Skip to content

Qilin Ransomware Claims Musashino University in Japan, Posts Sample Documents

Ransomware // Leak-site intercept
RW-2026-0629-MUS Unverified
OPERATION QILIN aka Agenda

Active since 2022 · ~1000+ victims in 2025 · double extortion · suspected Russia-linked

Victim organization

Musashino University

Assessment
SeverityHigh
ConfidenceHigh

A university in Tokyo, Japan, listed on the Qilin (WikiLeaks2) ransomware leak site, where the actor has posted sample documents and claims to hold data stolen from the institution. Authenticity, volume, and scope are unverified.

Telemetry
GroupQilin
CountryJapan flagJapan
SectorEducation
Domainmusashino-u.ac.jp
Data volumeUndisclosed
Samples15 images
Listed2026-06-29
StatusPublished
Auction listing
Auction listingOpen
Current price-- BTC
06Days: 13Hrs: 23Min: 07Sec
Place bid
Preview
Redacted Open image Qilin ransomware leak-site listing for Musashino University, redacted
Assessment

Appearance on the Qilin leak site with sample documents posted indicates the actor has exfiltrated data and is exposing samples to pressure the institution under a double-extortion model. As a university, Musashino holds large volumes of personal data on students, applicants, and staff, along with financial and administrative records, and any authentic exposure would carry risks of identity theft, fraud, and lasting privacy harm. Qilin is among the most active ransomware operations and has repeatedly targeted education and healthcare. The posted samples appear to include financial and administrative documents, though their authenticity and full scope remain unverified. No data, samples, or actor contact channels are reproduced here. Musashino University has not publicly addressed the claim as of this post.

Want the non-redacted screenshots? Paid subscribers get full claim details and unredacted screenshots. Find this alert on the ransomware feed after subscribing. View pricing

Dark Web InformerThreat Intelligence

Latest