National Flight Academy
bd_e9a87094e084e663 · schema v1 · pii pii-v1
Full breach record for National Flight Academy →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Dispossessor on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
The National Flight Academy, LLC is a subsidiary of the Naval Aviation Museum Foundation. The Academy is an educational activity authorized but not endorsed or financially supported by the United States Navy. In 1993, the Foundation began to focus on youth education programs including a Distinguished Lecturer Series, Kids Day in Space, Kids Day in Antarctica, Kids Day with the Blue Angels, and special teacher education programs. In 1996, the Foundation implemented its Flight to Excellence program, where as of 2019, more than 575,000 children from five states have participated. In 1999, the Foundation created the Flight Adventure Deck, a 39-station interactive exhibit on aviation, which addresses the scientific and mathematical principles of aerodynamics, propulsion and meteorology. The network of this company has been breached and as a result over 200GB of data leaked from there. These leaked data contains a lot of sensitive data related to patients and employees, including aerodynamics, propulsion, navigation, communications, flight physiology and meteorology. We have been trying to reach to the National Flight Academy with an offer to protect leaked data for a several weeks. All our messages still unanswered. NFA board of directors being called everyday for a week with the message about leaked data. None of the NFA management answered our messages, yet. That is why you can see the sample of this leaked data. We have been trying to reach NFA management for a very long time. Since we are people of business and we our main goal is the money we will provide very last opportunity for the NFA to protect their patients missing data. NFA company have 3 days to contact us and start the negotiations. Otherwise all the data will be disclosed to public
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Apr 18, 2024
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
dispossessor
According to ransomware.live, This is not a ransomware group but a data broker