Arizona Caregiver Training Portal Allegedly Targeted in Database Leak

A threat actor claims to have obtained a database from Assisted Living Training School's online Moodle platform, exposing student and staff account information, though the claim remains unverified.
Screenshot of a threat actor’s forum post allegedly offering a database from the online learning portal for Assisted Living Training School (online.arizonacaregivertraining.net), with a blurred sample of purported Moodle user records.
The threat actor claims to be offering a “fresh” database from Assisted Living Training School’s online Moodle portal. BreachNews blurred the leaked data sample because it contains sensitive information. The authenticity and age of the alleged database have not been independently verified.

A threat actor is allegedly offering a database purportedly stolen from online.arizonacaregivertraining.net, the online learning portal operated by Assisted Living Training School (ALTS). The claim surfaced on July 18, with the actor describing the database as “fresh” and sharing a sample that appears consistent with a Moodle learning management system.

BreachNews reviewed the leaked sample but could not independently verify when the data was obtained or whether the complete database is authentic. Assisted Living Training School had not issued any public statement at the time of publication.

Training provider offers Arizona caregiver certification

Assisted Living Training School (ALTS) is an Arizona-based education provider that delivers caregiver and assisted living manager certification programs. Founded in 2001, the organization states that its programs are approved by the National Center for Institutions and Alternatives (NCIA) and recognized by the Arizona Department of Health Services. The school offers both in-person and online instruction, with an emphasis on flexible scheduling and self-paced learning for students balancing work and other commitments.

The alleged victim, online.arizonacaregivertraining.net, serves as the school’s online learning platform, where students can access coursework, complete training requirements, and manage their accounts through a Moodle-based learning management system.

Leaked sample resembles Moodle user database

The data shared by the threat actor closely matches the structure of Moodle’s mdl_user table. The sample includes fields commonly associated with Moodle deployments, including authentication methods, account status, usernames, email addresses, phone numbers, language preferences, timezone settings, and bcrypt password hashes.

BreachNews also observed administrator accounts, instructor-related email addresses, and contact information that appears consistent with publicly available details for Assisted Living Training School. Several usernames include timestamp-style suffixes that are commonly generated when Moodle renames deleted or suspended accounts, providing another indicator that the sample may have originated from a legitimate Moodle database.

Although these characteristics make the sample appear technically credible, they do not independently confirm that a recent compromise occurred.

Student and staff information may be exposed

If authentic, the alleged database could expose personally identifiable information belonging to students, instructors, and administrative staff using the online training platform.

  • Names
  • Email addresses
  • Phone numbers
  • Physical addresses
  • Usernames
  • Bcrypt password hashes
  • Institution and enrollment details
  • Account configuration metadata

The exposed password hashes appear to use the $2y$ bcrypt format, which is significantly more resistant to password cracking than older hashing algorithms. However, weak passwords may still be vulnerable to offline cracking attempts if attackers obtain sufficient computing resources.

Freshness of the data remains unclear

Despite the threat actor describing the database as “fresh,” there is currently no evidence establishing when the information was allegedly obtained. The data could represent a recent compromise, an older breach that has not previously been disclosed, or a historical database that has resurfaced online.

At the time of publication, BreachNews found no publicly available statement from Assisted Living Training School acknowledging a cybersecurity incident affecting its online learning platform.

While the leaked sample contains multiple indicators consistent with a genuine Moodle user database, there is not yet sufficient evidence to independently verify the scope, age, or origin of the alleged leak. Until additional information emerges or the organization confirms an incident, the claim should be treated as unverified.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map