On October 23, 2023, the Portage Township Schools district in Indiana appeared on the leak site of the Alphv ransomware group, with the attackers warning that all exfiltrated internal files would be published if a ransom was not paid within 48 hours.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch portage.k12.in.us
Get alerted the next time portage.k12.in.us files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about portage.k12.in.us’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The primary disclosure on the Alphv leak site states that the district’s systems were compromised in a ransomware attack and that attackers successfully exfiltrated internal files. The listing does not specify the number of records affected, the exact data types beyond “internal files,” or name any particular categories such as student records or employee information. It simply presents the 48-hour ultimatum and the threat of full publication. Public reporting on Alphv indicates the group often uses this public shaming tactic after initial encryption to increase pressure on victims who refuse to pay.
Why This Matters for You and Your Family
When a K-12 school district is hit, the people most exposed are the families whose children attend those schools. Your child’s personal details, medical notes, disciplinary records, or family contact information may sit inside the very “internal files” now at risk. Even if the leak-site listing does not quantify affected records, the exposure of any district-held data creates immediate identity and privacy risks for every current and former student, every employee, and every parent whose information was stored on those systems. School breaches repeatedly prove that once data leaves controlled environments it circulates quickly among identity thieves, blackmailers, and opportunistic criminals.
The Doxxing and Identity-Chain Implications
School records are especially dangerous because they link children’s names, dates of birth, addresses, and parent contacts in one place. Attackers or subsequent buyers can chain that information with usernames discovered in the same files, creating persistent doxxing profiles. A single leaked school email address or student ID can be correlated with gaming accounts, social-media handles, and family phone numbers. The result is an identity chain that follows your family for years, enabling everything from spear-phishing campaigns against your child to physical stalking based on home addresses pulled from emergency-contact forms.