skirball.org Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
skirball.org has been listed by the Qilin ransomware group, which claims to have exfiltrated internal files in an attack on the organisation. The listing was reported on 22 May 2025; the exact date of the intrusion has not been established. Individuals who may have shared data with skirball.org should verify whether their information is affected and take appropriate protective steps.
People connected to the Skirball Cultural Center—staff, visitors, donors, partners, or anyone whose details sit in its systems—face a practical concern: a ransomware group has publicly claimed to have taken internal files and set a date to release them. When an organisation that hosts cultural programs and community gatherings appears on a leak site, the immediate question is whether personal or operational information could be exposed and what that means for everyday security.
Public reporting so far is limited. The listing attributes the incident to the Qilin ransomware group, names the organisation as skirball.org, and states that internal files were exfiltrated. The number of people affected remains unknown, and the precise contents of the files have not been independently confirmed. What is known is the claim itself and the stated release timeline.
What happened
On or around 22 May 2025, skirball.org was listed by the Qilin ransomware group. According to the group’s claim, internal files belonging to the organisation were exfiltrated in a ransomware attack. The listing further states that “all data of this company will be available for download on 22.06.2025.” No independent confirmation of the intrusion method, the volume of data taken, or the exact systems involved has been made public in the available record. The number of people affected is listed as unknown. The facts describe the event as a ransomware attack involving exfiltration of internal files; further technical detail is undisclosed.
Who is qilin?
Qilin is a well-documented ransomware group that has operated for several years, typically under a ransomware-as-a-service model. Public reporting on the group describes a pattern of double-extortion tactics: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group maintains leak sites where it posts victim names and, in some cases, sample files or full archives after a deadline. Qilin has been linked to attacks across multiple sectors, including education, healthcare, manufacturing and cultural institutions. Its operators commonly use phishing, compromised credentials or vulnerable remote-access services as initial entry points, though the specific vector in any given case is often not publicly confirmed. In this instance, the group claims to have listed skirball.org and to hold its data for release; that claim has not been independently verified beyond the listing itself.
About skirball.org
Skirball.org is the online presence of the Skirball Cultural Center, a Los Angeles institution described in the available summary as a meeting place guided by the Jewish tradition of welcoming the stranger and inspired by American democratic ideals of freedom and equality. Cultural centres of this kind typically host exhibitions, educational programs, public events, membership activities and community gatherings. They commonly maintain records related to staff, volunteers, donors, ticket holders, program participants and institutional partners. A breach involving such an organisation is consequential because the data it holds often includes contact details, financial or membership information, and operational documents that, if exposed, can affect both individuals and the centre’s ability to operate with public trust.
The information in question
The facts name the exposed material as “internal files exfiltrated in ransomware attack.” The group’s listing asserts that all data of the company will be available for download on 22 June 2025. No further breakdown of file types, categories or specific personal data fields has been disclosed in the public record. Organisations of this kind typically hold employee and volunteer records, donor and membership lists, visitor or ticketing information, email correspondence, financial and administrative documents, and program-related materials. Whether any of those categories are present in the claimed archive remains unconfirmed. The exact contents are therefore unknown; only the general description of internal files and the group’s claim of a full release date are on record.
Why it matters
For individuals, the practical risk is that personal or contact information, if present in the files, could be used for phishing, identity-related fraud or unwanted contact. Even limited internal documents can reveal patterns of communication, organisational structure or financial relationships that adversaries later exploit. For the organisation, the consequences include potential disruption of operations, the need to investigate and remediate systems, notification obligations where required by law, and the longer-term task of restoring confidence among staff, members and the public. Because the scale of the claimed exfiltration and the precise data types remain unconfirmed, the full extent of impact cannot yet be measured. The stated release date of 22 June 2025 creates a clear window in which the claimed material may become more widely available if the group follows through.
Were you affected?
If you have had any relationship with the Skirball Cultural Center—employment, volunteering, membership, donations, event attendance or correspondence—treat the claim as a reason to take basic precautions. Monitor financial and email accounts for unexpected activity, be alert to phishing messages that reference the centre or cultural events, and consider changing passwords on accounts that may have been used in connection with the organisation. Where multi-factor authentication is available, enable it. Because the number of people affected and the exact data types remain unknown, there is no public list of confirmed individuals. Readers can run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check is a practical first step while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Madera County Superintendent of Schools Listed by qilin Ransomware GroupEllison Educational Equipment Listed by qilin Ransomware GroupSW/WC Service Cooperative Listed by qilin Ransomware GroupEanes ISD schools Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the skirball.org Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.