A significant data breach at Ravin Academy, a cybersecurity training center linked to Iran's Ministry of Intelligence and Security, resulted in the exposure of personal information belonging to over 1,000 individuals enrolled in its technical programs. The leaked records included usernames and phone numbers, and the incident was confirmed by the organization via its Telegram channel. Ravin Academy, established in 2019 and sanctioned by the U.S. Treasury in 2022 for supporting Iranian intelligence operations, offers courses in both defensive and offensive cyber skills, such as red-teaming, malware reverse engineering, and vulnerability analysis.
The full dataset was provided to U.K.-based activist Nariman Gharib, who published portions of the information online. The academy characterized the breach as an attempt to damage its reputation and undermine national cybersecurity efforts in Iran. This incident occurred amid heightened Iranian cyber activity and increased tensions with Israel and the U.S., including a surge in ransomware attacks targeting healthcare and public health organizations. The breach highlights ongoing risks to organizations involved in nation-state cyber operations and the potential for sensitive data exposure to impact both individuals and broader security initiatives.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said the leaked material exposed the identities of students associated with the Iranian intelligence-linked training academy. This expanded the understood impact of the breach by highlighting personal exposure risks for attendees.
Ravin Academy publicly confirmed that it had experienced a data breach. The confirmation followed earlier reporting that the incident exposed sensitive records tied to the institution and its students.
An apparent breach affected Ravin Academy, an Iranian cybersecurity school reportedly linked to the Ministry of Intelligence and Security. Reporting indicates internal data was exposed, including information related to students and academy operations.
4 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.