A ransomware group called incransom has claimed it stole data from The New Community School, a small Richmond, Virginia school for students with dyslexia. The school has not publicly confirmed the breach or its scope. Families and staff should watch for official school communication and consider monitoring credit reports, especially for minors, as a precaution.
| Company | The New Community School |
|---|---|
| Industry | Education |
| Data Types Exposed | Student Names and Dates of Birth, Parent or Guardian Contact Information, Enrollment and Academic Records, Special Education Records, Staff Personnel Information, Social Security Numbers, Financial Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the New Community School Data Breach?
A ransomware group calling itself incransom has claimed it accessed data belonging to The New Community School, a small independent day school in Richmond, Virginia. The group listed the school on its dark web leak site as a victim. As of now, the school has not publicly confirmed this claim.
Because this is an extortion group’s own claim, many details remain unclear. The exact timeline of the alleged New Community School data breach has not been publicly disclosed. It is also not yet known what systems the attackers may have accessed, or how they gained entry.
Ransomware groups like incransom typically post stolen files or data samples on leak sites to pressure victims into paying a ransom. However, a listing on a leak site alone does not always confirm the scope of a breach. As a result, affected families and staff should watch for official communication directly from the school.
At this stage, there is no public indication that a forensic investigation has started or concluded. Because the school has not issued a statement, important facts such as what data was taken and how many people are affected remain unverified by the institution itself.
Who was affected?
The New Community School serves students in grades 5 through 12 who have dyslexia. This means any data breach involving the school could affect minors, a population that is especially vulnerable to long-term identity theft risk.
In addition to students, the breach may also affect parents, guardians, and school staff members whose personal information was stored in school systems. Because the school is a small, specialized institution, the number of affected individuals is likely limited compared to large school districts.
The exact number of people affected by this incident has not been publicly disclosed. Until the school releases official findings or notifies affected individuals directly, the full scope of who was impacted remains unknown.
Given the nature of the school, it is possible that sensitive educational records tied to learning disabilities could be involved. This would raise additional privacy concerns beyond typical personal identifiers.
What Information Was Potentially Exposed?
Because incransom has only made a claim and the school has not confirmed specifics, the exact categories of exposed data are not fully known. However, schools typically store a range of sensitive information that could be at risk in an incident like this.
- Student names and dates of birth
- Parent or guardian contact information
- Enrollment and academic records
- Special education or learning disability records
- Staff personnel information
- Potentially Social Security numbers used for enrollment or employment
- Financial information related to tuition payments
If these categories are confirmed, the risks to affected individuals could be significant. For example, exposed Social Security numbers could allow criminals to open fraudulent credit accounts in a child’s name. This type of fraud often goes unnoticed for years because children rarely check their credit.
In addition, exposure of academic or learning disability records could lead to targeted phishing scams. Scammers sometimes use specific, personal details to make fraudulent emails or calls seem more convincing. Because many of those potentially affected are minors, parents should remain especially alert to unusual account activity tied to their children’s names.
What is the company doing?
Because The New Community School has not publicly confirmed this incident, there is no confirmed information about an internal investigation, remediation steps, or notification process. The incransom group’s leak site claim is not a statement from the school itself.
As a result, it would be inaccurate to say the school has begun notifying affected individuals or offering credit monitoring at this time. Families and staff who are concerned should reach out directly to the school for updates, since no official response has been documented publicly.
If the school does confirm the breach and outlines its response, that information would typically include details on affected data types, notification timelines, and any protective services offered. Until then, the situation remains unconfirmed by the organization itself.
What Should Affected Individuals Do?
Monitor Credit Reports Closely
Anyone who believes they or their child may be connected to the school should check credit reports regularly. This is especially important for parents monitoring a minor’s identity, since children’s credit files are rarely checked and fraud can go undetected for years.
You can request a free credit report from each of the three major bureaus. Because fraud involving a Social Security number can take time to surface, consistent monitoring over the next year is a smart precaution.
Consider a Credit Freeze or Fraud Alert
If Social Security numbers were involved, placing a credit freeze is one of the strongest protective steps available. A freeze blocks new creditors from accessing your credit file, which makes it much harder for identity thieves to open new accounts.
For a child, parents can request a credit freeze directly with each bureau by providing proof of guardianship. This step is especially valuable because minors rarely have existing credit files, making unauthorized ones easier to spot if a freeze is in place beforehand.
Stay Alert for Phishing Attempts
Because stolen personal data is often used in targeted scams, families should be cautious of unexpected emails, texts, or calls claiming to be from the school. Scammers may reference specific details to appear legitimate.
Never click links or share personal information in response to unsolicited messages. Instead, contact the school directly using a verified phone number or website to confirm whether any communication is genuine.
Protect Educational and Health-Related Records
Because the school serves students with dyslexia, some records may include sensitive learning or health-related information. This type of data deserves extra caution, since it can be misused in ways beyond standard financial fraud.
If you discover that educational or health records were exposed, consider documenting any suspicious use of this information. In addition, speaking with a data breach attorney can help you understand your rights and whether compensation may be available.
Keep Records and Seek Legal Guidance
It is wise to save any correspondence related to this incident, including emails, letters, or public notices from the school. These records could be important if you later need to file a claim.
Because this situation involves a ransomware group’s claim rather than a confirmed breach notice, affected individuals should stay patient but prepared. Consulting a data breach attorney for a free case evaluation can help clarify your options as more facts become available.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
