Ransomware gang's claim on WA school shows where cyber cover can fall short
Education sector policyholders carry material cyber exposure when cover is silent on exfiltration, dwell time, and dark web monitoring costs
Ransomware gang's claim on WA school shows where cyber cover can fall short
CYBER
By Roxanne Libatique
01 Oct 2026

A West Australian Anglican school is managing an active cyber security situation – with student and community data potentially at risk – against a backdrop of rising ransomware pressure across the education sector nationally.

St James’ Anglican School, in the outer Perth suburb of Alkimos, first disclosed the breach on September 14, advising that it had identified “unauthorised access to its computer systems.” The school, which has more than 1,100 students from kindergarten to Year 12, said the incident had been contained and that a “thorough cyber security audit” was underway.

The school’s investigation found that personal information relating to members of the school community was involved. Families were notified and provided guidance on steps to protect their information.

Both the Australian Cyber Security Centre (ACSC) and the Office of the Australian Information Commissioner (OAIC) were notified when the school first became aware of the breach – consistent with mandatory reporting obligations under the Privacy Act 1988.

Read next: Education clients face broader cyber exposure after Perth school breach

Ransomware group claims responsibility

The situation escalated on September 28, when the ThreeAM ransomware group claimed responsibility via its darknet leak site, stating that “the files will be available soon.” No data had been published at the time of reporting, and the group provided no supporting evidence for its claim.

A school spokesperson told Cyber Daily that security experts had found no evidence that information from its systems had been released online. “We are continuing to work with our independent cyber security experts to investigate the incident, including to continue to monitor for any publication of data,” the spokesperson said.

The school confirmed that teaching continued without disruption throughout. “If our investigation identifies that any individual’s personal information has been affected, we will write to them directly and provide further specific guidance and steps they can take to protect themselves,” it said.

How the group operates

ThreeAM was first observed in August 2023 and has claimed 99 victims across 22 countries, including in Australia, according to Cyber Daily. Its most recent confirmed Australian victim prior to St James’ was ANU Enterprise, which confirmed a ransomware attack in November 2024.

In a May 2025 blog post, Sophos documented a ThreeAM attack it responded to in Q1 2025 – one that illustrates directly why education clients’ cyber policies warrant close scrutiny.

In that incident, the attacker conducted pre-attack reconnaissance to gather employee email addresses and the internal IT department’s phone number. The attacker then placed a voice call spoofing that number, using it to socially engineer an employee into granting remote access. A virtual machine was then deployed to the compromised computer to establish a foothold hidden from endpoint protection software.

The ransomware itself was blocked – but the attacker had already been on the network for nine days, and approximately 868 GB of data had been exfiltrated to a cloud storage provider before the encryption attempt. “They used this information to tailor their attack,” Sophos said, referring to the employee data gathered during reconnaissance.

For brokers with education clients, that sequence has direct policy implications. A placement that responds only to a successful encryption event – and not to data exfiltration, extended network dwell time, or the costs of forensic investigation and dark web monitoring – may leave a school materially exposed even when the ransomware itself is stopped.

A sector under pressure

The St James’ incident is part of a wider pattern.

Aon's 2026 Independent Schools Risk Report, based on a survey of 306 schools conducted between January and March 2026, found that one in four Australian independent schools reported experiencing a cyber incident – up from one in five in the previous survey cycle in 2024.

“Cyber risk is no longer simply an IT issue for schools. It is a governance priority that can influence every aspect of school operations, from teaching continuity to financial management, student safety, and community trust,” said Lachlan Bowden, practice group leader of education for Australia at Aon.

At the national level, the OAIC recorded 1,205 data breach notifications in 2025 – the highest annual total since the Notifiable Data Breaches (NDB) scheme commenced in 2018, an 8% increase on 2024. Of those, 716 were attributable to malicious or criminal activity. The education sector ranked fifth by volume, with 81 notifications.

Read next: UWA student records walked out the door via an accidental leak

Regulatory exposure

Under the NDB scheme, organisations must notify the OAIC and affected individuals where a breach is likely to result in serious harm. The OAIC has previously stated that paying a ransom does not satisfy that notification obligation – a position with direct bearing on how claims involving ransomware are structured and assessed.

Brokers placing cyber cover for education clients should consider whether policies address notification costs, incident response, data exfiltration independent of encryption, and dark web monitoring – all of which are features of the St James’ situation as it currently stands.

“We deeply regret any concern this incident has caused and will continue to do everything we can to support anyone affected in our school community,” the school said.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.