SBC Global, Bitfinex, Coinmom, and Rutgers University Part 2 Listed by flocker Ransomware Group
If you are a customer of SBC Global, Bitfinex, Coinmom, and Rutgers, here’s what is being claimed, and what it would mean for you.
the four victims of our attack – SBC Global, Bitfinex, Coinmom, and Rutgers University. You refused to pay, and now […]
— from Flocker’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
SBC Global, Bitfinex, Coinmom, and Rutgers customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On May 5, 2024, the Flocker ransomware group publicly listed four organizations on its leak site, including Rutgers University, declaring that the victims had refused to pay and would now face publication of stolen internal files.
Primary Disclosure Details
The Flocker leak site posting explicitly names Rutgers University alongside SBC Global, Bitfinex, and Coinmom as the four victims of its ransomware attack. The group states that internal files were exfiltrated and warns that the data will be released because ransom demands were not met. The disclosure does not quantify how many records were taken, list specific file types beyond “internal files,” or provide a firm publication deadline. Public reporting on the incident draws directly from the onion-site listing hosted at the address indexed by ransomware.live.
Why This Matters for You and Your Family
When a major public university suffers a ransomware breach, the personal information of students, alumni, faculty, staff, and their families is often caught in the net. Even though the Flocker listing does not detail exact data types, university systems routinely hold Social Security numbers, dates of birth, addresses, financial aid records, health information, and academic transcripts. Once those records appear on a leak site, they become raw material for identity theft, tax fraud, and phishing campaigns aimed at you or your children. The breach therefore carries direct consequences for any household connected to Rutgers through enrollment, employment, or dependent status.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Doxxing and Identity-Chain Risks
Exposed university files frequently contain email addresses, usernames, and directory listings that link real identities to gaming handles, social-media accounts, and family relationships. Attackers chain these fragments together: a leaked Rutgers email leads to a reused password on a gaming platform, which yields chat logs containing home addresses or phone numbers. The result is a doxxing cascade that can expose your family’s physical location, children’s names and ages, and financial details. Credential leaks like this one routinely fuel account takeovers on Steam, Roblox, Discord, and other services popular with students and siblings.
Flocker Ransomware Group Track Record
Public reporting attributes the emergence of Flocker to late 2023. The group has targeted a mix of corporations, cryptocurrency platforms, and educational institutions using double-extortion tactics: encrypt victim systems, exfiltrate sensitive files, then threaten public release unless payment is made. Notable prior victims listed on leak sites include smaller financial services firms and regional healthcare providers. Flocker’s typical playbook begins with phishing or exploited remote-access tools for initial access, followed by lateral movement to harvest internal shares, then exfiltration over several days before encryption. The group maintains its own leak portal rather than relying exclusively on third-party data brokers, a pattern consistent with mid-tier ransomware operators seeking to control their narrative and pressure victims directly.
What to do
- Run a DoxxScan to map every link between your Rutgers-related emails, usernames, phone numbers, and real-world identity so you can see the full exposure chain.
- Rotate any password used at Rutgers anywhere else it is reused, and switch to 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next leak that touches your family is caught in hours, not months.
- Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts which often chain back to the same university-linked addresses and credentials.
- Let remediation specialists handle data-broker takedown requests and opt-out processes on your behalf while you focus on securing accounts.
The incident underscores that ransomware operators continue to treat universities as high-value targets whose compromise ripples outward to thousands of ordinary families. Starting a DoxxScan trial gives you continuous monitoring across 13.1B+ breach records and 100+ platforms, AI-powered identity-chain mapping that connects handles to real identities, hands-on remediation by specialists, and household coverage that includes children’s gaming accounts at risk from credential-stuffing attacks. Source: Flocker leak site via ransomware.live
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Kessler Creative Listed by coinbasecartel Ransomware Group
Kessler Creative was listed on the coinbasecartel ransomware leak site. The group claims to have sto…
LifeBank Microfinance Foundation Listed by coinbasecartel Ransomware Group
LifeBank Microfinance Foundation is a nonprofit microfinance institution operating in the Philippine…
RXPE Group Listed by coinbasecartel Ransomware Group
RXPE Group was listed on the coinbasecartel ransomware leak site. The group claims to have stolen in…