Ransomware.live listed EduSpa as a reported victim on 2026-08-06, and the entry was tagged as reports-only. The source material provided for this review did not include a public breach notice, regulator filing, or company statement confirming the incident. No confirmed data types, affected count, or notice timeline were available in the sources reviewed. The raw ingest data tied the entry to an attack date of 2026-08-06, but it did not provide evidence about whether Social Security numbers, medical information, or financial information were exposed. Further details may be released later through company notices, regulatory filings, or court records, but none were identified in the sources consulted here.