LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › University of Defence - Full Leak Listed by monti Ransomware Group

HIGH severityUnverified claimHow we verify

University of Defence - Full Leak Listed by monti Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 23, 2023
University of Defence - Full Leak Listed by monti Ransomware Group

Reported October 23, 2023.

HIGH
Severity
October 23, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The University of Defence - Full Leak Listed by monti Ransomware Group (reported October 23, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

When a military university appears on a ransomware group's leak site, the practical stakes fall first on the people whose records may sit inside its systems: students, staff, service members, and anyone whose personal or professional details were stored for enrolment, employment, or research. Public reporting on 23 October 2023 stated that the monti ransomware group had listed the University of Defence with a claim of a full leak after internal files were exfiltrated. The number of people affected remains unknown, and exact file contents have not been publicly itemised, yet the mere claim is enough to warrant careful attention from anyone connected to the institution.

What follows is a plain account of what has been reported, what is still undisclosed, and what steps affected individuals can reasonably take. No negligence on the part of the university is asserted here; the available record simply does not establish how the incident occurred or what defences were in place.

Breaking down the breach

According to public reporting dated 23 October 2023, the University of Defence was listed by the monti ransomware group under a headline describing a “full leak.” The only data description supplied is that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been released. Timing of the intrusion itself, the initial access method, the volume of data taken, and any ransom demand or payment status are all undisclosed in the material available for this account. The listing on the group’s leak site constitutes a claim by the actors; independent confirmation of the full scope has not been supplied in the reported facts.

In short, the public record establishes a claimed ransomware incident involving exfiltration of internal files, reported in late October 2023, with scale and precise contents still unconfirmed.

Who is monti?

Monti is a ransomware operation that became visible in the threat landscape after the Conti group largely disbanded. Like many successors in that ecosystem, monti has typically combined data theft with encryption, then threatened to publish stolen material on a dedicated leak site if its demands are not met. The group has been observed using common initial-access routes such as compromised credentials or vulnerable remote services, followed by lateral movement and selective exfiltration before ransomware deployment. Its public leak site has previously listed organisations across education, government-adjacent, and commercial sectors. These patterns are drawn from well-documented public reporting on the actor; they do not constitute proof of the exact tactics used against the University of Defence. With respect to this incident, the only specific assertion is the group’s own claim that it obtained and intended to leak internal files from the university.

About University of Defence

The University of Defence is a military higher-education institution. Public background notes that the city of Brno was selected as the location for the new engineering-oriented military college because of its long tradition of high-quality engineering education. Institutions of this type educate future officers and specialists, conduct defence-related research, and maintain administrative records for students, faculty, and staff. They routinely handle personnel data, academic records, research materials, and operational or administrative documents that, by nature, can be sensitive. A breach claim against such an organisation therefore carries weight beyond ordinary commercial incidents: the data may touch national-security adjacent functions, career military pathways, and the personal lives of people who serve or study under heightened trust expectations. Nothing in the reported facts establishes that classified material was involved; the consequential nature of the claim rests on the ordinary holdings of a defence university.

What data was at risk

The facts name the exposed material only as “internal files exfiltrated in a ransomware attack.” No further breakdown—such as student records, payroll, medical information, research datasets, or credentials—has been publicly itemised. Organisations of this kind typically hold identity and contact details, academic and personnel files, financial and administrative documents, and research or project materials. Whether any of those categories were among the files taken remains unconfirmed. Readers should treat specific content claims as unverified until the university or competent authorities provide clearer inventories.

The real-world impact

For individuals, the concrete risks centre on misuse of personal information if it was present in the stolen files: targeted phishing that references real university affiliations, identity-fraud attempts, or reputational pressure. Military and defence-linked populations can face additional scrutiny or social-engineering attempts that exploit knowledge of rank, unit, or course of study. For the institution, a claimed leak can disrupt academic and administrative continuity, require costly forensic and recovery work, and erode confidence among students, staff, and partner organisations. Because the number of people affected and the exact data types remain unknown, the practical severity cannot yet be quantified; the prudent stance is to assume that anyone with a recent or ongoing relationship to the university may need to monitor for secondary misuse.

No public confirmation of ransom payment, data destruction, or full recovery has been supplied in the available facts. Impact assessments will depend on later official statements.

Were you affected?

If you are a current or former student, employee, or contractor of the University of Defence, treat the claim seriously until clearer information appears. Change passwords for university-related and reused accounts, enable multi-factor authentication wherever it is offered, and watch financial and email accounts for unexpected activity. Be sceptical of unsolicited messages that reference the university or this incident. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Official updates from the university or relevant authorities remain the most reliable source for confirmation of scope and next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyUniversity of Defence security record
86/100
DoxxScan™ · Low doxx risk
B 81Good record

2 reported incidents on record.

See University of Defence’s full breach history →
RelatedMore incidents at University of Defence

More recent breaches

University Obrany - Part 2 (Tiny Leak) Listed by monti Ransomware GroupOctober 7, 2023University of Defence - Part 1 Listed by monti Ransomware GroupSeptember 27, 2023University Obrany - Press Release Listed by monti Ransomware GroupSeptember 20, 2023HMW - Press Release Listed by monti Ransomware GroupDecember 9, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the University of Defence - Full Leak Listed by monti Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by monti — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram