On February 8, 2025, the ransomware group Cicada3301 listed a substitute teacher service on its leak site, claiming to have exfiltrated 210 GB of internal files. The posting, which at the time of writing had been live for six days, threatens to publish the data unless the victim pays an undisclosed ransom.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Substitute Teacher Service
Get alerted the next time Substitute Teacher Service files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Substitute Teacher Service’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the victim is a service that connects schools with substitute teachers. The Cicada3301 leak page shows a countdown timer and lists the stolen archive as 210 GB in size. No exact number of affected individuals has been confirmed, but the nature of the business means records for teachers, school staff, and potentially students could be included. Available reporting describes the exposed material as internal files; the precise data types have not been independently verified beyond the group’s claims.
Why This Matters for You and Your Family
When a substitute teacher platform is breached, the information at risk often includes names, addresses, phone numbers, email accounts, dates of birth, and employment details for educators and support staff. If your family includes anyone who works as a substitute, registers with such agencies, or has children in schools that use them, your personal data may now sit in a ransomware actor’s archive. Credential leaks from these incidents frequently cascade into gaming accounts, email takeovers, and further identity theft that can affect every member of the household.
The Doxxing and Identity-Chain Implications
Ransomware groups rarely stop at one database. Once internal files leave the victim’s network they can be sold, traded, or used to map relationships between email addresses, phone numbers, usernames, and physical addresses. A single exposed substitute-teacher record can link a parent’s work email to a child’s school login, a family gaming handle, or an old streaming account. These identity chains allow attackers to build convincing profiles for phishing, SIM-swapping, or targeted harassment. Public reporting on similar incidents shows that doxxing often follows initial data leaks within weeks.