Quick Summary
AllegedExecutive Summary
Richmont Graduate University, an educational institution located in the United States, has been identified as a victim on the AiLock ransomware group’s dark web portal. The listing was published on July 7, 2026, and was discovered by SOCRadar’s threat intelligence services. The university operates within the education sector. This incident adds a US-based education entity to AiLock’s reported victimology. AiLock has claimed 13 other victims in the 60 days preceding this listing, with a notable focus on the healthcare, consumer services, and business services sectors. Geographically, AiLock’s victims are primarily located in the United States, Italy, and Chile. While Richmont Graduate University fits the pattern of being a US entity, its inclusion in the education sector is a slight deviation from AiLock’s typical top three targeted industries.
Technical Analysis
SOCRadar’s analysis of stealer logs revealed a limited exposure related to the richmont.edu domain. The data contained two records associated with a student-facing portal, with no corporate email credentials identified. This suggests that any compromised credentials were for external or user accounts, indicating a risk of customer or student account takeover rather than a direct compromise of corporate systems. No high-value identity, mail, or VPN endpoints were found to be exposed in this specific log slice. The observed exposure is limited to student/external accounts. This type of credential theft and subsequent use for initial access is a common tactic for ransomware groups like AiLock. They often source credentials from underground marketplaces, validate them for corporate logins (e.g., Microsoft 365, VPN), and then deploy ransomware. While the current findings do not directly link these compromised student credentials to the AiLock listing or establish a corporate access path, CTI teams should use this information to review credential hygiene for student portals and reinforce account takeover protections.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.