Cressex Community School
bd_939fe0e4caa0dae8 · schema v1 · pii pii-v1
Full breach record for Cressex Community School →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
High Wycombe Cressex Community School hit by cyber attack | Bucks Free Press. Cressex Community School: Cressex Community School was the victim of a cyberattack on Friday, March 22, affecting its computer systems. The school implemented its cyber incident response plan and continued to operate normally, while collaborating with specialists and informing the ICO in accordance with GDPR. Measures have been taken to limit data loss and restore computer systems, and the incident is being investigated by the relevant authorities. Linked ransomware group: ransomhouse.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Mar 22, 2024
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteransomhousebd_6bb2ccdebd0d37622024-03-25 · +3dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
ransomhouse
According to ransomware.live, RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120 organizations across healthcare, finance, transportation, and government, recently upgrading to a multi-layered dual-key encryption architecture.