Ransomware victim disclosure
← All victimsGrey High School
listed as greyhighschool.com · Claimed by Lockbit5 · listed 4 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profileGrey High School is a leading independent secondary school founded in 1856, located in South Africa (based on Afrikaans language offerings and timezone +02:00). The school operates a comprehensive academic program across multiple disciplines, maintains boarding facilities (Meriway House), and offers extensive extracurricular activities including sports, arts, and community service programs.
- Industry
- Secondary Education
- Founded
- 1856
Attack summary
Severity: high — Educational institution with confirmed data publication (disclosed_status: data_published) affecting minors and staff. School records typically contain PII at scale and are regulated in most jurisdictions. No exfiltration of specific sensitive categories confirmed, but the institutional context and publication status elevate risk.LockBit5 claims to have compromised Grey High School and published data. The leak post references the school by name but the truncated excerpt provides no specific detail on what data was exfiltrated or whether encryption occurred.
Data the group says was taken
AI dossier — extracted from the leak post- student records
- staff information
- financial/banking details
- admissions data
- academic records
What the group claims
Grey remains as one of the leading schools in the country, with a culture and value system that supp...
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

