LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ZS Salovnova Listed by thegentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

ZS Salovnova Listed by thegentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 7, 2026

Occurred August 2026 · publicly disclosed August 7, 2026.

HIGH
Severity
August 7, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On 7 August 2026, ZS Salovnova was listed by thegentlemen ransomware group in connection with exposure of personal data affecting an undisclosed number of people. Individuals who may have had dealings with the organisation are advised to check their accounts and monitor for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the ZS Salovnova Listed by thegentlemen Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account. Details go to your inbox.

When a primary school appears on a ransomware group's listing, the practical concern is immediate for families, staff and former pupils: personal details held by the school may have been copied and could be misused. Public reporting on 7 August 2026 stated that ZS Salovnova, also known as ZŠ Šalounova, had been named by the group calling itself thegentlemen. The number of people affected and the exact data involved have not been disclosed, so the scale of any exposure remains unconfirmed.

For parents, teachers and others connected to the school, the listing raises ordinary but serious questions about whether contact information, records or other files linked to the institution could surface elsewhere. Until more detail is released by the school or independent investigators, the prudent response is to treat the claim as unverified and to take basic protective steps.

Inside the incident

According to the available public record, ZS Salovnova was listed by thegentlemen ransomware group on or around 7 August 2026. The listing itself is a claim made by the group; it has not been independently confirmed in the material provided. No technical description of how any intrusion occurred, no timeline of events inside the school's systems, and no statement of files taken or encrypted have been released in the facts at hand.

The number of people potentially affected is recorded as unknown. Data types said to have been exposed are listed as not disclosed. In short, the public picture is limited to the organisation's name appearing on the group's leak-site style listing and the date that appearance was reported. Everything else about method, duration or confirmed compromise remains undisclosed.

Who is thegentlemen?

thegentlemen is a ransomware operation known in open-source reporting for double-extortion tactics: encrypting systems while also claiming to steal data and threatening to publish it if a ransom is not paid. Like other groups in this category, it typically maintains a leak site or similar channel on which it names alleged victims and sometimes posts sample files to pressure organisations. Public documentation of the group describes standard ransomware practices—initial access through common vectors, lateral movement, data exfiltration and deployment of encryptors—rather than any unique signature tied exclusively to this incident.

No specific statements by thegentlemen about ZS Salovnova beyond the act of listing the school are contained in the facts. Any assertion that particular files were stolen or that a ransom demand was issued should therefore be treated as the group's unverified claim unless corroborated by the school or another reliable source.

ZS Salovnova and its sector

ZS Salovnova, operating as ZŠ Šalounova, is a primary school in the Vítkovice district of Ostrava, Czech Republic. It runs across two buildings on Šalounova and Halasova streets and provides standard primary education together with specialised programmes, extracurricular clubs and a full school counselling service. Staff include school psychologists, special educators and career counsellors; the school also runs educational and sports projects aimed at supporting pupil success.

Primary schools routinely hold records needed to educate and safeguard children: pupil enrolment data, contact details for parents or guardians, health or special-needs information, attendance and assessment records, and staff employment files. A breach affecting such an institution is consequential because the data subjects include minors, whose information requires heightened care, and because disruption to school systems can interrupt teaching, counselling and administrative functions that families rely on daily.

What was likely exposed

The facts state that the data types named as exposed are not disclosed. It is therefore not possible to assert that any particular category of information was taken. Organisations of this kind typically maintain pupil and parent contact details, dates of birth, addresses, health or dietary notes, special-educational-needs documentation, staff personal and payroll data, and internal administrative files. Whether any of those categories were involved in this incident remains unconfirmed.

Readers should not assume that specific records have been published or sold simply because a listing appeared. Until the school or competent authorities release a verified inventory, the contents of any alleged exfiltration stay unknown.

What's at stake

For individuals, the main risks are ordinary identity-related harms: unwanted contact, phishing that impersonates the school, or misuse of personal details if they later appear in criminal markets. Because pupils are minors, any exposure of their information carries additional sensitivity; parents may face targeted messages that reference school activities or family circumstances. Staff could encounter similar risks around employment or financial data if such files were involved—again, an unconfirmed possibility.

For the school itself, the stakes include potential operational disruption, the cost of investigation and recovery, reputational damage among families, and regulatory obligations under data-protection rules that apply to educational bodies holding children's data. None of these outcomes is established as fact from the listing alone; they are the concrete consequences that typically follow confirmed ransomware incidents in the education sector.

Were you affected?

If you are a parent, guardian, pupil, former pupil or staff member connected to ZS Salovnova, begin with simple precautions: be alert to unexpected emails or messages that claim to come from the school or reference the incident; avoid clicking links or opening attachments from unfamiliar sources; and consider changing passwords for any accounts that reused credentials associated with school systems. Monitor financial and email accounts for unusual activity.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step will not confirm or deny involvement in this specific incident, but it can show whether your address has surfaced elsewhere and help you decide what further monitoring is worthwhile. Official updates, if any, should come from the school or relevant Czech authorities rather than from the ransomware group's own claims.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyZS Salovnova security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See ZS Salovnova’s full breach history →
RelatedMore incidents at ZS Salovnova

More recent breaches

Tesi Listed by thegentlemen Ransomware GroupAugust 7, 2026Preferred Listed by thegentlemen Ransomware GroupJuly 31, 2026Kosh Innovations Listed by thegentlemen Ransomware GroupJuly 31, 2026Salem Saleh Babgi Listed by thegentlemen Ransomware GroupJuly 31, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the ZS Salovnova Listed by thegentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram