On December 26, 2022, Cosmopoint College appeared on the leak site operated by the AvosLocker ransomware group. The listing states that the attackers exfiltrated roughly 80 gigabytes of internal school documents, including teacher and student contact information, student loan contracts, and internal financial records. Anyone whose personal data was held by the Malaysian institution is now at risk of exposure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details from the Leak Site
The primary disclosure on the AvosLocker portal, archived via ransomware.live, states that attackers gained access to Cosmopoint College’s systems and removed approximately 80 GB of internal files. The listing explicitly names categories of stolen material: teacher and student contact details, student loan contracts, and various financial documents. The leak site does not specify the exact number of individuals affected, nor does it provide a public sample of the data. A deadline for payment was listed, after which the group threatened to publish or sell the archive. The notification does not detail the initial access vector or the precise systems compromised.
Why This Matters for You and Your Family
If you or your children attended or worked at Cosmopoint College, your contact information, financial agreements, and possibly dates of birth or national identification numbers may now sit in an attacker-controlled archive. This kind of data fuels identity theft, loan fraud, and targeted phishing campaigns that feel personal because they reference real school records. Families often reuse the same email address or phone number across school portals, banking apps, and government services, turning one breach into multiple points of compromise. Even if you have moved on from the institution, the exposure remains relevant for years because stolen records do not expire.
Doxxing and Identity-Chain Risks
Contact lists and loan contracts frequently contain enough breadcrumbs to link an individual’s school identity to their current home address, phone number, and online handles. Attackers can combine this information with data from other breaches to build detailed profiles. Once a real name and phone number surface, doxxing escalates quickly: gaming accounts, social-media profiles, and family members become easy follow-on targets. Credential leaks of this nature routinely cascade into account takeovers on Steam, Roblox, or Discord, especially for children who share devices or email addresses with parents. The chain from an old student record to live household exposure is shorter than most people realize.