Royal ransomware gang claimed 20GB of data stolen from EdisonLearning
- Organization
- EdisonLearning
- Exploit
- Ransomware
- Industry
- Education Services
The Royal ransomware group added EdisonLearning to its dark web leak site on April 26, 2023, claiming to have stolen 20GB of data from the education management company. Royal said the material included personal information belonging to employees and students, and taunted the organization in its posting.
EdisonLearning is a for-profit education management organization based in Fort Lauderdale, Florida. It operates and supports public schools and distance learning programs in the United States and the United Kingdom.
The company confirmed that a cyber incident had occurred but declined to provide details, saying its investigation was ongoing. Its director of communications, Michael Serpe, said the impacted systems did not hold student data, which sits at odds with Royal's claim. Neither the company nor the outlets reporting on the listing verified the group's assertions, and researchers noted that ransomware operations sometimes list victims falsely or overstate what they have taken.
Listing a victim publicly usually signals that a ransom has been demanded and that negotiations are under way or have broken down. Neither the size of any demand nor whether EdisonLearning engaged with the attackers was disclosed. As of the reporting date the company had not said how many people, if any, had information exposed.