Ransomware victim disclosure
← All victimsBattle Creek Public Schools
Claimed by Rhysida · listed 2 hours ago
Status timeline
- ListedAug 25, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Sector
- Education
- Listed on leak site
- Aug 25, 2026
- Data size
- 1.08 TB
- Records
- 5941 files
About the victim
AI dossier — public-source company profileBattle Creek Public Schools is a public school district in Nebraska providing educational services for students from pre-kindergarten through 12th grade.
- Industry
- Public Education
- Address
- Nebraska, US
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data: PII of named minors (students) at scale, including special-education and disability records (protected under FERPA and ADA), discipline records, and federal education compliance documentation. Exposure of minors' identifiable educational and health information represents critical risk.Rhysida claims to have exfiltrated student records including IEP/special-education files, disability determination notices, discipline/suspension records, and federal funds compliance documentation (ESSA/Title I applications) and staff health-spending claims.
Data the group says was taken
AI dossier — extracted from the leak post- Student records of named minors
- IEP/special-education files
- Disability determination notices
- Discipline/suspension records
- Federal funds compliance trail (ESSA/Title I)
- Staff health-spending claims (payflex/EHA)
What the group claims
Public school district in Nebraska providing educational services for students from pre-kindergarten through 12th grade.
The leak post
captured from the group's siteCRI Electric is a veteran-owned business based in San Antonio, providing professional electrical services since 1998. They cater to both residential and commercial clients, offering services such as emergency electrical repairs, EV charger installations, and home rewiring. **We are pleased to present:** Employee's federal account artifacts** (`HR-Confidential\Israel's Forms`): Login.gov personal recovery key (VA identity), TSP (retirement savings), ID.me, DoD DS Logon, PIEE (DoD contract payments)151 vendor W-9 forms** (SSN/EIN), payroll docs, HR-lawyer (privileged) correspondence, OSHA-adjacent injury/incident reports with photos.Public-sector bid pricing** (2025�2026: SAWS HQ EV charging, SAISD, NISD) � bid-competitiveness and Davis-Bacon certified-payroll context.Corporate docs (SDVOSB certification, Articles, bylaws, stock ledgers), QuickBooks financials, a Power of Attorney With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, l…
Data the group says was taken
- student records of minors
- IEP/special-ed files
- disability determination notices
- discipline/suspension records
- federal funds compliance documents
- staff health-spending claims
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

