Quick Summary
AllegedExecutive Summary
Salida Union School District, an education organization based in the United States, has been listed as a victim on the Qilin ransomware group’s dark web portal, published on July 22, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. As a K-12 district, it operates student information systems and parent portals holding sensitive records on minors, the kind of data that makes education a recurring extortion target. Its listing adds an education-sector entry to Qilin’s large and active recent victim population. In the 60 days prior to this listing, Qilin has claimed 126 other victims across its leak portal. The group has shown a strong targeting pattern in the business services, manufacturing, and healthcare sectors. Geographically, its victims are concentrated in the United States, Australia, and Spain. Other recent Qilin listings that overlap with Salida’s profile — education organizations — include The Nueva School, Kinetic Education, Alamo Heights School District, and Associated Theatrical Contractors. The district diverges from the group’s dominant business-services and manufacturing lean but aligns with its strong US concentration and its intermittent targeting of schools.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a notable exposure for the salida.k12.ca.us domain. The queried slice returned fourteen records tied to the district’s Aeries student information system: one corporate credential consistent with an employee account, one unclear record, and the remainder student and parent accounts on the SIS portal. One reused Yahoo-address credential recurs across several records and portal URLs, pointing to credential reuse on the parent portal. The dominant profile is Mixed, and the freshness window is long-tailed, spanning August 2025 to mid-July 2026, indicating credentials that appear not to have been rotated. One record carried a Brazilian geolocation, which may reflect a compromised endpoint or proxy rather than attacker location. For ransomware groups such as Qilin, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by Qilin, the presence of an employee credential alongside persistent SIS-portal exposure is consistent with the kill chain typically observed for this class of incident, and it makes resetting the staff account, forcing parent/student resets, and auditing the SIS a priority for organizations fitting this profile.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.