LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › uatf.edu.bo Listed by stormous Ransomware Group

HIGH severityUnverified claimHow we verify

uatf.edu.bo Listed by stormous Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·November 16, 2024
uatf.edu.bo Listed by stormous Ransomware Group

Reported November 16, 2024.

HIGH
Severity
November 16, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

uatf.edu.bo was listed by the stormous ransomware group on November 16, 2024, with internal files reported as exfiltrated. Individuals who may have records at the institution should verify their exposure and follow any guidance issued by the university.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On November 16, 2024, the Bolivian university domain uatf.edu.bo was listed by the ransomware group stormous. Public reporting indicates that internal files were exfiltrated in a ransomware attack, with the group claiming the material includes personal data of students such as addresses and phone numbers, along with internal correspondence involving employees and students. The number of people affected remains unknown, and many operational details of the incident have not been disclosed.

For a higher-education institution, any confirmed or claimed exposure of student and staff records carries lasting consequences. The listing itself is an unverified claim by the group; independent confirmation of the full scope has not been publicly established.

Inside the incident

According to the available record, uatf.edu.bo appeared on a stormous leak-site listing dated November 16, 2024. The reported summary states that internal files were exfiltrated during a ransomware attack. Named categories include personal data of students—addresses, phone numbers, and additional unspecified fields—plus internal correspondence of several employees and students. No figure for the total number of individuals affected has been released, nor have precise file counts, exact dates of intrusion or encryption, or the technical method of initial access been made public. Public detail on whether systems were restored, whether a ransom demand was issued or paid, or whether the data has been further distributed remains limited.

The group behind it: stormous

Stormous is a ransomware operation that follows a familiar double-extortion model: encrypting systems while simultaneously claiming to have stolen data, then listing the victim on a dedicated leak site to pressure payment. Like other groups in this category, it typically advertises stolen archives and sets countdown timers before threatening public release. Its listings are claims of compromise rather than independently Reported Facts; victims and investigators often treat them as assertions that require separate confirmation. Stormous has previously targeted a range of organisations across different sectors, using the same public-shaming tactic to amplify leverage. Nothing in the public record beyond the listing itself establishes additional specific statements stormous made about uatf.edu.bo.

Who is uatf.edu.bo?

Uatf.edu.bo is the online domain of the Universidad Autónoma Tomás Frías, a public university based in Potosí, Bolivia. As a higher-education institution it maintains academic records, student enrolment and contact information, employee personnel files, internal administrative correspondence, and research or operational documents. Universities of this type routinely hold sensitive personal identifiers, contact details, academic histories, and sometimes financial or health-related data linked to students and staff. A breach or claimed breach at such an organisation is consequential because the affected population includes young adults, faculty, and administrative personnel whose records may remain relevant for years after graduation or employment ends. The institution also serves a regional public mission, so disruption or data exposure can affect trust in educational services more broadly.

What was likely exposed

The facts name the following categories: personal data of students such as addresses, phone numbers, and more, together with internal correspondence of several employees and students, all described as internal files exfiltrated in a ransomware attack. Exact contents beyond these descriptions are unconfirmed. Organisations of this kind typically store student registration details, home and contact addresses, telephone numbers, email addresses, academic transcripts, employee directories, payroll or HR notes, and internal email threads. Because the public summary does not itemise every field or confirm the completeness of the archive, it is not possible to state with certainty which additional data elements—if any—were included. Readers should treat the named categories as the only currently reported elements and regard further specifics as undisclosed.

What's at stake

For individuals whose information may have been taken, the concrete risks include unwanted contact, phishing attempts that reference real personal details, and potential identity-related fraud if addresses, phone numbers, or other identifiers are combined with data from other sources. Students and staff may face long-term exposure of private correspondence that was never intended for public view. For the university, the stakes include operational disruption, the cost of forensic investigation and system recovery, possible regulatory or contractual obligations to notify affected parties, and erosion of confidence among current and prospective students and employees. Because the total number of people affected is unknown, the scale of these risks cannot yet be quantified. No public evidence has established negligence on the part of the institution; the incident is reported solely as a claimed ransomware event with data exfiltration.

If your data was in this claimed breach

If you are a current or former student, employee, or correspondent of the university, treat the possibility of exposure seriously even while details remain limited. Change passwords on any accounts that reused credentials associated with university email or portals, enable multi-factor authentication wherever available, and monitor financial and email accounts for unexpected activity. Be alert to phishing messages that appear to reference genuine personal details. Consider placing fraud alerts with relevant credit or identity services if you believe sensitive identifiers were involved. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check provides an additional, independent signal but does not replace official notifications from the institution itself. Continue to watch for any formal statements from the university regarding confirmation, scope, or recommended next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyuatf.edu.bo security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See uatf.edu.bo’s full breach history →

More recent breaches

education.eeb-lost Listed by stormous Ransomware GroupMarch 14, 2024uffs.edu.br Listed by stormous Ransomware GroupJanuary 18, 2024Official Statement: Protecting palatineschool.org Infrastructure Listed by stormous Ransomware GroupJune 28, 2026katholiekamersfoort.nl Listed by stormous Ransomware GroupJune 2, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the uatf.edu.bo Listed by stormous Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by stormous — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram