FunkSec claimed a breach at Sorbonne Universite; the university called it limited

Organization
Sorbonne Université
Exploit
Ransomware
Industry
Education

In early March 2025 the FunkSec extortion group added Sorbonne Université to its dark web leak site, claiming it had taken 20 GB of files from the Paris institution. Leak site trackers recorded the listing on March 7, 2025. The group gave the university roughly 12 days to meet an undisclosed ransom demand and threatened to publish the material.

Sorbonne Université's communications service acknowledged an incident but described it as limited in scope and confined to Polytech Sorbonne, the university's engineering school. LeMagIT, reviewing the screenshots FunkSec published, assessed the compromise as the takeover of a single user account with remote access to internal resources through a Citrix gateway rather than a broad intrusion or an encryption event.

FunkSec listed the University of Rennes at around the same time, claiming some 50 GB taken through a Fortinet SSL VPN used by one of its schools. Rennes also called the incident limited in scope and said its network remained operational while technical teams responded.

FunkSec emerged in late 2024 and drew attention for claims that parts of its ransomware were generated with AI tooling. Researchers at Check Point have tied the group to hacktivist activity and described its operators as likely inexperienced, and inflated victim claims have been a recurring feature of its postings.

Sources