www.certifiedinfosec.com Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
www.certifiedinfosec.com has been listed by the apt73 ransomware group, which claims to have stolen internal files. The incident was disclosed on December 4, 2024; individuals should check whether their information was exposed and take appropriate protective steps.
On December 4, 2024, the website www.certifiedinfosec.com was listed by the ransomware group known as apt73. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.
Certified Information Security operates as a registered trade name for Certified Tech Trainers (CTT), a corporation identified by D-U-N-S number 010573009 and CAGE code 3FKS0. The listing itself is a claim by the group; independent confirmation of the full scope is limited at this stage. The incident matters because organizations in the information-security training sector routinely handle sensitive internal material that, if exposed, can create lasting risks for staff, partners, and clients.
Inside the incident
According to the available record, www.certifiedinfosec.com was named on a leak site associated with the apt73 ransomware group on December 4, 2024. The reported summary states that internal files were exfiltrated as part of a ransomware attack. No public figures have been released for the volume of data taken, the precise date the intrusion began, or the technical method used to gain access. The number of individuals whose information may have been involved is listed as unknown. Beyond the claim of exfiltration of internal files, no additional breach specifics—such as encryption status of systems, ransom demands, or recovery timelines—have been confirmed in the public facts.
Inside apt73
apt73 is identified in public reporting as a ransomware group that operates by claiming to have compromised organizations and listing them on dedicated leak sites. Like other ransomware actors, groups of this type typically combine data theft with encryption of victim systems, then threaten to publish or sell the stolen material if payment is not made. Their listings serve as both pressure tactics and public assertions of success. Well-documented patterns among such groups include opportunistic targeting across multiple sectors, use of common initial-access techniques such as phishing or exploitation of unpatched services, and subsequent exfiltration of files before or during encryption. No verified statements from apt73 beyond the listing of this particular victim appear in the available facts; any claims of specific data volumes or contents tied solely to this incident should be treated as unverified assertions by the group.
www.certifiedinfosec.com and its sector
www.certifiedinfosec.com functions under the trade name Certified Information Security for Certified Tech Trainers (CTT), a corporation registered with the cited D-U-N-S and CAGE identifiers. Organizations of this type operate in the information-security education and certification sector, delivering training programs, professional credentials, and related technical instruction. Such entities commonly maintain internal repositories of course materials, instructor records, student or client enrollment data, corporate financial documents, and partner agreements. A breach involving a training provider can be consequential because the sector sits at the intersection of technical expertise and personal or organizational trust; exposure of internal files may affect not only the company itself but also the professionals and institutions that rely on its services for workforce development and compliance.
What data was at risk
The facts name “internal files” as the data type exfiltrated in the ransomware attack. No further breakdown—such as employee records, customer lists, financial documents, or intellectual property—has been publicly detailed. The number of people affected is unknown. Organizations in the information-security training sector typically hold personnel files, student or client contact information, training curricula, examination materials, contracts, and operational correspondence. Because the exact contents remain unconfirmed, it is not possible to state with certainty which of these categories, if any, were among the files taken. Readers should treat the scope as limited to the disclosed description of internal files pending additional verified reporting.
Why it matters
When internal files leave an organization through a ransomware incident, the practical risks include potential misuse of any personal or business information contained in those files, targeted follow-on phishing against staff or clients, and competitive or reputational harm to the company. For individuals whose data may appear in the material, consequences can range from unwanted contact to identity-related fraud if identifiers or credentials are present. For the organization, recovery involves not only technical restoration but also notification obligations, possible regulatory scrutiny, and the need to rebuild trust with partners who depend on secure handling of training-related information. Because the scale remains unknown, the full extent of these risks cannot yet be quantified, yet the mere confirmation of exfiltration establishes a baseline of exposure that warrants attention.
What to do if you're exposed
If you have a past or present relationship with Certified Information Security or Certified Tech Trainers—whether as an employee, instructor, student, or client—monitor financial and email accounts for unusual activity and consider placing fraud alerts with major credit bureaus. Change passwords on any accounts that may have shared credentials or recovery information with the organization, and enable multi-factor authentication where available. Retain any official notices the company may issue. As a practical next step, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; such a scan provides an early indicator but does not replace ongoing vigilance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
leadboxhq.com Listed by apt73 Ransomware Grouphpecds.com Listed by apt73 Ransomware Groupwww.prixet.com Listed by apt73 Ransomware Groupwww.netromsoftware.ro Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the www.certifiedinfosec.com Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.