On September 30, 2024, the Puerto Rico-based Instituto de Cultura Puertorriqueña appeared on the RansomHub ransomware leak site. The listing states that internal files were exfiltrated during a ransomware attack on www.icp.pr.gov. The number of records affected remains unknown, and the precise contents of the stolen material have not been detailed by the group.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch icp.pr.gov
Get alerted the next time icp.pr.gov files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about icp.pr.gov’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The RansomHub leak page, accessible via the onion address linked through ransomware.live, lists the Instituto de Cultura Puertorriqueña as a victim and claims successful data exfiltration. The disclosure indicates that files were taken but does not specify volume, file types, or whether any personal information was included. No ransom demand figure or payment deadline is published on the listing itself. The Instituto has not yet issued a public breach notification quantifying impact or describing the data involved.
Why This Matters for You and Your Family
When a government-affiliated cultural institution like the ICP is breached, the information it holds often includes details on employees, contractors, grant recipients, artists, educators, and program participants across Puerto Rico. Even if the exact data types are not yet public, such incidents routinely expose names, addresses, dates of birth, Social Security numbers, financial records, or correspondence that can be used for identity theft. If your family has interacted with Puerto Rican cultural programs, arts funding, historical preservation projects, or museum services, your information may be among the unknown volume now in attackers’ hands. Any exposed personal records increase the risk of targeted fraud that can affect credit, tax filings, and government benefits for years.
Doxxing and Identity-Chain Risks
Stolen internal files frequently contain not just standalone records but linked datasets that map email addresses to physical addresses, phone numbers to family members, and professional roles to personal identities. Attackers and subsequent data brokers can chain these fragments with information from other breaches, turning a single cultural-agency leak into a detailed profile. This chaining accelerates doxxing, where public handles, children’s school activities, or gaming usernames become connected to real-world addresses and family relationships. Credential leaks of this nature often cascade into account takeovers on email, social media, and gaming platforms, exposing your family to harassment, extortion, or further breaches.