
The Royal ransomware group, a Ransomware-as-a-service (Raas) that first made an appearance in January 2022 and conducts the world’s most active and dangerous ransomware operations, has claimed to have infiltrated public school management and virtual learning provider Edison Learning, based in Fort Lauderdale, Florida, which provides school management services for public schools in the United States and the United Kingdom.
According to a post on its dark web data leak site, the group had stolen 20GB of data from this for-profit education management organization, including the personal information of employees and students. It threatened to leak the data early next week. The gang wrote: “Looks like knowledge providers missed some lessons of cyber security [sic]. Recently we gave one to EdisonLearning and they have failed.”
Reports say that the Royal ransomware group may have made a ransomware demand and may be in negotiations with Edison Learning. Although Edison Learning confirmed a cyber incident has occurred, it could not disclose anything else as the investigation into this incident is ongoing.
Meanwhile, Edison Learning Director of Communications Michael Serpe told a media representative in an email that the impacted systems contained no student data. It is yet to confirm the Royal ransomware group’s claims since occasionally cyber criminal groups list victims they didn’t compromise.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543