CSIDB logo
Incident

Universidad Piloto de Colombia

Incident posture

Attack window
Oct 2022
Location
Colombia
Status
Historical
CIA posture
Available to members
Updated
2026-08-28 14:53

Linked entities

Victim
Universidad Piloto de Colombia
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Oct 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Universidad Piloto de Colombia experienced a cybersecurity incident involving the ALPHV (BlackCat) ransomware group, which claimed responsibility for exfiltrating approximately 300 GB of sensitive data encompassing student, faculty, and administrative records. The attackers published samples of the stolen information on their leak site as evidence of the compromise. While the institution publicly acknowledged a computer security incident via its official communication channels, it did not explicitly confirm or deny ALPHV’s assertions regarding the scope or validity of the data breach despite external inquiries. The incident highlights unauthorized access to personal and operational information within the academic sector.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On October 21, 2022, Universidad Piloto de Colombia publicly disclosed a computer security incident via its official Facebook page. The announcement did not specify the nature or scope of the breach. Approximately one week later, on October 28, the ALPHV/BlackCat ransomware group listed the university on its data leak site, claiming possession of 300 gigabytes of stolen data. ALPHV asserted the compromised information included files pertaining to students, faculty members, and administrative operations. The group published sample documents to substantiate their claims, though the specific contents of these samples were not detailed in available reports. DataBreaches.net attempted to contact the university via email to verify ALPHV's assertions but received no response as of the article's publication date.

The incident exposed sensitive institutional and personal information based on ALPHV's claims regarding the data categories affected. No technical details about the attack vector, duration of network compromise, or encryption of systems were disclosed by either the university or the threat actors. Universidad Piloto de Colombia did not release follow-up statements beyond its initial Facebook notification, leaving the extent of operational disruption and data integrity impacts unconfirmed. The lack of public remediation updates or communication regarding potential notifications to affected individuals created uncertainty about the breach's consequences for the university community. ALPHV's inclusion of the institution on its leak site indicated unsuccessful ransom negotiations or refusal to pay, consistent with the group's typical extortion tactics against other victims.

Sources

Sources available to members: 1 source.

CSIDB