On November 28, 2025, Concord Academy appeared on the Medusa ransomware group’s leak site after the school’s internal files were allegedly exfiltrated during a ransomware attack. The Massachusetts-based institution serves children and young adults with autism, learning disabilities, intellectual disabilities, language processing disorders, ADD/ADHD, and other neurodiverse needs. Families who entrusted the academy with sensitive records now face the possibility that medical histories, educational evaluations, contact details, and other personal information have been stolen and may be published or sold.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details of the Breach
Public reporting indicates that Medusa listed Concord Academy on its dark-web leak portal with an identifier tied to the specific incident. The data consists of internal files exfiltrated during the ransomware deployment. No exact victim count has been released, and the precise volume or types of records remain unclear from the leak-site posting. The academy has not yet issued a public statement detailing the scope, though the presence on the Medusa site states that negotiations for decryption or non-disclosure appear to have failed.
Why This Matters for You and Your Family
When a school that supports neurodiverse students is breached, the exposed information is rarely limited to names and addresses. Educational and medical records often contain diagnoses, Individualized Education Programs (IEPs), therapy notes, guardianship documents, and emergency contact lists. For families already managing complex care needs, the leak can create additional stress and open doors to targeted scams, identity theft, or harassment that exploits a child’s vulnerabilities. Even if your own child’s file is not among those published, the incident shows how quickly any educational provider can become a target, leaving ordinary families to clean up the consequences.
The Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one database. Attackers or buyers can combine the stolen files with other publicly available data to build detailed profiles. A parent’s email from an IEP document can be matched to a gaming username, a family address, or a child’s social-media handle. These identity chains allow doxxing that follows children from school systems into online games or social platforms. Credential leaks of this nature frequently cascade into account takeovers, especially for gaming accounts that use the same passwords or recovery emails as school-related logins.