Ransomware victim disclosure
← All victimsSchool Health
Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Apr 7, 2026
About the victim
AI dossier — public-source company profileSchool Health is a US-based company founded in 1957 that specializes in the retail and distribution of health and wellness supplies to K-12 schools. Headquartered in Rolling Meadows, Illinois, the company serves educational institutions across the United States. It operates within the niche intersection of healthcare supply and the K-12 education sector.
- Industry
- Health & Wellness Supply Retail (K-12 Education)
- Address
- Rolling Meadows, Illinois, US
- Founded
- 1957
Attack summary
Severity: high — Akira claims confirmed exfiltration of 15 GB of data encompassing customer PII, HR records, and financial data. While the scale is not explicitly large enough to reach 'critical' without confirmed regulated medical/PII data at scale, the combination of customer info, HR files, and financials from a healthcare-adjacent supplier represents significant sensitive business and personal data exposure.The Akira ransomware group claims to have exfiltrated approximately 15 GB of corporate data from School Health, including financial records, HR files, drawings, project files, and customer information, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Financial records
- HR files
- Engineering or product drawings
- Project files
- Customer information
What the group claims
School Health was founded in 1957. This company provides the reta iling of health and wellness supplies to K-12 schools. Their head quarters are located in rolling Meadows, Illinois. We will upload 15gb of corporate data soon. Financials, a bit of HR files, drawings, projects, customer info, etc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

