On May 5, 2024, the Flocker ransomware group publicly listed four organizations on its leak site, including Rutgers University, declaring that the victims had refused to pay and would now face publication of stolen internal files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch SBC Global, Bitfinex, Coinmom, and Rutgers
Get alerted the next time SBC Global, Bitfinex, Coinmom, and Rutgers files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about SBC Global, Bitfinex, Coinmom, and Rutgers’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Flocker leak site posting explicitly names Rutgers University alongside SBC Global, Bitfinex, and Coinmom as the four victims of its ransomware attack. The group states that internal files were exfiltrated and warns that the data will be released because ransom demands were not met. The disclosure does not quantify how many records were taken, list specific file types beyond “internal files,” or provide a firm publication deadline. Public reporting on the incident draws directly from the onion-site listing hosted at the address indexed by ransomware.live.
Why This Matters for You and Your Family
When a major public university suffers a ransomware breach, the personal information of students, alumni, faculty, staff, and their families is often caught in the net. Even though the Flocker listing does not detail exact data types, university systems routinely hold Social Security numbers, dates of birth, addresses, financial aid records, health information, and academic transcripts. Once those records appear on a leak site, they become raw material for identity theft, tax fraud, and phishing campaigns aimed at you or your children. The breach therefore carries direct consequences for any household connected to Rutgers through enrollment, employment, or dependent status.
Doxxing and Identity-Chain Risks
Exposed university files frequently contain email addresses, usernames, and directory listings that link real identities to gaming handles, social-media accounts, and family relationships. Attackers chain these fragments together: a leaked Rutgers email leads to a reused password on a gaming platform, which yields chat logs containing home addresses or phone numbers. The result is a doxxing cascade that can expose your family’s physical location, children’s names and ages, and financial details. Credential leaks like this one routinely fuel account takeovers on Steam, Roblox, Discord, and other services popular with students and siblings.