The Teaching Company, LLC Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The The Teaching Company, LLC Listed by akira Ransomware Group (reported December 12, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to pressure organisations by stealing data and threatening public release, a pattern that has become a steady feature of the cyber-threat landscape rather than an exception. Listings on criminal leak sites are one of the main ways these incidents surface, often before victims or regulators have issued formal statements.
On December 12, 2023, The Teaching Company, LLC — which does business as The Great Courses — was listed by the Akira ransomware group. The group claimed it had exfiltrated internal files in a ransomware attack and stated that roughly 60GB of data would be uploaded. The number of people affected remains unknown, and independent confirmation of the full scope is limited. For customers, employees, and partners, the listing raises practical questions about what may have been taken and what steps are worth taking now.
Breaking down the breach
Public detail on the incident is drawn primarily from the Akira group's leak-site listing reported on December 12, 2023. According to that claim, The Teaching Company, LLC was the victim of a ransomware attack in which internal files were exfiltrated. The group stated that 60GB of data would be uploaded and described the material as including client information, substantial accounting and finance data, course-related information, and even a holiday video, adding that further updates would follow.
No confirmed figure for the number of individuals affected has been published in the available record. The precise method of initial access, the duration of any intrusion, and whether systems were encrypted in addition to data theft have not been disclosed in the facts at hand. As with many ransomware listings, the group's assertions should be treated as claims until corroborated by the organisation or by independent investigation.
Who is akira?
Akira is a ransomware operation that emerged in early 2023 and has since been linked to numerous attacks on organisations across multiple sectors. Like many modern ransomware groups, it commonly follows a double-extortion model: encrypting systems where possible while also stealing data and threatening to publish it on a dedicated leak site if payment demands are not met. The group has typically targeted mid-sized and larger organisations, often using compromised credentials, exposed remote-access services, or other common initial-access paths before moving laterally and exfiltrating files.
Akira's leak site is used both to name victims and to release samples or full archives when negotiations stall. Public reporting on the group has described relatively polished negotiation portals and a focus on volume of stolen data as leverage. None of that general pattern, however, constitutes independent proof of every specific claim made about any single victim. In this case, the listing of The Teaching Company, LLC and the description of the 60GB archive and its contents remain attributions to the group unless and until verified elsewhere.
Who is The Teaching Company, LLC?
The Teaching Company, LLC is known to the public primarily through its consumer brand The Great Courses. It produces and distributes educational lecture series and courses in formats that have included digital versatile discs, audio compact discs, and digital delivery. Its audience typically includes adult learners, lifelong-education customers, and institutions or individuals who purchase recorded academic-style content.
Organisations in this sector ordinarily hold customer account and order data, payment-related records, marketing lists, employee and contractor information, and internal business documents covering finance, content production, and operations. A breach involving such an entity matters because the customer base can be broad and long-standing, and because financial and client records, if exposed, can be reused for fraud, phishing, or further social engineering. The consequential nature of the incident does not require assuming negligence; it follows from the ordinary sensitivity of the data such a business is expected to maintain.
The information in question
The facts describe the exposed material as internal files exfiltrated in a ransomware attack. The Akira group's own summary claimed the forthcoming 60GB release would contain client information, lots of accounting and finance data, courses information, and a holiday video. Beyond that claim, the exact inventory of files, the completeness of any customer databases, and whether payment card data, passwords, or government identifiers were included have not been independently confirmed in the available record.
Companies that sell educational media and digital courses commonly store names, contact details, purchase histories, shipping addresses, and accounting records, along with internal documents about content and operations. It is reasonable to note those categories as typical, yet it remains unconfirmed which specific fields or records were actually taken in this incident. Readers should treat the group's content description as an unverified claim rather than as a verified data inventory.
What's at stake
For individuals whose information may have been involved, the practical risks include targeted phishing that references real purchases or account details, attempts at identity fraud if enough personal data was present, and misuse of any financial or billing information that might have been among the accounting files. Even partial client lists can make scam messages more convincing. Because the number of people affected is unknown, anyone who has been a customer or employee of The Great Courses or The Teaching Company has reason to remain alert rather than to assume they were untouched.
For the organisation, the stakes include operational disruption, regulatory and contractual notification duties where applicable, reputational harm, and the cost of investigation and remediation. Publication of internal finance and course materials can also expose business processes or commercial information to competitors or other opportunistic actors. These outcomes are the ordinary consequences of a claimed data-theft ransomware event; they do not depend on sensational framing.
What to do if you're exposed
If you have been a customer, employee, or partner of The Teaching Company or The Great Courses, treat the listing as a prompt to tighten basic hygiene rather than as proof that your specific records were released. Monitor bank and card statements for unfamiliar charges, and be wary of unsolicited messages that cite course purchases, account issues, or refunds. Consider changing passwords on related accounts, especially if you reused credentials, and enable multi-factor authentication where it is available. If you receive notices from the company, follow only the contact channels and instructions provided through official sources.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step will not confirm or deny involvement in this specific incident, but it can help you prioritise further monitoring and password changes across other services.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Stanford University Listed by akira Ransomware GroupChildren's Home of Wyoming Conference Listed by akira Ransomware GroupJasper High School Listed by akira Ransomware GroupCamino Nuevo CharterAcademy Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.