univ-rennes.fr Listed by funksec Ransomware Group
If you are a customer of univ-rennes.fr, here’s what is being claimed, and what it would mean for you.
univ-rennes.fr was listed on Funksec's leak site. Funksec claims to have stolen internal data. This is the group's claim, not a confirmed finding.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Assessing univ-rennes.fr as a vendor?
Check your own domain — free, no cardEnter a work email. We count the addresses at that domain sitting in the leaked-data corpus, and how many arrived with a password.
Were you personally caught up in this? Run a free 15-second personal scan.
On March 8, 2025, the ransomware group FunkSec added univ-rennes.fr to its leak site, claiming that internal files from the University of Rennes had been exfiltrated during a ransomware attack. The breach affects current and former students, faculty, staff, and anyone whose personal information was stored in the university’s systems. While the exact number of individuals impacted remains unknown, the exposure of internal documents means sensitive data linked to real people may now be in the hands of attackers.
What's Publicly Reported from Reporting
Public reporting indicates the University of Rennes, a major French public research institution split between science-focused University of Rennes 1 and arts-and-social-sciences-focused University of Rennes 2, was hit by a ransomware operation. The attackers successfully exfiltrated internal files before encrypting systems or while systems were locked. As of March 8, 2025, samples or proof of the stolen data appeared on the FunkSec leak site hosted on the dark web. No precise victim count or complete list of exposed data types has been publicly detailed, but the nature of “internal files” in a university environment typically includes documents containing names, addresses, dates of birth, student IDs, employee records, research data, and possibly financial or medical information tied to campus services.
Why This Matters for You and Your Family
If you or your children attended, worked at, or interacted with the University of Rennes, your information may now be circulating among criminals. Internal files exfiltrated can contain the exact details attackers need to open accounts in your name, file fraudulent tax claims, or target your family with phishing emails that look legitimate because they reference real campus activities. Even if you left the university years ago, old records often stay in active databases. For families, the risk extends beyond the individual: one compromised parent record can lead to attacks on children whose information appears in the same files, such as emergency contact forms or scholarship applications.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
The Doxxing and Identity-Chain Implications
Stolen university records frequently link email addresses, usernames, phone numbers, and physical addresses. Once attackers have that chain, they can correlate it with data from other breaches to build a complete profile. This is how isolated leaks become persistent harassment. Credential leaks like this one often cascade into gaming account takeovers, especially for students and teenagers who reuse university emails or passwords on Steam, Roblox, Discord, or other platforms. A compromised gaming account can expose chat logs, voice recordings, and location data that further enrich the identity chain, leading to doxxing, swatting, or long-term stalking. Identity-chain mapping turns one breach into dozens of new attack surfaces for you and your family.
FunkSec’s Publicly Known Track Record
Public reporting attributes the attack to the FunkSec ransomware group. The group emerged in late 2024 and has targeted a range of organizations, including educational institutions and mid-sized enterprises. Their typical playbook involves gaining initial access through phishing or exploited vulnerabilities, exfiltrating data before deploying ransomware, and then pressuring victims with threats to publish stolen files on their leak site if ransom demands are not met. FunkSec’s extortion style relies on public shaming and the threat of selling or freely releasing sensitive internal documents rather than solely focusing on encryption alone.
What to do
- Run a DoxxScan to map every link between your university email, handles, phone numbers, and real identity so you can see exactly what chains exist today.
- Rotate any password you ever used at univ-rennes.fr anywhere else it is reused, and switch to 2FA through an authenticator app instead of SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next time your data appears it is caught and acted on within hours.
- Cover the household with DoxxScan family coverage that includes dependents and your children’s gaming accounts, which often chain back to the same addresses and emails used for school records.
- Let remediation specialists handle the time-consuming work of sending takedown requests to data brokers and monitoring for reappearance of your information.
The University of Rennes breach is a reminder that data stolen today can fuel identity theft and harassment for years. Taking concrete steps now limits how far attackers can travel down the identity chain that begins with this leak. Start your DoxxScan trial and use its continuous monitoring, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage—including children’s gaming accounts—to protect yourself and your family from cascading threats like this one.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
OTEIS Conseil & Ingénierie Listed by coinbasecartel Ransomware Group
OTEIS Conseil & Ingénierie is a French engineering and consulting firm specializing in building and …
Geb Sas Listed by thegentlemen Ransomware Group
geb.fr zoominfo.com/c/geb-sas/372743980 GEB SAS is a historic French chemical manufacturing company …
Abacus Advisors Listed by coinbasecartel Ransomware Group
Abacus Advisors was listed on the coinbasecartel ransomware leak site. The group claims to have stol…