On August 23, 2024, the official website of Guatemala’s Ministry of Education (www.mineduc.gob.gt) appeared on the RansomHub ransomware group’s leak site. The listing states that internal files were exfiltrated during a ransomware attack on the ministry, which provides educational resources, policies, and administrative services to students, teachers, and parents across Guatemala. The number of people whose information was taken remains unknown, and the exact contents of the stolen files have not been detailed by the threat actors.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch mineduc.gob.gt
Get alerted the next time mineduc.gob.gt files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about mineduc.gob.gt’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The RansomHub listing states that data was taken from the Ministry of Education’s systems and is now hosted on their extortion platform. The disclosure indicates that the files were obtained through a ransomware deployment, though it does not specify the initial access method, the volume of data, or the precise data types involved. As of the publication date, the ministry had not issued a public breach notification quantifying affected records or naming the specific categories of information at risk. The leak site entry serves as the primary public record of the incident.
Why This Matters for You and Your Family
If you or your children have interacted with Guatemala’s education system — whether through school enrollment, teacher portals, scholarship applications, or parent accounts — your personal details may be among the stolen internal files. Names, addresses, national identification numbers, student records, and contact information are common in ministry databases. Exposure of such records can lead to identity theft, fraudulent loan applications, or targeted scams that affect your finances and credit for years. Even when exact record counts are unknown, the potential scale of a national education ministry means thousands of Guatemalan families could be impacted.
Doxxing and Identity-Chain Risks
Stolen ministry files often contain linked data points — email addresses, phone numbers, student IDs, and parent names — that attackers can chain together with information from other breaches. These identity chains allow criminals to map online handles to real-world identities, locate family members on social media, and escalate to full doxxing. Credential leaks from education portals frequently cascade into gaming account takeovers, especially for children who reuse passwords or email addresses tied to school logins. Once an attacker controls a child’s gaming profile, they can harvest additional personal details and expand the doxxing chain across platforms.