Ransomware victim disclosure
← All victimsAHeadStart Tutoring
Claimed by Gammax · listed 4 hours ago
Status timeline
- ListedSep 29, 2026
- Data leakeddate unknown
At a glance
- Group
- Gammax
- Status
- Data leaked
- Country
- New Zealand
- Sector
- Education
- Listed on leak site
- Sep 29, 2026
About the victim
AI dossier — public-source company profileAHeadStart is a private tutoring company based in Christchurch, New Zealand, founded by Melanie Coker in 2009. They provide personalized one-on-one and small group tuition across multiple subjects (Maths, Science, English, Commerce) for primary, secondary (NCEA, Cambridge, IB), and adult students, with over 40 tutors and 4,000+ students served to date.
- Industry
- Education Services - Private Tutoring
- Address
- 40 Wyn Street, Hoon Hay, Christchurch 8025, New Zealand
- Employees
- 51-200
- Founded
- 2009
Attack summary
Severity: high — Confirmed exfiltration of significant data volume (57.94 GB, 72k+ files) from an educational organization. Educational institutions hold PII of minors and sensitive learning records; the scale and nature of the dataset suggests broad exposure of student and staff information.Gammax claims to have exfiltrated 72,135 files (57.94 GB) of data from AHeadStart. The post does not specify the nature of the data or publish proof files.
Data the group says was taken
AI dossier — extracted from the leak post- student records
- tutor information
- billing/payment data
- educational assessments
- personal contact details
What the group claims
AHeadStart is a Christchurch-based tutoring company in New Zealand that provides personalized instruction for primary, secondary, and adult learners. ...
The leak post
captured from the group's site40 Wyn Street, Hoon Hay, Christchurch 8025, New Zealand Access the complete dataset including 72,135 files (57.94GB)
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

