LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › www.usmba.ac.ma Listed by GDLockerSec Ransomware Group

HIGH severityUnverified claimHow we verify

www.usmba.ac.ma Listed by GDLockerSec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 24, 2025
www.usmba.ac.ma Listed by GDLockerSec Ransomware Group

Reported January 24, 2025.

HIGH
Severity
January 24, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The website www.usmba.ac.ma was listed by the GDLockerSec ransomware group on January 24, 2025, with internal files reported as exfiltrated. Individuals who may have shared data with the institution should review any communications from the organisation and monitor their personal information for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On January 24, 2025, the website www.usmba.ac.ma was listed by the ransomware group GDLockerSec as a victim of a data-exfiltration attack. Public reporting indicates that internal files totaling 8MB were taken. The number of people affected remains unknown, and further operational details have not been disclosed.

This listing places an academic institution in the public record of a ransomware claim. For students, staff, alumni and partners who interact with the university’s systems, the incident raises practical questions about what information may have left the organisation’s control and what steps can be taken next.

What happened

According to the available record, GDLockerSec listed www.usmba.ac.ma on its leak site on January 24, 2025. The group claims that internal files were exfiltrated during a ransomware attack and that the volume of data involved is 8MB. No public confirmation of the intrusion method, the exact date of compromise, or the full scope of systems affected has been released. The number of individuals whose data may be involved is listed as unknown. Beyond the group’s claim and the reported summary of 8MB of internal files, additional technical or forensic detail remains undisclosed.

Who is GDLockerSec?

GDLockerSec is a ransomware operation that has appeared in public threat reporting as a group that combines data encryption with the theft of files for double-extortion pressure. Like many such actors, it maintains a leak site on which it posts the names of organisations it claims to have compromised, sometimes accompanied by sample data or statements about the volume of material taken. The group’s typical pattern involves gaining access to a network, moving laterally to locate valuable repositories, exfiltrating selected files, and then demanding payment under threat of publication. Prior public listings by GDLockerSec have involved a range of sectors; however, no verified statements from the group beyond the basic listing of www.usmba.ac.ma and the 8MB claim are part of the current record for this incident. The listing itself should be treated as an unverified claim until independently confirmed.

Who is www.usmba.ac.ma?

www.usmba.ac.ma is the online presence of Sidi Mohamed Ben Abdellah University (Université Sidi Mohamed Ben Abdellah), a public higher-education institution based in Fez, Morocco. Universities of this type routinely manage student academic records, staff employment data, research materials, administrative correspondence, financial and scholarship information, and authentication systems that support campus services. Because such organisations hold both personal data of large numbers of individuals and internal operational documents, a successful intrusion can affect privacy, academic continuity and institutional trust. The listing of the university’s domain by a ransomware group therefore carries consequences that extend beyond the organisation itself to the people who rely on its systems.

What was likely exposed

The only data type named in the public record is “internal files” said to have been exfiltrated in a ransomware attack, with a reported volume of 8MB. Exact file names, categories or individual records have not been disclosed. Organisations of this kind typically hold a range of materials that could fall under the broad heading of internal files; the precise contents of the claimed 8MB set remain unconfirmed. In the absence of further detail, the following points summarise what is known and what is not:

Until the university or independent investigators release additional findings, any assumption about particular documents or personal identifiers would be speculative.

Why it matters

Even a modest volume of internal files can contain sensitive personal or operational information. For individuals, the practical risks include potential misuse of contact details, academic or employment records, or other identifiers that could support phishing, identity fraud or social-engineering attempts. For the university, the incident may disrupt administrative processes, require notification and remediation efforts, and affect confidence among students, staff and external partners. Because the number of people affected is unknown and the exact contents of the 8MB set are unconfirmed, the full scale of impact cannot yet be measured. The listing itself, however, places the organisation and its community on notice that data may have left its control.

Were you affected?

If you have an account, student record, employment relationship or other ongoing connection with www.usmba.ac.ma, treat the claim seriously until more information is available. Practical first steps include changing passwords used on university systems (and any reused elsewhere), enabling multi-factor authentication where offered, monitoring financial and email accounts for unusual activity, and remaining alert to unsolicited messages that reference the university or request personal information. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Official updates from the university, if issued, should be followed for any specific guidance or support channels.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companywww.usmba.ac.ma security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See www.usmba.ac.ma’s full breach history →

More recent breaches

www.fgse.cu.edu.eg Listed by GDLockerSec Ransomware GroupJanuary 26, 2025www.shihka.com.hk Listed by GDLockerSec Ransomware GroupJanuary 24, 2025www.lnrbda.gov.ng Listed by GDLockerSec Ransomware GroupJanuary 24, 2025aws.amazon.com Listed by GDLockerSec Ransomware GroupJanuary 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the www.usmba.ac.ma Listed by GDLockerSec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by gdlockersec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram