LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › vaud-promotion Listed by darkrace Ransomware Group

HIGH severityUnverified claimHow we verify

vaud-promotion Listed by darkrace Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 6, 2023
vaud-promotion Listed by darkrace Ransomware Group

Reported June 6, 2023.

HIGH
Severity
June 6, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The vaud-promotion Listed by darkrace Ransomware Group (reported June 6, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target public-facing organisations and regional promoters, using leak-site listings to pressure victims after claiming to have stolen internal material. In this landscape, even smaller associations that coordinate economic, tourism and cultural activity can appear on criminal forums, raising questions for partners and residents whose details may sit in shared systems.

On 6 June 2023, the organisation known as vaud-promotion was listed by the darkrace ransomware group. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and wider technical detail has not been released. The listing itself is a claim by the group; independent confirmation of the full scope is limited.

What happened

According to available records, vaud-promotion appeared on a darkrace leak site on or around 6 June 2023. The report characterises the incident as a ransomware attack in which internal files were taken. No public figure has been given for the volume of data, the exact date of initial intrusion, or the encryption or negotiation timeline. Methods used to gain access have not been disclosed. The number of individuals potentially touched by the event is listed as unknown. Beyond the group’s claim that internal files were exfiltrated, further concrete particulars remain unconfirmed in open sources.

The group behind it: darkrace

Darkrace is a ransomware operation that has followed the familiar double-extortion pattern seen across several criminal brands: after gaining access to a network, operators claim to steal data before deploying encryption, then threaten to publish the material on a dedicated leak site if payment is not made. Like other groups in this category, darkrace has used public listings to advertise alleged victims and to apply reputational pressure. Its activity has been tracked in open reporting as part of the broader ransomware ecosystem that emerged and evolved in the early 2020s. Specific statements darkrace may have made solely about vaud-promotion, beyond the fact of the listing and the assertion of internal-file exfiltration, are not detailed in the available record; the listing should therefore be treated as the group’s unverified claim.

Who is vaud-promotion?

Vaud-promotion, formally associated with L’Association Vaud Promotion, works to raise the profile, competitiveness and attractiveness of the Swiss canton of Vaud. It does so under the VAUD+ brand and in collaboration with economic actors, regions and institutions. Its stated scope covers activities, products and services spanning the economy, academia, tourism, culture, sport, local produce and gastronomy. It animates a multi-sector community of Vaudois participants who embody and promote those strengths.

Organisations of this type typically maintain contact databases, partnership records, event and campaign materials, and internal administrative files. A breach affecting such an entity matters because the data can touch businesses, public bodies, cultural operators and individuals who interact with cantonal promotion efforts. Disruption or exposure can affect trust among partners and the practical running of joint initiatives, even when the precise scale of any compromise is still unclear.

The information in question

Public facts name the exposed material only as internal files exfiltrated in a ransomware attack. No itemised inventory—such as specific categories of personal data, financial records, or credential stores—has been released in the material provided. Exact contents therefore remain unconfirmed.

Associations that promote a region commonly hold names and contact details of member organisations and individuals, correspondence, planning documents, and operational files. Whether any of those categories were among the files darkrace claims to have taken has not been independently established. Readers should treat assertions about precise data types as unverified until official notice or further reliable reporting appears.

What's at stake

For people whose information may have been stored in the association’s systems, the practical risks include unwanted contact, phishing that references genuine partnerships or events, and the long-term recirculation of any personal details that might later surface. For partner organisations, exposure of internal files can reveal commercial or collaborative arrangements and create openings for social-engineering attempts aimed at staff.

For vaud-promotion itself, the incident carries operational and reputational consequences: the need to investigate, to notify relevant parties where required, and to restore confidence among the multi-sector community it serves. Because the count of affected individuals is unknown and the full data set is undescribed in public sources, the outer bound of harm cannot yet be stated with precision. Calm verification and proportionate precautions remain the sensible response.

Were you affected?

If you have worked with, joined, or supplied information to vaud-promotion or related VAUD+ initiatives, consider the following steps:

Public detail on this event is limited. Further clarity, if it comes, will most likely arrive through statements by the organisation or competent authorities rather than through criminal leak sites.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyvaud-promotion security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See vaud-promotion’s full breach history →

More recent breaches

marstrand.se Listed by darkrace Ransomware GroupJune 9, 2023COOPERATIVETECH Listed by darkrace Ransomware GroupJune 7, 2023PICPLUS.COM Listed by darkrace Ransomware GroupJune 6, 2023rzepeckimroczkowski Listed by darkrace Ransomware GroupJune 5, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the vaud-promotion Listed by darkrace Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by darkrace — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram