On January 29, 2024, Castilleja School appeared on the leak site operated by the Akira ransomware group. The private girls’ school serving grades six through twelve confirmed that attackers had exfiltrated roughly 10GB of internal files, including documents tied to the education process, administrative records, and information about students. The listing does not specify the exact number of individuals affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details in the Akira Listing
The primary disclosure on the Akira leak site states that the group intends to publish the stolen data unless the school meets their demands. It describes the archive as containing “various files containing education process and administrative information” along with “numerous files with information about students.” No precise count of records or breakdown of data fields is provided. The notification does not detail which specific systems were initially compromised or the exact date of intrusion. Public reporting on Akira indicates the group typically exfiltrates data before encrypting systems and uses the leak site as leverage for extortion.
Why This Matters for You and Your Family
When a school’s internal files are stolen, the exposure reaches far beyond the institution. Families entrust these organizations with names, dates of birth, addresses, medical notes, and sometimes Social Security numbers for enrollment and emergency contacts. If your daughter attends Castilleja or any similar independent school, your family’s details may now sit in an attacker-controlled archive. Even without a full record count, the 10GB volume signals a substantial cache that can be searched, sold, or weaponized. The breach also underscores how educational institutions remain attractive targets because they hold sensitive information on minors who cannot easily monitor or remediate identity misuse themselves.
Doxxing and Identity-Chain Risks
Student and administrative files often link email addresses, phone numbers, home addresses, and parent names. Attackers and subsequent data brokers can chain these pieces together with usernames from gaming platforms, social media handles, or older breaches. A single leaked school record can anchor a larger profile that reveals where your family lives, where your children spend their time, and which accounts they use. This is exactly how doxxing campaigns begin: one credential leak cascades into account takeovers on Roblox, Discord, or school portals, exposing chat logs, location data, or photos. Credential leaks like this one frequently surface months later on underground forums, giving thieves time to map relationships before victims notice.