On December 31, 2025, the Universidad Nacional Autónoma de México appeared on the leak site of the ransomware group RansomHub. The listing includes 20GB of internal files that the attackers claim to have exfiltrated. The data has not yet been published, and the number of individuals whose personal information may be inside the archive remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Universidad Nacional Autónoma de México
Get alerted the next time Universidad Nacional Autónoma de México files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Universidad Nacional Autónoma de México’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the RansomHub leak site, tracked by ransomware.live, shows the Mexican university was added with a visit count of 129. The archive size is listed as 20GB, and the status remains “Published: False.” No sample files or full dataset have been released to the public as of the latest available information. The breach stems from a ransomware incident in which attackers gained access, copied internal documents, and are now using the threat of release to pressure the institution.
Why This Matters for You and Your Family
Universities hold records on students, faculty, alumni, parents, and sometimes vendors or contractors. If your name, address, phone number, email, date of birth, government ID, or financial details are among the internal files, that information could surface on criminal forums. Once exposed, it can be combined with other leaks to build a profile that puts your family at risk of identity theft, phishing, or harassment. Even if you never attended UNAM, shared family members, joint accounts, or co-signed loans can pull your household into the exposure.
The Doxxing and Identity-Chain Risk
A single institutional breach rarely stays isolated. Attackers and subsequent buyers often link the leaked data to usernames, gaming handles, social-media accounts, and phone numbers found in earlier breaches. This creates an identity chain that can lead to doxxing, account takeovers, and targeted scams. Credential leaks like this one frequently cascade into gaming accounts belonging to you or your children, where stolen university email passwords are tested against Steam, Roblox, Epic, or Discord. The result can be lost progress, virtual goods, or further personal details extracted from chat logs and linked payment methods.