Ransomware victim disclosure
← All victimsSouth St Paul Public Schools
Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedMar 15, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- United States
- Sector
- Government
- Listed on leak site
- Mar 15, 2024
- Ransom demanded
- $25M
About the victim
AI dossier — public-source company profileSouth St. Paul Public Schools (SSPPS) is a K-12 school district serving the South St. Paul area of Minnesota. The district operates multiple schools including elementary, middle, and high school campuses, along with community education and early learning programs, serving 251–500 employees.
- Industry
- Public Education
- Address
- South St. Paul, Minnesota, United States
- Employees
- 251-500
Attack summary
Severity: critical — Public K-12 school district with confirmed data exfiltration and publication. Victim population includes minors whose personally identifiable information, educational records, and potentially biometric data are likely compromised. This involves regulated data (FERPA-protected student records) at scale.Blacksuit claims to have exfiltrated data from SSPPS and published it. The group is demanding $25M ransom and has marked the data as published, indicating confirmed data disclosure.
Data the group says was taken
AI dossier — extracted from the leak post- student records
- employee payroll data
- administrative files
- potentially sensitive educational records
What the group claims
South St Paul Public Schools is a company that operates in the Education industry. It employs 251-500 people and has $25M-$50M of revenue.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

