On June 2, 2026, the ransomware group apt73 added the Armenian government domain elections.mia.gov.am to its leak site, stating that it had exfiltrated internal files from the Central Election Commission of Armenia during a ransomware attack. The listing, hosted on an onion address and mirrored on ransomware.live, includes a message referencing contact with the Turkish Wolves of Turan group. The number of people whose data may have been exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch elections.mia.gov.am from WOLVES OF TURAN
Get alerted the next time elections.mia.gov.am from WOLVES OF TURAN files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about elections.mia.gov.am from WOLVES OF TURAN’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that elections.mia.gov.am systems were compromised and that internal files were successfully exfiltrated. The apt73 group published the victim on its leak site on June 02, 2026, following the pattern used in its other ransomware cases. The posted note begins with “Hello, dear visitors of Bashe’s blog” and claims contact was made with the Wolves of Turan group, though the exact nature of that communication is not detailed in available reporting. No specific volume of records or list of exposed data types has been published on the leak page itself.
Why This Matters for You and Your Family
When government election systems are breached, the information inside often includes names, addresses, dates of birth, contact details, and sometimes national identification numbers of voters or officials. If your family voted in Armenian elections or has any connection to government services tied to that infrastructure, your personal records may now sit in an attacker’s archive. Credential leaks like this one frequently cascade into account takeovers on email, banking, and social media, putting everyday families at risk of identity theft, phishing, and harassment that can last for years.
The Doxxing and Identity-Chain Implications
Once internal government files leave official control, they become raw material for doxxing chains. Attackers or resellers can link an email address found in the leak to usernames on social platforms, gaming services, and family accounts. A single exposed phone number or home address can connect your professional life to your children’s online profiles. Available reporting describes how such leaks routinely fuel follow-on extortion, identity fraud, and public shaming campaigns. Gaming accounts belonging to teenagers are especially vulnerable because kids often reuse passwords or security questions tied to family information that now sits in the stolen dataset.