A South Australian School Just Had 600GB of Student Data Dumped Online – Is Your School or Business Next?

A South Australian School Just Had 600GB of Student Data Dumped Online – Is Your School or Business Next?

~5 min read

In early June 2026, Reynella East College in Adelaide – a school of more than 1,900 students from preschool to Year 12 — discovered its entire computer system had been compromised. Parents were notified on June 9th. What happened next is a warning every Australian school and small business needs to read.

Two weeks later, the ransomware group responsible made good on their threat. More than 600 gigabytes of alleged school data was published on the dark web — over 473,000 files across 68,000 folders. Among the data reported to have been exposed: passport scans of international students and staff, contact records for students and families, internal budget documents, and — most alarmingly — plaintext credential lists. That means usernames and passwords stored in readable, unencrypted form. Sitting there, waiting to be found.


What Actually Happened?

The group behind the attack, known as Interlock, is a ransomware operation that has been active since late 2024 and has now claimed more than 111 victims — predominantly in education and manufacturing. Reynella East College was their first known Australian target.

Interlock’s method is what’s known as double-extortion ransomware. They don’t just lock your systems and demand payment to restore access. They simultaneously steal your data — and then threaten to publish it unless you pay. Even if a ransom is paid, there is no guarantee the data won’t be released anyway. Paying does not make the problem go away.

The group gains initial access through techniques including compromised websites and social engineering — including a method called ClickFix, which tricks users into clicking fraudulent prompts that silently install malicious software. Once inside a network, they move quietly, extracting data before anyone knows they’re there.

The school’s systems were down for an extended period. Staff were notified. Parents were notified. And then, fourteen days later — the data appeared online anyway.


This Is Not an Isolated Incident

What makes this particularly concerning for the education sector is that Reynella East College is far from alone. Around the same period, the University of Western Australia disclosed a breach after database credentials were accidentally published online, exposing student records from their student information management platform. Notably, this was the university’s second breach within six months.

Nationally, the education sector consistently ranks in the top five industries for data breach notifications. Ransomware incidents in particular carry a disproportionately large impact — with an average of nearly 300,000 individuals affected per incident in recent reporting periods. And according to Australia’s own cybersecurity authorities, the number of cyber incidents being responded to has risen significantly year on year, with financial losses for businesses climbing sharply across all size categories.

For small businesses, the average self-reported loss from a cybercrime incident now sits at over $56,000. For larger organisations it’s considerably more. These aren’t theoretical figures — they’re what businesses are actually reporting after an attack.


What This Means for Victorian Schools and Small Businesses

If you’re reading this thinking “that’s a South Australian school, not us” — that’s exactly the kind of thinking that leaves organisations exposed.

The attack vectors Interlock used are not unique to one school, one state, or one sector. Credential lists stored in plaintext. Systems that weren’t adequately segmented. A gap between when the breach happened and when it was detected. These are infrastructure and configuration problems that exist across thousands of Australian organisations right now — in schools, in small businesses, in any environment where IT has grown organically over time without a structured review.

The uncomfortable reality is that most schools and small businesses don’t know what their actual security posture looks like until something goes wrong. By then, the data has already left the building.


What Good Looks Like

Preventing an incident like Reynella East College’s isn’t about buying the most expensive security product on the market. It’s about getting the fundamentals right — and knowing where your gaps are before an attacker finds them first.

That means understanding what’s actually on your network and who has access to it. It means ensuring credentials are never stored in plaintext and that password hygiene is enforced consistently. It means having systems properly segmented so that if one part of the network is compromised, an attacker can’t walk freely through the rest. It means having backups that are tested, isolated, and actually restorable. And it means knowing — not assuming — that your current setup meets your legal and compliance obligations around the data you hold.

None of this requires a team of dedicated security engineers. It does require someone to take an honest look at what you currently have, identify the gaps, and put a plan in place to address them in order of priority.

Once the fundamentals are solid, there are additional layers worth considering — external 24×7 monitoring being one of the most effective. Having eyes on your environment around the clock means threats can be detected and responded to before they escalate into the kind of incident Reynella East College experienced. But monitoring on top of a weak foundation doesn’t fix the foundation. The basics come first.

That’s precisely what an infrastructure health assessment is for.

 

Concerned About Your Current Security?

If reading this has raised questions about where your organisation actually stands — that’s the right instinct to act on. We work with schools and small businesses across Victoria to assess, report on, and address exactly these kinds of risks.

If you haven’t had a proper infrastructure review done in a while, or you’re simply not sure where you stand — please don’t hesitate to Contact Us and let’s have a conversation: www.ozzeal.com.au/learn-more or 📞 1300 676 498

Source:https://www.insurancebusinessmag.com/au/news/cyber/south-australian-school-data-dumped-online-weeks-after-hack-580273.aspx

 

 

 

Leave a Reply