Ransomware victim disclosure
← All victimsDesert Christian Schools
listed as Desert Christian Schools (DCS) · Claimed by Medusalocker · listed 1 month ago
Status timeline
- ListedMay 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Medusalocker
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- May 5, 2026
About the victim
AI dossier — public-source company profileDesert Christian Schools is a K-12 Christian school affiliated with First Baptist Church of Lancaster, California. The school operates educational programs and administers childcare services through involvement with DCFS programs and local municipal initiatives.
- Industry
- K-12 Education
- Address
- Lancaster, California, USA
Attack summary
Severity: high — Confirmed exfiltration of sensitive data including payroll records (PII, SSNs), financial statements, and tax forms affecting employees and potentially families in childcare programs. School board minutes may contain additional sensitive administrative data.Medusalocker claims to have exfiltrated financial documents, payroll records, school board minutes, and administrative data from Desert Christian Schools' systems.
Data the group says was taken
AI dossier — extracted from the leak post- ADP payroll records
- DCFS childcare program data
- Financial statements (P&L, Balance Sheet, Trial Balance)
- 1099 tax forms
- School Board minutes (2025)
- City of Lancaster Water Safety program records
What the group claims
K-12 Christian school affiliated with First Baptist Church of Lancaster, CA. ADP payroll, DCFS childcare program, City of Lancaster Water Safety program. Financial docs: P&L, Balance Sheet, Trial Balance, 1099s. School Board minutes 2025.
Sources
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

