Saint George’s School Data Breach

Alleged

Ransomware claim involving Saint George's School

Published: Jul 16, 2026 CmdOrganization
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Saint George's School
Industry
Education
Threat Actor
CmdOrganization
Date of Incident
Jul 16, 2026

Executive Summary

Saint George’s School, an educational institution located in Colombia, has been identified as a victim of the CmdOrganization ransomware group. The listing appeared on the group’s dark web portal on July 16, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. Operating within the Education sector, Saint George’s School’s inclusion on the leak site aligns with CmdOrganization’s pattern of targeting similar organizations across various regions. The group’s recent activity suggests a strategic focus on entities within the Healthcare, Education, and Manufacturing sectors, with a notable prevalence of victims in the United States, United Kingdom, and Colombia. In the 60 days preceding this listing, CmdOrganization claimed a total of 22 victims. This sustained campaign indicates a highly active threat actor. The group’s recent targeting demonstrates a consistent pattern, with entities like Mount Royal University, Lake Washington School District, Fidelity Security Group, and Target Energy Solutions falling prey to similar extortion tactics. Saint George’s School’s profile as an educational organization in Colombia fits precisely within this established modus operandi, suggesting a potential continuation of the group’s established cybercrime operations.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a significant credential exposure linked to the domain sgs.edu.co, closely aligning with the leak-site listing date. The queried data indicated a substantial corporate footprint, encompassing 14 employee credentials on organization-owned systems, nine corporate users associated with third-party services, one external user, and one record of unclear affiliation. Critical endpoints identified include two variants of Microsoft identity/SSO sign-in credentials and internal Moodle and classroom portals. A notable concern is a single corporate account that appears across multiple internal and third-party services, utilizing a reused password, which significantly elevates the risk of corporate intrusion. The credential exposure window ranges from July 6 to July 16, 2026, directly preceding the ransomware group’s public listing. The presence of credentials within a Microsoft 365 tenant is flagged as a high-priority item requiring immediate rotation and multi-factor authentication enforcement. For threat actors such as CmdOrganization, infostealer-harvested credentials represent a well-established initial access vector. Attackers or initial access brokers often acquire fresh credential logs from underground marketplaces, validate them, and subsequently use them to gain unauthorized access to systems, including Microsoft 365, VPNs, or remote-access portals, before deploying ransomware. While the current stealer-log evidence does not definitively confirm that CmdOrganization utilized these specific credentials for the Saint George’s School incident, the observed pattern is highly consistent with the typical kill chain for such attacks. This exposure designates the compromised accounts and endpoints as prime targets for immediate review and remediation.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.