St. Thomas Aquinas High School Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The St. Thomas Aquinas High School Listed by medusa Ransomware Group (reported July 30, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target educational institutions as part of a broader pattern of double-extortion attacks, in which data is stolen and then used as leverage. In this environment, even private high schools have appeared on criminal leak sites. On July 30, 2024, St. Thomas Aquinas High School in Fort Lauderdale, Florida, was listed by the Medusa ransomware group, which claimed responsibility for a ransomware attack involving the exfiltration of internal files totaling 103.8 GB.
The number of people affected remains unknown, and public detail on the precise method or timeline of the intrusion is limited. What is known is that the group publicly associated the school with a data leak of that size. For students, families, staff, and alumni, any unauthorized access to school systems raises practical questions about personal information and institutional records.
Breaking down the breach
According to the available record, St. Thomas Aquinas High School was listed by the Medusa ransomware group on July 30, 2024. The listing describes a ransomware attack in which internal files were allegedly exfiltrated. The total volume of data claimed to have been taken is 103.8 GB. No confirmed figure for the number of individuals affected has been published, and details such as the exact date of initial access, the vulnerability or entry vector used, or whether systems were encrypted in addition to data theft have not been disclosed in the public summary.
The facts characterize the incident as involving the theft of internal files rather than a confirmed public dump of every record. Because the information originates from a threat-actor listing, it should be treated as a claim by the group rather than an independently verified forensic report. No further technical indicators or official confirmation of the full scope appear in the provided record.
Inside medusa
Medusa is a ransomware operation that has been active in recent years and is known for a double-extortion model: operators encrypt systems where possible and simultaneously steal data, then threaten to publish the material on a dedicated leak site if a ransom is not paid. The group has listed victims across multiple sectors, including education, healthcare, and commercial organizations. Listings typically include the victim’s name, a claimed data volume, and sometimes sample files or countdown timers.
Public reporting on Medusa describes it as operating in a ransomware-as-a-service style, with affiliates conducting intrusions and the core group handling negotiations and leak-site infrastructure. The group’s claims about any specific victim, including the volume of data or the nature of the files, are assertions made by the actors themselves and are not automatically confirmed. In this case, the only concrete claim attached to St. Thomas Aquinas High School is the listing itself and the stated 103.8 GB of internal files.
About St. Thomas Aquinas High School
St. Thomas Aquinas High School is a private, Roman Catholic, college-preparatory high school founded in 1936 and located in Fort Lauderdale, Florida. It currently enrolls approximately 2,420 students on a 25-acre campus and employs about 257 people. Its corporate office address is listed as 2801 SW 12th St, Fort Lauderdale, Florida 33312. As a college-preparatory institution, it maintains academic records, administrative systems, and the kinds of operational data common to private secondary schools.
Educational organizations of this type routinely hold personally identifiable information about students and families, employment and payroll data for staff, academic transcripts, health or counseling notes where applicable, financial-aid or tuition records, and internal communications. A breach at such a school is consequential because the population includes minors, parents or guardians, and employees whose records may remain relevant for years after graduation or departure.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack and that the total claimed volume is 103.8 GB. No further breakdown of file types, databases, or specific categories of personal data has been disclosed. Exact contents therefore remain unconfirmed.
Organizations of this kind typically store student enrollment and demographic information, contact details for parents or guardians, academic performance records, staff personnel files, email and document repositories, and financial or administrative records. Whether any of those categories were among the 103.8 GB claimed by Medusa is not established in the public record. Readers should treat the exposure as involving unspecified internal school files rather than a verified inventory of particular data elements.
Why it matters
When internal school files are taken, the practical risks include potential misuse of personal details for identity fraud, targeted phishing against students or parents, or exposure of sensitive academic or employment information. Even if the full contents are unknown, the mere existence of a large claimed exfiltration creates uncertainty for anyone whose data may have been stored on the affected systems. For the school, the incident can disrupt operations, require forensic investigation and notification processes, and damage trust among families and staff.
Because the number of affected individuals is unknown, the circle of people who may need to take precautions cannot be precisely defined from public information alone. The 103.8 GB figure indicates a substantial volume of material, but volume alone does not reveal sensitivity. The real-world impact depends on what was actually inside those files—an answer that remains undisclosed.
Were you affected?
If you are a current or former student, parent, guardian, or employee of St. Thomas Aquinas High School, treat the listing as a reason to increase caution rather than as proof that your specific records were taken. Monitor financial and credit activity for unusual behavior, be alert to phishing emails or calls that reference the school, and consider placing fraud alerts if you have reason to believe sensitive identifiers were involved. Change passwords on any accounts that reused credentials associated with school systems, and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this particular incident, but it can surface other exposures that warrant attention. Official updates, if any, would come from the school itself; until then, the public record consists of the Medusa listing and the limited facts summarized here.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Broker Educational Sales & Training Listed by medusa Ransomware GroupAlbion College Listed by medusa Ransomware GroupSpirit Lake Community School District Listed by medusa Ransomware GroupInner City Education Foundation Listed by medusa Ransomware GroupLatest breaches
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.