On December 21, 2024, the Salvadoran higher-education institution ITCA appeared on the leak site operated by the safepay Ransomware Group. The listing states that internal files were exfiltrated during a ransomware attack; the number of affected individuals and the precise volume or types of records remain unknown because the disclosure provides no further detail.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch itca.edu.sv
Get alerted the next time itca.edu.sv files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about itca.edu.sv’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The safepay leak site entry, first observed on December 21, 2024, states that ITCA.edu.sv suffered a ransomware intrusion in which attackers successfully copied internal files before encryption. The listing does not quantify the number of records, name the specific systems compromised, or itemize the data categories taken. It simply states that exfiltrated material is available for review by authorized parties on the extortion portal. Revenue figures sometimes attached to such listings, in this case $56.5 million, typically reflect the victim organization’s estimated annual turnover rather than ransom amounts demanded.
Why This Matters for You and Your Family
Even when a breach originates at a university or technical institute, ordinary people are often the ones placed at risk. Students, alumni, faculty, staff members, and their families frequently have personal information stored in institutional systems: application forms, transcripts, employment records, tax identifiers, and contact details. If those files have left the organization’s control, the exposure can follow you long after graduation or employment ends. A single leaked record can supply the seed data that links your email address, phone number, and physical address across dozens of other services.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at publishing a single compressed archive. Once internal files are in their possession, the data can be parsed for names, dates of birth, national identification numbers, and email addresses that appear in spreadsheets, PDFs, or database exports. Those fragments become the starting point for doxxing chains: an attacker or downstream buyer cross-references the leaked material with information already circulating on criminal forums, gaming platforms, and social-media scrapes. The result is a detailed profile that can be used for identity theft, targeted phishing, or harassment. Credential leaks of this nature also cascade into account takeovers on personal and children’s gaming accounts that reuse the same passwords or recovery email addresses.