Ransomware victim disclosure
← All victimsNotre-Dame du Grandchamp
Claimed by Nightspire · listed 2 months ago
Status timeline
- ListedApr 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- France
- Sector
- Education
- Listed on leak site
- Apr 1, 2026
About the victim
AI dossier — public-source company profileNotre-Dame du Grandchamp is a French Catholic private educational institution offering programmes from CAP (vocational certificate) to Master level, including secondary, higher education, apprenticeship and preparatory classes. It operates two campuses in the Île-de-France region (Versailles and Montigny-le-Bretonneux) and serves approximately 1,300 secondary pupils, 1,200 higher-education students, and 550 apprentices.
- Industry
- Catholic Private Education (Secondary & Higher Education)
- Address
- 97 rue Royale, 78000 Versailles, France; 7 rue J. le Theule, 78180 Montigny-le-Bretonneux, France
Attack summary
Severity: critical — Confirmed exfiltration and publication of regulated sensitive data at scale, including medical records of minors (students), PII of both students and employees, and HR records — all categories subject to GDPR and special-category data protections under EU law.The Nightspire ransomware group claims to have exfiltrated sensitive data from Notre-Dame du Grandchamp and has published it; stolen data reportedly includes student medical records, HR and employee personal data, student personal and academic data, and contracts and administrative documents.
Data the group says was taken
AI dossier — extracted from the leak post- Student medical records
- HR and employee personal data
- Student personal data
- Student academic data
- Contracts
- Administrative documents
What the group claims
- Students Medical Records- HR& Employee Personal Data- Student Personal & Academic Data- Contracts & Administrative Documents
Sources
- Victim sitewww.nd-grandchamp.fr
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

