Key Takeaways
The Yokosuka Gakuin School Corporation, a prominent educational institution in Japan, has publicly disclosed a significant ransomware attack that resulted in a data leak. In a statement, the school confirmed it was the victim of a cyber intrusion in early December 2025.Â
The event was first identified after a university employee was unable to connect to a server, prompting an immediate investigation that uncovered illegal external access and the execution of a malicious program.Â
The investigation confirmed that threat actors achieved unauthorized server access and deployed ransomware. As a result of the breach, the school discovered that multiple files, including photos and videos, had been leaked from the compromised system.Â
Meanwhile, the Rhysida seems to be auctioning sensitive internal files and personal identification records now for 6 BTC. Reports suggest that the threat actor conducted the cyber intrusion on December 15, allegedly via exploiting vulnerabilities in the institution’s network.Â
The full scope of the exfiltrated data is still being determined as part of the ongoing forensic analysis. This type of data breach in education highlights the vulnerability of academic institutions, which often hold large volumes of potentially sensitive information about students and staff.Â
Upon discovering the attack, Yokosuka Gakuin took immediate action to contain the threat by disconnecting its systems from the internet. The institution is now collaborating with external specialists to conduct a thorough investigation and restore affected systems.Â
The school's public statement apologized for the concern caused and committed to providing updates as the situation develops.
Among the threat actor’s claimed targets this year are Cookeville Regional, the U.S. architecture and engineering company LaBella Associates, and Bayhealth Medical Center, as well as Sunflower Medical Group and Community Care Alliance (CCA).