Medusa ransomware gang leaked Minneapolis Public Schools student records
- Organization
- Minneapolis Public Schools
- Exploit
- Ransomware
- Industry
- Education
Files stolen from Minneapolis Public Schools in a February 2023 ransomware attack circulated widely online through the spring, exposing student and staff records the district had never intended to become public. The Medusa ransomware group claimed the attack and demanded $1 million. The district did not pay.
After its deadline passed, Medusa published the material in March 2023, promoting it through its leak site, Telegram and other channels, and later made the full archive downloadable. Reporting at the time put the volume at more than 189,000 files. Journalists who reviewed the tranche said they could not independently verify the documents.
The records went well beyond names and identifiers. Alongside dates of birth and Social Security numbers, the leak included student mental health and psychological reports, special education files describing home circumstances, medical conditions and test results, behavioral incident logs, allegations of abuse involving district staff, and campus security material such as surveillance camera locations and building blueprints.
Minneapolis Public Schools notified families of an encryption event on March 1 and began contacting some known victims in April while it ran an automated and manual review of the leaked data. That review was completed in late July 2023. The district subsequently reported that 105,617 people were affected and offered them 24 months of credit monitoring and identity theft services.