uatf.edu.bo Listed by stormous Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
uatf.edu.bo was listed by the stormous ransomware group on November 16, 2024, with internal files reported as exfiltrated. Individuals who may have records at the institution should verify their exposure and follow any guidance issued by the university.
On November 16, 2024, the Bolivian university domain uatf.edu.bo was listed by the ransomware group stormous. Public reporting indicates that internal files were exfiltrated in a ransomware attack, with the group claiming the material includes personal data of students such as addresses and phone numbers, along with internal correspondence involving employees and students. The number of people affected remains unknown, and many operational details of the incident have not been disclosed.
For a higher-education institution, any confirmed or claimed exposure of student and staff records carries lasting consequences. The listing itself is an unverified claim by the group; independent confirmation of the full scope has not been publicly established.
Inside the incident
According to the available record, uatf.edu.bo appeared on a stormous leak-site listing dated November 16, 2024. The reported summary states that internal files were exfiltrated during a ransomware attack. Named categories include personal data of students—addresses, phone numbers, and additional unspecified fields—plus internal correspondence of several employees and students. No figure for the total number of individuals affected has been released, nor have precise file counts, exact dates of intrusion or encryption, or the technical method of initial access been made public. Public detail on whether systems were restored, whether a ransom demand was issued or paid, or whether the data has been further distributed remains limited.
The group behind it: stormous
Stormous is a ransomware operation that follows a familiar double-extortion model: encrypting systems while simultaneously claiming to have stolen data, then listing the victim on a dedicated leak site to pressure payment. Like other groups in this category, it typically advertises stolen archives and sets countdown timers before threatening public release. Its listings are claims of compromise rather than independently Reported Facts; victims and investigators often treat them as assertions that require separate confirmation. Stormous has previously targeted a range of organisations across different sectors, using the same public-shaming tactic to amplify leverage. Nothing in the public record beyond the listing itself establishes additional specific statements stormous made about uatf.edu.bo.
Who is uatf.edu.bo?
Uatf.edu.bo is the online domain of the Universidad Autónoma Tomás Frías, a public university based in Potosí, Bolivia. As a higher-education institution it maintains academic records, student enrolment and contact information, employee personnel files, internal administrative correspondence, and research or operational documents. Universities of this type routinely hold sensitive personal identifiers, contact details, academic histories, and sometimes financial or health-related data linked to students and staff. A breach or claimed breach at such an organisation is consequential because the affected population includes young adults, faculty, and administrative personnel whose records may remain relevant for years after graduation or employment ends. The institution also serves a regional public mission, so disruption or data exposure can affect trust in educational services more broadly.
What was likely exposed
The facts name the following categories: personal data of students such as addresses, phone numbers, and more, together with internal correspondence of several employees and students, all described as internal files exfiltrated in a ransomware attack. Exact contents beyond these descriptions are unconfirmed. Organisations of this kind typically store student registration details, home and contact addresses, telephone numbers, email addresses, academic transcripts, employee directories, payroll or HR notes, and internal email threads. Because the public summary does not itemise every field or confirm the completeness of the archive, it is not possible to state with certainty which additional data elements—if any—were included. Readers should treat the named categories as the only currently reported elements and regard further specifics as undisclosed.
What's at stake
For individuals whose information may have been taken, the concrete risks include unwanted contact, phishing attempts that reference real personal details, and potential identity-related fraud if addresses, phone numbers, or other identifiers are combined with data from other sources. Students and staff may face long-term exposure of private correspondence that was never intended for public view. For the university, the stakes include operational disruption, the cost of forensic investigation and system recovery, possible regulatory or contractual obligations to notify affected parties, and erosion of confidence among current and prospective students and employees. Because the total number of people affected is unknown, the scale of these risks cannot yet be quantified. No public evidence has established negligence on the part of the institution; the incident is reported solely as a claimed ransomware event with data exfiltration.
If your data was in this claimed breach
If you are a current or former student, employee, or correspondent of the university, treat the possibility of exposure seriously even while details remain limited. Change passwords on any accounts that reused credentials associated with university email or portals, enable multi-factor authentication wherever available, and monitor financial and email accounts for unexpected activity. Be alert to phishing messages that appear to reference genuine personal details. Consider placing fraud alerts with relevant credit or identity services if you believe sensitive identifiers were involved. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check provides an additional, independent signal but does not replace official notifications from the institution itself. Continue to watch for any formal statements from the university regarding confirmation, scope, or recommended next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
education.eeb-lost Listed by stormous Ransomware Groupuffs.edu.br Listed by stormous Ransomware GroupOfficial Statement: Protecting palatineschool.org Infrastructure Listed by stormous Ransomware Groupkatholiekamersfoort.nl Listed by stormous Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the uatf.edu.bo Listed by stormous Ransomware Group →
Publicly posted by stormous — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.