Quick Summary
AllegedExecutive Summary
Doommageddon added ENKA Schools, a K-12 international school in Turkey, to its leak site on October 5, 2026. The group claims access to the institution’s systems. Ransomware actors often target schools due to the sensitive and valuable data they hold, including student records, parent information, staff details, and financial data, often coupled with constrained IT security budgets. Over the past 60 days, Doommageddon has claimed 8 victims across Turkey, India, and the United States, targeting sectors such as education and transportation. Recent victims include Akpera Gayrimenkul Yatırım A.Ş., SITTNAK Lojistik A.Ş., Cam Group LLC, and Chem Process Systems Pvt. Ltd. Turkey frequently features as a primary target country for this ransomware group.
Technical Analysis
SOCRadar’s investigation identified 17 compromised credential records associated with the domain enka.k12[.]tr, originating from August to October 2026, immediately preceding the leak site listing. This included 11 corporate credential logs, 1 business application credential, 2 workstation compromise artifacts, and 3 URL-based credentials. The concentrated timeframe of these findings suggests a systematic harvesting of staff and administrative accounts within a two-month period leading up to the ransomware attack, indicating a well-developed attack chain observed within the stealer log data. For educational institutions like ENKA Schools, a ransomware incident poses both operational and data protection challenges. It is crucial for ENKA Schools to notify Turkey’s KVKK data protection authority, inform affected students and parents as mandated by regulations, and engage cybersecurity incident response professionals promptly. All systems that potentially accessed sensitive data, including student records, academic assessments, or personal information during the identified period, must be included in the breach assessment scope.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.