacher qualifications for salary purposes. Organizations of this type maintain records of educators’ credentials, course completions, and related professional documentation so that school boards can place teachers on the correct salary grids. Because these evaluations directly influence compensation and career progression for teachers across Ontario, the body holds sensitive professional and personal information that is consequential both to individual educators and to the wider public-education system.

What was likely exposed

The facts state that internal files were exfiltrated in the ransomware attack. No more granular inventory of data types—such as specific categories of personal identifiers, salary records, or credential documents—has been disclosed. Organizations that evaluate teacher qualifications typically hold materials including names, contact details, educational transcripts, certification histories, and correspondence related to salary-category placements. Whether any or all of those categories were among the internal files taken in this incident remains unconfirmed. Public reporting does not name exact file names, record counts, or data fields, so any assumption about precise contents would be speculative.

Why it matters

For educators whose records may have been involved, the primary risks are identity-related misuse and professional disruption. Stolen internal files could contain enough personal and credential information to enable targeted phishing, fraudulent applications, or attempts to alter salary-related documentation. Even without confirmed identity-theft cases, the mere exposure of professional evaluation data can create lasting uncertainty for individuals who rely on accurate qualification records for employment and pay. For Qeco itself, the incident raises operational and reputational questions: the organization must determine the integrity of its systems, notify affected parties if required, and restore confidence that qualification assessments remain secure and objective. Because the number of people affected is unknown, the full scale of individual impact cannot yet be measured, but the nature of the data typically held by such a body makes the event material to Ontario’s teaching workforce.

If your data was in this claimed breach

If you are a teacher or education professional who has submitted materials to Qeco for qualification evaluation, treat the possibility of exposure seriously even while exact contents remain unconfirmed. Begin by monitoring financial and professional accounts for unusual activity, and consider placing fraud alerts with credit-reporting agencies if you believe sensitive identifiers may have been involved. Change passwords on any accounts that reuse credentials linked to your professional email, and enable multi-factor authentication wherever available. Review correspondence from Qeco or your school board for official notifications about the incident. As a practical next step, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; such a scan provides an additional data point but does not replace official guidance from the organization itself. Continue to follow any updates released by Qeco or relevant authorities rather than relying solely on third-party claims.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyQualifications Evaluation Council of Ontario security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Qualifications Evaluation Council of Ontario’s full breach history →

More recent breaches

Rutherford County Schools Listed by rhysida Ransomware GroupNovember 25, 2024Bishop Ireton High School Listed by interlock Ransomware GroupNovember 20, 2024Vermilion Parish School System Listed by rhysida Ransomware GroupOctober 7, 2024Shenango Area School District Listed by rhysida Ransomware GroupSeptember 26, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Qeco/coeq Listed by rhysida Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by rhysida — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram