Gruppo Spaggiari Parma, an Italian provider of school administration software, has been identified as the victim of a ransomware-linked breach attributed to the xpl0itrs group. Reporting says the incident was discovered on August 20, and the attack has been characterized as both ransomware activity and a data breach affecting an organization tied to Italy’s education sector.
A user operating under the name xpl0itrs is now offering an alleged 6.1 TB dataset for $50,000, claiming it contains identity cards, tax and income records, diplomas, report cards, prescriptions, pediatric and medical certificates, vaccination records, and driving licences. Gruppo Spaggiari Parma has acknowledged a security incident but said it was limited to a forms component and did not affect its register or school management systems, leaving the scale of the compromise disputed; if the seller’s claims are accurate, the exposure could create long-term fraud and extortion risks, especially because the records reportedly include children’s educational and medical data.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
A forum user using the handle xpl0itrs advertised an alleged 6.1 TB dataset purportedly stolen from Gruppo Spaggiari Parma for $50,000. The seller claimed the trove included sensitive identity, financial, medical, and school records and said samples had been published after failed negotiations.
Gruppo Spaggiari Parma was identified as the victim of a ransomware attack attributed to the xpl0itrs group. The incident was described as a data breach affecting the Italy-based school management software provider.
Gruppo Spaggiari Parma publicly acknowledged that a security event occurred, stating it was confined to a forms component used to compile and submit forms. The company said its register and school management systems were separate and unaffected.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
darkwebinformer.com
Open sourcehookphish.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.