ENKA Schools Data Breach

Alleged

Ransomware claim involving ENKA Schools

Published: Oct 5, 2026 Doommageddon
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
ENKA Schools
Industry
Education
Threat Actor
Doommageddon
Date of Incident
Oct 5, 2026

Executive Summary

Doommageddon added ENKA Schools, a K-12 international school in Turkey, to its leak site on October 5, 2026. The group claims access to the institution’s systems. Ransomware actors often target schools due to the sensitive and valuable data they hold, including student records, parent information, staff details, and financial data, often coupled with constrained IT security budgets. Over the past 60 days, Doommageddon has claimed 8 victims across Turkey, India, and the United States, targeting sectors such as education and transportation. Recent victims include Akpera Gayrimenkul Yatırım A.Ş., SITTNAK Lojistik A.Ş., Cam Group LLC, and Chem Process Systems Pvt. Ltd. Turkey frequently features as a primary target country for this ransomware group.

Technical Analysis

SOCRadar’s investigation identified 17 compromised credential records associated with the domain enka.k12[.]tr, originating from August to October 2026, immediately preceding the leak site listing. This included 11 corporate credential logs, 1 business application credential, 2 workstation compromise artifacts, and 3 URL-based credentials. The concentrated timeframe of these findings suggests a systematic harvesting of staff and administrative accounts within a two-month period leading up to the ransomware attack, indicating a well-developed attack chain observed within the stealer log data. For educational institutions like ENKA Schools, a ransomware incident poses both operational and data protection challenges. It is crucial for ENKA Schools to notify Turkey’s KVKK data protection authority, inform affected students and parents as mandated by regulations, and engage cybersecurity incident response professionals promptly. All systems that potentially accessed sensitive data, including student records, academic assessments, or personal information during the identified period, must be included in the breach assessment scope.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.