Ransomware victim disclosure
← All victimsAcadémie de Montpellier / CSJM
Claimed by MEDUSA LOCKER (aka BAVACAI · listed 5 days ago
Status timeline
- Listed
May 16, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileAcadémie de Montpellier is a French regional education authority (rectorat) overseen by the French Ministry of National Education, responsible for administering primary, secondary, and higher education across the Hérault, Gard, Lozère, and Pyrénées-Orientales departments. The CSJM (Centre de Services du Jury des Mentions) likely refers to an administrative unit within or affiliated with the academy. As a public institution, it manages student records, staff data, and educational operations for a large geographic area in southern France.
- Industry
- Public Education Administration
- Address
- 31 rue de l'Université, 34064 Montpellier Cedex 2, France
- Employees
- 1001-5000
Attack summary
Severity: high — The victim is a public education authority handling PII at scale including student and staff records; data has been published (disclosed status: data_published) with demo files already accessible, indicating confirmed exfiltration of sensitive personal data from a government-affiliated institution.MEDUSA LOCKER (aka BAVACAI) claims to have exfiltrated data from Académie de Montpellier / CSJM and has published demo access showing up to 10 files per folder as proof, with full data to be released following publication. The nature of the exfiltrated data has not been fully detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Student records
- Staff personal data
- Administrative documents
- Internal correspondence
The group's post references roughly 10 proof files.
What the group claims
French academic institution - Académie de Montpellier / CSJM
The leak post
captured from the group's site## Académie de Montpellier / CSJM ⚠ Demo access — showing up to 10 files per folder. Full data will be available after publication.
Screenshot of the leak post

Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
