Insurancebusinessmag Ransomware Attack on WA School by ThreeAM Group
Article Content
- •St James' Anglican School experienced a ransomware attack affecting personal data.
- •ThreeAM ransomware group claimed responsibility but has not yet published any data.
- •The school is conducting a cyber security audit and has notified affected families.
St James’ Anglican School in Alkimos, WA, reported a cyber security incident on September 14, 2026, involving unauthorized access to its computer systems. The school confirmed that personal information of community members may be affected and has notified families about the breach. On September 28, the ThreeAM ransomware group claimed responsibility for the attack via its darknet site, threatening to publish the stolen data. However, the school stated that no evidence of data publication had been found so far. A thorough cyber security audit is underway, and the Australian Cyber Security Centre and the Office of the Australian Information Commissioner have been notified. Teaching at the school has continued without disruption. The ThreeAM group has previously targeted 99 victims across 22 countries since its emergence in August 2023.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Threeam and ANU Enterprise in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data was compromised?
Is the data published yet?
What steps is the school taking?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…