Jigme Singye Wangchuck School of Law Data Breach

Alleged

Ransomware claim involving Jigme Singye Wangchuck School of Law

Published: Sep 1, 2026 Krybit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Jigme Singye Wangchuck School of Law
Industry
Professional Services
Threat Actor
Krybit
Date of Incident
Sep 1, 2026

Executive Summary

The krybit ransomware group has listed the Jigme Singye Wangchuck School of Law, Bhutan’s national law institution, on its dark web portal on September 1, 2026. SOCRadar’s Dark Web Monitoring identified this listing. The institution provides legal education and professional training. This incident marks a rare appearance of a South Asian legal education facility on a ransomware leak site. Educational institutions, particularly those handling sensitive information, are increasingly becoming targets for ransomware operations. In the preceding 60 days, krybit has claimed 58 other victims. The group primarily targets organizations within the Professional Services, Other, and Technology sectors. Its most frequent victim countries include India, Thailand, and Brazil. Previous Professional Services and South Asian victims of krybit include Southsign Technologies, Union for International Cancer Control, APSA Internacional S.A., and Studio Associato Tibaldi. While Bhutan is not a typical target geography for krybit, the school’s classification within the Professional Services sector aligns with the group’s primary focus.

Technical Analysis

A stealer-log query targeting the domain jswlaw[.]bt revealed 26 records spanning from December 2024 to August 2026, with 14 of these identified as employee credentials. This extensive credential window of nearly 20 months indicates a significant dwell time for the attackers, suggesting the initial compromise occurred in December 2024 and remained undetected until at least August 2026. Compromised endpoints provided access to the student information management system (sims.jswlaw[.]bt) and an internal LAN addressbook. This access suggests that the threat actor gained substantial insight into the institution’s operations and personnel well before the ransomware listing. The exposed credentials include those related to Google identity provider accounts and the aforementioned student information management system. The long duration of unrotated credentials, spanning almost two years, indicates a potential lack of proactive credential management and security hygiene. This extended access window could have facilitated further lateral movement and data exfiltration within the network. The presence of accessible internal address books further aids attackers in identifying key personnel and valuable data repositories. The provided assessment highlights the prolonged undetected access, with the earliest compromise dating back to December 2024. The attacker’s visibility into institutional operations, including the student information management system and internal network structures, is a significant concern. Organizations should prioritize rotating all exposed Google IdP and SIMS credentials, enforcing re-authentication for all accounts, and thoroughly reviewing SIMS access logs from December 2024 to identify any anomalous activities.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.