On February 25, 2026, the Romanian school Primaria Ungheni appeared on the leak site of the ransomware group Killsec, with internal files reportedly exfiltrated during a ransomware attack now publicly listed.
Watch primaria ungheni
Get alerted the next time primaria ungheni files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about primaria ungheni’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the ransomware.live aggregator describes the incident as a ransomware deployment that resulted in data exfiltration. The listing shows 0/1 disclosures completed, indicating the group has published an initial sample or announcement but has not yet released the full archive. The exact number of people whose information is contained in the files remains unknown, as no detailed victim count or data inventory has been published. Available reporting indicates the exposed material consists of internal municipal files rather than a structured database of citizen records.
Why This Matters for You and Your Family
When a local government body like a town hall suffers a breach, the documents often contain addresses, tax records, family names, and correspondence that directly identify ordinary residents. If your town or a neighboring municipality uses similar systems, your household data may already sit in files that criminals can search. Internal files from such organizations frequently include scanned documents, spreadsheets of residents, and email archives that reveal far more than a simple password leak. Once published on a ransomware site, the information becomes freely available to identity thieves, stalkers, and scammers who target families for fraud, phishing, or physical intimidation.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one dataset. A single address or parent’s email from municipal records can be combined with credentials stolen in other breaches to map an entire household. Criminals chain these fragments: an email leads to a reused password, which unlocks a social-media account, which reveals children’s names and schools. Gaming accounts belonging to your kids are especially vulnerable because they often share the same family email or phone number listed in government files. This creates a doxxing chain that can expose your home address, daily routines, and children’s online identities within hours of the data appearing on a leak site.