On July 28, 2022, the Argentine university email service correounir.com.ar appeared on the LockBit 3.0 ransomware leak site. The listing states that the group exfiltrated internal files during a ransomware attack and threatens to publish the stolen data if demands are not met. Anyone whose email address ends in @correounir.com.ar, or whose personal documents were stored on the university’s systems, may now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch correounir.com.ar
Get alerted the next time correounir.com.ar files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about correounir.com.ar’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The primary disclosure on the LockBit 3.0 leak page states that correounir.com.ar was listed after an intrusion in which the attackers claim to have stolen internal files. The entry does not specify the volume of data taken, the exact file types, or the number of individuals affected. It simply states that internal data was exfiltrated and sets a publication deadline typical of the group’s extortion timeline. No official breach notification from the university has surfaced publicly, so the precise scope remains unconfirmed by the victim organization itself.
Why This Matters for You and Your Family
If you or any member of your household has an email account at correounir.com.ar, your contact details and any documents tied to that address could now sit in a criminal archive. Internal files often contain names, national ID numbers, addresses, academic records, financial details, or scanned identification documents. Once such information leaves institutional control, it can be sold, traded, or used to target you with identity theft, phishing, or financial fraud. Your family members listed as emergency contacts or co-signers on university paperwork face the same risk even if they never had their own university email.
The Doxxing and Identity-Chain Risk
A single institutional breach rarely stops at the initial data set. Attackers and subsequent buyers map email addresses to personal accounts across the web, linking them to social-media handles, gaming profiles, and family addresses. This creates an identity chain that can lead to doxxing, account takeovers, and harassment. Credential leaks of this kind frequently cascade into gaming accounts belonging to you or your children, where the same password or recovery email is reused. The result is a widening web of exposure that can surface months or years later.