nccer.org Listed by Qilin Ransomware Group
If you are a customer of nccer.org, here’s what is being claimed, and what it would mean for you.
With nearly 30 years of expertise in building craft training and assessments, NCCER has added Construction Leadership to its portfolio. These online programs go beyond field experience, focusing on essential leadership skills. Offering flexib ...
— from Qilin’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On March 21, 2025, the National Center for Construction Education and Research (NCCER) appeared on the leak site of the qilin ransomware group. The organization, known for nearly 30 years of craft training and assessment programs, is claimed to have had internal files exfiltrated during a ransomware attack. Public reporting indicates that the number of individuals directly affected remains unknown, but the exposure of internal documents raises immediate concerns for anyone whose personal or employment records may have been stored in NCCER systems.
Watch nccer.org
Get alerted the next time nccer.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about nccer.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Available reporting describes the incident as a ransomware attack in which qilin actors gained access, exfiltrated data, and later listed nccer.org on their leak site. The exposed material consists of internal files. No confirmed total of records or specific victim count has been published. The listing appeared on March 21, 2025, consistent with qilin’s typical practice of publishing victim data after an initial extortion window expires.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Why This Matters for You and Your Family
When training organizations like NCCER suffer breaches, the people most likely to be exposed are current and former students, instructors, contractors, and their families. Internal files can contain names, addresses, Social Security numbers, employment histories, certification records, and contact details. Once that information leaves a trusted environment, it can be sold, traded, or used to target you with identity theft, tax fraud, or phishing campaigns. For families, a single breach can create months or years of cleanup work if children’s information is included in training or scholarship records.
Credential leaks from such incidents frequently cascade into account takeovers elsewhere. Passwords or email addresses reused across services become entry points for attackers to seize gaming accounts, email, or financial portals.
The Doxxing and Identity-Chain Risks
Exfiltrated internal files often contain enough personal details to link disparate online handles to real-world identities. Attackers can combine leaked training records with publicly available information to build detailed profiles. These profiles enable doxxing, swatting, or sustained harassment. Gaming accounts belonging to you or your children are particularly vulnerable because usernames, email addresses, and passwords exposed in one breach can unlock linked profiles on Steam, Discord, Roblox, or other platforms. What begins as a construction-industry breach can quietly expand into full identity compromise across both professional and personal life.
Qilin Ransomware Group’s Track Record
Public reporting attributes the attack to the qilin ransomware group. The group emerged in 2022 and has since targeted organizations across multiple sectors. Notable prior victims include healthcare providers, manufacturers, and educational institutions. Qilin’s typical playbook involves initial access through phishing or exploited remote desktop protocols, followed by data exfiltration and deployment of ransomware. The group then demands payment and, if unmet, publishes samples or full datasets on their leak site to pressure victims. Their extortion style combines data-theft threats with file-encryption demands.
What to do
- Run a DoxxScan to map every link between your emails, phone numbers, usernames, and real identity so you can see exactly what chains exist from this claimed breach.
- Rotate any password you used on nccer.org or related training portals anywhere it has been reused, and immediately enable two-factor authentication through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your information is caught in hours instead of months.
- Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts, which often chain back to the same addresses and emails leaked in incidents like this.
- Let remediation specialists handle takedown requests across data brokers and leak sites so you do not have to negotiate or chase them yourself.
The incident underscores a simple reality: data stolen in one industry rarely stays contained. DoxxScan by GalaxyWarden delivers that visibility through continuous monitoring across 13.1B+ breach records and 100+ platforms, AI-powered identity-chain mapping, and hands-on remediation by specialists who manage the cleanup work for you and your entire household, including children’s gaming accounts. Start your DoxxScan trial today to close the gaps this claimed breach has created.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.