DisclosureLens
GLOBALMalwareEducationEducationRansomwareLapsus$LapsusRansom DemandedActor NamedMedium

Lille University

bd_51a7c555d04a7dfd · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Mar 1, 2026

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for Lille University

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Lapsus$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: EducationDiscovered: 2026-03-01

Source: Ransomware.live

Post text · scraped from the leak site

Lille University, also known as University of Lille, is a well-recognized public university located in Lille, France. It was established in 1562 and offers a wide range of educational programs covering multiple disciplines. The university is known for its focus on research and innovation, and boasts a diverse student population from around the globe. In addition to its academic achievements, Lille University also encourages sports and cultural activities.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Mar 1, 2026

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2021-12-10

lapsus$

According to ransomware.live, Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.

25 victims claimed globally25 tracked hereFull profile →