On March 22, 2026, the French boarding school Notre-Dame du Grandchamp appeared on the leak site of the nightspire ransomware group. Public reporting indicates that attackers exfiltrated internal files containing students’ medical records, HR and employee personal data, student personal and academic records, and contracts and administrative documents. The number of people affected remains unknown, but any current or former student, parent, or staff member whose information passed through the school’s systems could be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from Reports
Available reporting describes a classic ransomware incident: nightspire gained access, encrypted systems, and later published a sample of stolen data when the school did not meet their demands. The leak site lists the victim under the exact name “Notre-Dame du Grandchamp@nightspire.” The exposed material includes sensitive health information, employment records, academic transcripts, and legal contracts. No evidence has surfaced that payment was made or that the data was removed from the leak site.
Why This Matters for You and Your Family
When a school’s internal files leave its control, the people listed in them lose the ability to control their own information. Medical histories, home addresses, phone numbers, dates of birth, and parent contact details can be combined with other leaks to build detailed profiles. For families, this often means children’s data may now be circulating alongside adults’. Once information reaches criminal forums, it can be sold, traded, or used months or years later. The breach therefore affects not only past students but also siblings, parents, and grandparents whose details appear in emergency contacts or family records.
The Doxxing and Identity-Chain Risk
Credential leaks of this type rarely stop at one incident. A phone number or email taken from a school contract can be matched to gaming accounts, social-media handles, or family shared logins. Attackers follow these links to map an entire household. Children’s gaming usernames are especially vulnerable because young users often reuse simple passwords or email addresses tied to the family domain. The result is a chain that leads from an old school record to live accounts that can be hijacked for harassment, extortion, or identity theft. DoxxScan by GalaxyWarden is built for exactly this problem, offering continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping that connects handles to real identities, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts.