Battle Creek Public Schools in the US reported a ransomware incident attributed to threat actor rhysida, impacting student records including IEP/special-ed files, disability determinations, and discipline/suspension records, along with federal funds compliance and staff health-spending documentation. The exposed data also included ESSA/Title I application materials and payflex/EHA-related claims, with impacts affecting #UnitedStates.
Incident Details
- Victim: Battle Creek Public Schools
- Sector: Education
- Country: US
- Actor: rhysida
- Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=259
- Discovered: 2026-08-21T10:28:03.015892+00:00
- Published: 2026-08-21T10:27:30.392150+00:00
Information
- Student records of named minors, including IEP/special education files, disability determination notices, and discipline or suspension records.
- Federal funds compliance records, including ESSA/Title I application materials.
- Staff health-spending claims, including Payflex/EHA records.
- Additional related materials.

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.