Cyber & AI intelligence
Wasteland.
Briefs indexed2961
Issues30
Published Mondays07:30 CT
█ Ransomware ST-JAMES-ANGLICAN 2026-10-01

St James' Anglican School: ThreeAM Extortion Group Claims Breach of WA School

"St James' Anglican School in Alkimos, in Perth's outer north, is investigating a cyber security incident involving unauthorised access to its computer systems. The school first disclosed the incident on 14 September…"

St James' Anglican School in Alkimos, in Perth's outer north, is investigating a cyber security incident involving unauthorised access to its computer systems. The school first disclosed the incident on 14 September 2026. On 28 September the ThreeAM (3AM) ransomware and extortion group listed the school on its darknet leak site and said "the files will be available soon." The school has more than 1,100 students from kindergarten to Year 12, according to Insurance Business. It has confirmed that personal information about members of its community was involved, and it has notified families. Media reports cited by several outlets, all tracing back to The West Australian, say the data covers current and former students enrolled since 2015, including bank account details, medical records and photographs. No affected-record count has been published by the school, the attacker or any outlet. As of 1 October, the school says it has found no evidence that the data has been released online.

What Happened

The school's own public update, dated 14 September, said it had "recently identified a cyber security incident involving unauthorised access to its computer systems." It said it acted immediately to contain the incident, secured its systems and began a "thorough cyber security audit" (Cyber Daily; Solway Web Consulting; Insurance Business).

According to Insurance Business, the school notified both the Australian Cyber Security Centre (ACSC) and the Office of the Australian Information Commissioner (OAIC) when it first became aware of the breach. Solway's review of the school's update says the OAIC report was made "within the required timeframe." A school spokesperson said the school "has notified families and provided them with information about the incident and practical steps they can take to protect their information" and is "continuing to work closely with its cyber security advisers" (Insurance Business, 17 September).

The West Australian broke the story on 15 September, and PerthNow/NewsWire and news.com.au syndicated it (Ground News; Rankiteo).

The incident escalated on 28 September, when ThreeAM posted the school (stjames.wa.edu.au) to its leak site (GalaxyWarden; Insurance Business). GalaxyWarden says the listing names no data categories, gives no victim count and no incident date. Insurance Business says the group gave no supporting evidence such as sample files. A school spokesperson told Cyber Daily that security experts had found no evidence that information from its systems had been released, and that the school is monitoring the dark web for any publication.

One aggregator, CSRaid, says the school is working with law enforcement. No other source supports this, and it should be treated as unverified.

What Was Taken

The school has confirmed only that "personal information relating to members of the school community was involved." It has not published which data categories were affected, how many people were affected, or how far back the records go.

The detailed breakdown comes from The West Australian's reporting, which was repeated by PerthNow, Insurance Business, Ground News and Rankiteo. It says hackers copied the following data about current and former students enrolled since 2015:

Solway Web Consulting cautions that this reporting "should not be read as confirmation that every category was accessed for every person." When Solway checked on 17 September, the school's public update did not give a per-category breakdown.

There is a gap between the sources about whether data was taken at all. Insurance Business (17 September) says the data "had already left its systems," but the school's own statements stop short of confirming exfiltration. ThreeAM's listing implies it holds files but offers no proof. Cyber Daily reports the school has seen no publication so far. In short, exfiltration is reported by the media and claimed by the attacker, but neither the school nor any published evidence has confirmed it.

Volume: unknown. The school has over 1,100 current students, but if the reported 2015 start date is correct, the affected group extends to former students (many now adults) and their families. That makes it considerably larger than current enrolment.

Why It Matters

Children's data with a long tail. Medical records, photographs and bank details for minors are among the most sensitive data a school holds. Children's identities can be misused for years before anyone notices, because they rarely have credit files to monitor. Photographs of children also create safeguarding concerns that go beyond financial fraud.

Old records widen the impact. Solway and Insurance Business both point out that data reportedly going back more than a decade pulls in families who left the school years ago. Solway is careful to say the school may have legitimate reasons to keep these records. Still, every year of archived data a school keeps adds to the damage when that data is stolen.

Mid-sized private schools are attractive targets. These schools hold health, financial and identity data, often have small IT teams, and face strong reputational pressure to settle quietly. Insurance Business notes that Australian private schools holding health information are generally covered by the Privacy Act 1988 whatever their turnover, so the Notifiable Data Breaches scheme applies to them.

Extortion runs on a timeline. ThreeAM listed the school two weeks after the school's disclosure. That fits the familiar pattern of using a public listing to pressure a victim that has not paid. Defenders should expect a possible data dump, and possibly direct contact with families, which extortion groups sometimes use to increase pressure.

The Attack Technique

How the attackers got in has not been disclosed. The school's statements do not describe the entry point, and Solway confirms the school's update does not explain it. CSRaid's suggestion that attackers "may have exploited vulnerabilities in the school's network or used social engineering" is generic speculation with no sourcing, and should not be taken as reported fact.

Background on ThreeAM. This comes from earlier public threat research, not from the sources for this incident. ThreeAM (also written 3AM) emerged in 2023 as a ransomware family written in Rust. It was first seen being deployed as a fallback payload when LockBit failed to run. Later vendor reporting linked its operators to former Conti and Royal affiliates and described intrusions that began with email bombing, followed by voice phishing in which attackers posed as IT support over Microsoft Teams or phone calls to get victims to grant remote access. The group runs a double-extortion model: it steals data, encrypts systems and posts victims to a leak site. None of these techniques has been confirmed in the St James' incident.

What Organizations Should Do

  1. Enforce data retention schedules. Map what student, parent and staff data you hold, including old SIS exports, finance archives and file shares. Archive offline or securely delete anything past its legal retention period. Records that are no longer on the network can't be stolen from it.
  2. Segment and tightly control sensitive data stores. Keep medical records, bank details and student photos in separate, access-controlled systems with logging, not on broadly shared drives. Alert on bulk reads or large outbound transfers.
  3. Harden against help-desk and vishing attacks. Restrict external Microsoft Teams chat, block remote-access tools that aren't approved, and require staff to verify any "IT support" contact through a separate channel before granting access.
  4. Use phishing-resistant MFA everywhere. Prioritise remote access, email, finance systems and administrator accounts. Audit for old VPN accounts and accounts without MFA.
  5. Prepare the extortion playbook before you need it. Decide in advance how you will handle leak-site listings, dark web monitoring, family communications, OAIC notification within the NDB timeframe and ACSC reporting. Check that your cyber insurance actually covers data theft, dark web monitoring and identity-protection services for affected people.
  6. Prepare affected families for follow-on scams. Warn them about phishing, invoice fraud and fake bank-detail-change requests that use the stolen data, and point them to IDCARE and bank fraud teams.

Sources: Exclusive: WA’s St James' Anglican School investigating cyber incid... | St James’ School Data Breach: Why Old Customer Data Increases Cyber... | Education clients face broader cyber exposure after Perth school br... | Student Info Stolen in School Cyber Attack | Ransomware gang's claim on WA school shows where cyber cover can fa... | St James Anglican School: St James Anglican School in Perth, WA hit... | Double Data Breach Alert: Australian School and US Utility Exp... | stjames.wa.edu.au Listed by Threeam Ransomware Group