Back to Romania Cyber Monitor
Ransomware claimUnverified claim

Universitatea de Vest „Vasile Goldiș” din Arad: ransomware group listing (unconfirmed claim)

Reported 26 July 2026

Executive summary

On 26 July 2026, Qilin listed Universitatea de Vest „Vasile Goldiș” din Arad on a data-leak site monitored by public ransomware intelligence sources.

What was reported

qilin listed Universitatea de Vest „Vasile Goldiș” din Arad on a data-leak site monitored by public ransomware intelligence sources on 2026-07-26T14:29:53.747725+00:00. This entry records a public claim made by a ransomware group. It does not by itself prove that the organisation was compromised or that the threat actor's statements are accurate. At the time of writing, the claim has not been independently confirmed by the organisation, DNSC, another Romanian authority, or another authoritative source. Universitatea de Vest „Vasile Goldiș” din Arad is reported to operate in the Education sector.

What has been independently confirmed

At the time of writing, this claim has not been independently confirmed by the organisation, DNSC, another Romanian authority, or another authoritative source.

Timeline

About Qilin

Qilin (also referenced as Agenda) is a ransomware-as-a-service operation active since 2022, known for double-extortion attacks and a leak site used to pressure non-paying victims.

Why this sector is targeted

Educational institutions are frequently targeted, often because of comparatively under-resourced IT security teams relative to the amount of personal data they hold.

What organisations can do about ransomware risk

Regardless of whether this specific claim is accurate, ransomware remains one of the most common serious incidents Romanian organisations face. The basics below stop most attacks before they reach the encryption stage:

Methodology and limitations

This page is generated automatically from a public ransomware threat-intelligence feed. See /methodology for the full Romania eligibility and verification policy.

This entry records a public claim made by a ransomware group. It does not by itself prove that the organisation was compromised or that the threat actor’s statements are accurate.

If you want a proper, individualised review of your security posture rather than a generic checklist - hardening, incident response planning, or a full audit - get in touch.

Sources