Ransomware victim disclosure
← All victimsNorth Ridgeville City School District
listed as nrcs.net · Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedOct 25, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- Switzerland
- Sector
- Technology
- Listed on leak site
- Oct 25, 2024
About the victim
AI dossier — public-source company profileNorth Ridgeville City School District (NRCS) is a public K-12 school district located in North Ridgeville, Ohio. The district operates multiple schools serving students from preschool through grade 12, offering standard curricula, special education services, and various support programs.
- Industry
- Public Education / K-12 School District
- Address
- North Ridgeville, Ohio, USA
Attack summary
Severity: high — Confirmed compromise of a public K-12 school district with access to sensitive student and employee records, including FERPA-protected educational data, health information, and personally identifiable information at scale. High operational and privacy impact.Blacksuit claims to have compromised nrcs.net. The group's post describes an Italian hospitality/retail software company, but the actual victim appears to be a U.S. public school district—indicating either domain confusion, misdirection in the leak post, or potential name spoofing by the attacker.
Data the group says was taken
AI dossier — extracted from the leak post- Student records
- Employee personal information
- Financial records
- Health and immunization data
- Special education records
- Enrollment information
What the group claims
NRCS.net is an Italian-based company specializing in the development and provision of software solutions for the hospitality and retail sectors. It offers a range of services, including point-of-sale systems, management software, and digital payment solutions. The company focuses on enhancing operational efficiency and customer experience through innovative technology tailored to client needs.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

