2026 Palatine School District — STORMOUS access claim (unverified); actor says no data leaked
Data compromised
Actor-claimed access to PALDC2020 server, pupil databases, and personnel records; actor publicly stated no data was leaked and offered to disclose vulnerabilities privately—unverified
Technical writeup
Unverified STORMOUS claim — June 28, 2026. Ransomware.live indexed an unusual post in which STORMOUS claimed unrestricted access to Palatine School District infrastructure in Illinois—including directories described as student and personnel data on server PALDC2020—while simultaneously stating the group chose not to leak data and offering to share vulnerability details with administrators. The district had not publicly confirmed at catalog time. Treat as unverified access claim with potential K-12/special-education exposure risk if substantiated. recordsAffected 0 pending attestation.
Root cause
STORMOUS ransomware group posted claim of full server access to Palatine School District (palatineschool.org) including student and staff directories—actor stated they chose not to publish data—unverified