Roedean School in South Africa appeared on the LockBit 3.0 ransomware leak site on 23 July 2022, with the operators claiming they had exfiltrated internal files during a ransomware attack on the private girls’ school’s network.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details in the Leak-Site Listing
The primary disclosure comes directly from the LockBit 3.0 leak portal. The listing states that internal files were stolen and warns that the data will be published if the school does not negotiate. The entry does not specify the volume of records affected, the exact file types involved, or name any individual students, staff, or parents. It simply states that roedeanschool.co.za was compromised and that exfiltrated material is held by the attackers. Public copies of the listing, preserved via ransomware.live, show the standard LockBit countdown timer and publication threat that the group uses across its victims.
Why This Matters for You and Your Family
When a school’s internal systems are breached, the people whose information sits inside those systems are placed at immediate risk. Even though the listing does not quantify affected records, any parent, student, alumna, or staff member whose details were stored on the school network could have personal information exposed. This includes names, addresses, contact numbers, dates of birth, medical notes, fee records, or correspondence that can be pieced together for identity theft or targeted scams. For families, the breach represents a concrete privacy loss: once data leaves the school’s control, it can circulate indefinitely on criminal forums and be reused in future attacks.
The Doxxing and Identity-Chain Risks
Ransomware groups rarely stop at publishing one file dump. They often release samples that contain spreadsheets, PDFs, or email archives which, in a school environment, can link a child’s name to a parent’s email, home address, and mobile number. These fragments become the starting point for doxxing chains. A seemingly harmless class list or parent directory can be cross-referenced with other breaches to map family relationships, locate social-media accounts, or even target children’s gaming profiles that reuse the same email or password. The longer the data remains available, the higher the chance that opportunistic criminals will combine it with later leaks to build a full identity profile.