
Bromley-based Charles Darwin School said it experienced a data security incident that forced school authorities to cancel classes for several days.
Earlier this month, in a letter addressed to parents and caregivers, the Biggin Hill-based secondary school said that it was a victim of a data security incident that affected its internal network.
Internal investigation revealed that the data security incident involved threat actors infiltrating the school’s network and infecting it with a encrypting malware that gave leverage to the hackers to ask for a ransom payment in exchange of a decryption key.
“We do not know at this point what data has been accessed however we need to state there is the potential for all information held by the school to have been accessed,” said head teacher Aston Smith.
School authorities notified Information Commissioner’s Office (ICO) about the incident and are “conducting a full Data Impact Assessment”.
“Information that is cloud based and with external providers have not been accessed, such as Parent Pay,” Mr. Smith said. “We currently have a cybersecurity company completing a forensic investigation and until this in completed, we will not be able to provide any further details on the level of any data breach.”
The ransomware attack affected the school’s access to the internet. This, in turn, disrupted its email servers and access to other systems. School authorities believe that the school will be without internet access for at least three weeks and to support the recovery process, Charles Darwin School cancelled all classes between September 9 and 11.
Recently, the BlackSuit ransomware group claimed responsibility for the ransomware attack on the school and listed it as a victim on its data leak site. The group claims to be in possession of 200GB of data stolen from Charles Darwin School and has threatened to publish the same if its ransom demands aren’t met.
🚨 BLACK SUIT Ransomware Alert 🚨
— FalconFeeds.io (@FalconFeedsio) September 11, 2024
Charles Darwin School 🇬🇧
Charles Darwin School , focuses on academic excellence and personal development, based in UK, has fallen victim to BLACK SUIT ransomware. The group claims to have obtained more than 200 GB of the organization's data.… pic.twitter.com/QIIg3FjMuI
© 2025, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543