Regent International School: Data analysis of the Global Schools Group breach, Part 2

Regent International School: Data analysis of the Global Schools Group breach, Part 2

Global Schools Group Suffers Massive Data Breach Exposing 183,000+ Accounts

A recent cyberattack on Global Schools Group (GSG), a network of international schools, has exposed sensitive data belonging to over 183,000 students, parents, and staff across 12 school brands. The breach, attributed to the hacking group FulcrumSec, resulted in the exfiltration of vast amounts of personal and operational data, including:

  • 83,132 student accounts and 35,938 detailed enrollment records containing passport numbers, government IDs, and extended family PII.
  • 88,856 parent accounts and 11,176 staff/teacher/admin accounts.
  • 9.4 million internal messages (2006–2024), including sensitive communications about students’ mental health and family matters.
  • 8.6 million attendance records, 122,862 Twilio SMS messages, and 112 source code repositories.
  • 168 AWS secrets and 46,901 job applicant document folders.

The affected schools span multiple countries, including India, Cambodia, the Philippines, South Korea, the UAE, Malaysia, and the UK. Notably, Regent International School in Malaysia had ~1,820 duplicate records, inflating the total count.

FulcrumSec described the breach as unsophisticated, citing poor security practices at GSG. The group claimed the teacher/staff authentication database stored 12,303 passwords in plaintext, with 12,301 using the default password "giis123" a critical lapse in basic security controls. The lack of encryption, access restrictions, or detection mechanisms allowed attackers to extract data undetected.

The incident raises concerns about the exposure of highly sensitive information, including private communications between parents and staff. While schools may not intentionally collect medical data, the breach revealed that such details were routinely stored in internal messages. Regulators and affected individuals are likely to scrutinize GSG’s security measures moving forward.

Source: https://databreaches.net/2026/06/18/data-analysis-of-the-global-schools-group-breach-part-2/

Regent cybersecurity rating report: https://www.rankiteo.com/company/regent-global

"id": "REG1781807543",
"linkid": "regent-global",
"type": "Breach",
"date": "1/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '183,000+ (students, parents, '
                                              'staff)',
                        'industry': 'Education',
                        'location': 'Global (India, Cambodia, Philippines, '
                                    'South Korea, UAE, Malaysia, UK)',
                        'name': 'Global Schools Group (GSG)',
                        'type': 'Education Network'},
                       {'customers_affected': '~1,820 duplicate records',
                        'industry': 'Education',
                        'location': 'Malaysia',
                        'name': 'Regent International School',
                        'type': 'School'}],
 'attack_vector': 'Unspecified (Poor security practices)',
 'data_breach': {'data_encryption': 'No (plaintext passwords, unencrypted '
                                    'data)',
                 'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '183,000+ accounts',
                 'personally_identifiable_information': 'Yes (passport '
                                                        'numbers, government '
                                                        'IDs, extended family '
                                                        'PII)',
                 'sensitivity_of_data': 'High (passport numbers, government '
                                        'IDs, family PII, mental health '
                                        'discussions, private communications)',
                 'type_of_data_compromised': ['Student accounts (83,132)',
                                              'Enrollment records (35,938)',
                                              'Parent accounts (88,856)',
                                              'Staff/teacher/admin accounts '
                                              '(11,176)',
                                              'Internal messages (9.4 million)',
                                              'Attendance records (8.6 '
                                              'million)',
                                              'Twilio SMS messages (122,862)',
                                              'Source code repositories (112)',
                                              'AWS secrets (168)',
                                              'Job applicant documents (46,901 '
                                              'folders)']},
 'description': 'A recent cyberattack on Global Schools Group (GSG), a network '
                'of international schools, has exposed sensitive data '
                'belonging to over 183,000 students, parents, and staff across '
                '12 school brands. The breach, attributed to the hacking group '
                'FulcrumSec, resulted in the exfiltration of vast amounts of '
                'personal and operational data, including student records, '
                'parent accounts, internal messages, attendance records, and '
                'source code repositories. The incident highlights poor '
                'security practices, including plaintext password storage and '
                'lack of encryption.',
 'impact': {'brand_reputation_impact': 'Likely significant due to exposure of '
                                       'sensitive communications and poor '
                                       'security practices',
            'data_compromised': '183,000+ accounts (students, parents, staff), '
                                '9.4 million internal messages, 8.6 million '
                                'attendance records, 122,862 Twilio SMS '
                                'messages, 112 source code repositories, 168 '
                                'AWS secrets, 46,901 job applicant document '
                                'folders',
            'identity_theft_risk': 'High (passport numbers, government IDs, '
                                   'family PII exposed)',
            'legal_liabilities': 'Likely due to exposure of PII and sensitive '
                                 'data'},
 'lessons_learned': 'Poor security practices (plaintext passwords, default '
                    'passwords, lack of encryption, no access restrictions or '
                    'detection mechanisms) led to a massive data breach with '
                    'high-risk exposure of sensitive information.',
 'post_incident_analysis': {'root_causes': 'Poor security practices, including '
                                           'plaintext password storage, '
                                           'default passwords, lack of '
                                           'encryption, and no access '
                                           'restrictions or detection '
                                           'mechanisms'},
 'recommendations': ['Implement encryption for sensitive data',
                     'Enforce strong password policies and eliminate default '
                     'passwords',
                     'Restrict access to sensitive systems and data',
                     'Deploy detection mechanisms for unauthorized access',
                     'Conduct regular security audits and penetration testing',
                     'Train staff on security best practices'],
 'references': [{'source': 'Cyber Incident Description'}],
 'threat_actor': 'FulcrumSec',
 'title': 'Global Schools Group Suffers Massive Data Breach Exposing 183,000+ '
          'Accounts',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Lack of encryption, plaintext password storage, '
                            'default passwords, no access restrictions or '
                            'detection mechanisms'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.