Post

North Queensland Cyber Watch: The Gentlemen claims a Charters Towers school as a ransomware victim

This entry in North Queensland Cyber Watch, the series looking at cyber security incidents that affect our region and what organisations here can take from them, needs a careful first sentence, because it is early and it is thin.

What has actually happened is that a criminal ransomware group has named All Souls St Gabriels School, the independent Anglican boarding and day school in Charters Towers, on its leak site, as recorded by CyberStack’s Australia desk. That is a claim by criminals, not a confirmed breach. When I last checked, on the evening of 10 October 2026, the school had said nothing publicly about it, I could find no police or regulator statement, and I could find no news outlet that had reported it. All Souls St Gabriels School is not accused of any wrongdoing, and on the current public record it is as much a potential victim as its students, families and staff are.

Photo by Allen Y on Unsplash.

What has been reported

The listing first appears on public trackers. ransomware.live’s victim page records a victim entry for All Souls St Gabriels School (allsouls.qld.edu.au), attributed to the ransomware group The Gentlemen, in the Education sector, with a discovery date of 9 October 2026 (19:24 UTC) and an estimated attack date of 6 October 2026. The tracker’s activity page for the Education sector shows the same entry.

The entry’s description text is not damage detail. It is a company profile (enrolment numbers, campus size, fees, staffing) of the kind these listings commonly carry next to a victim’s name. It does not state what data, if any, was taken, and I could find no data-volume or data-type claim from the group for this victim.

Other public trackers carry the same record. SOCRadar’s ransomware-intelligence page for the listing shows the school under thegentlemen, in Education, Australia, with the status “Claimed”. RansomLook lists a post naming the school dated 6 October 2026, and Breach House shows it with a discovery date of 9 October 2026 and a leak status of “pending”. CyberStack’s article on the claim (published 9 October 2026) says the gang has not said what data it holds, and advises treating it as a leak-site claim only until the school publishes.

I checked the school’s own website again on 10 October 2026 at about 22:41 AEST (12:41 UTC): neither the homepage nor the news page carried any cyber-incident, ransomware or data-breach statement.

I could not find any news coverage of this incident. When I searched on 10 October 2026 for the school’s name with “cyber”, “ransomware”, “data breach” and “hack”, the results were ransomware trackers, aggregator dashboards and CyberStack’s note, with no report from the ABC, the Townsville Bulletin, the Cairns Post, Cyber Daily or iTnews. There was also no matching entry on Webber Insurance’s list of Australian data breaches when I checked it the same evening.

What is reported, claimed and still unknown

As with the Westco Motors entry in this series, the responsible way to read this is to keep three categories apart.

  • Reported: Public ransomware trackers have indexed a leak-site listing naming All Souls St Gabriels School under The Gentlemen, in the Education sector. ransomware.live gives a discovery date of 9 October 2026 and an estimated attack date of 6 October 2026, and SOCRadar shows the listing’s status as “Claimed”. When I checked on 10 October 2026, the school’s public website carried no incident notice, and I found no news report of the incident.
  • Claimed by the group: The Gentlemen has posted the school’s name and domain on its leak site, and trackers show a company profile alongside it. That listing is the group’s claim, not a confirmed breach. As far as I could find, the group has not said what data it holds, how much, or where it came from.
  • Not established publicly: whether the school was actually breached at all; whether any data was stolen or copied; what kinds of records (if any) were involved; how many students, families or staff might be affected; when any intrusion began; whether the school is working with Queensland Police, the Australian Signals Directorate’s ACSC, or the Office of the Australian Information Commissioner; and whether the school will confirm, deny or otherwise respond.

The Townsville Christian College entry earlier in this series shows what the other side of that line looks like. There, the College itself confirmed the attack in a notice to its community under the Notifiable Data Breaches scheme, said an attacker had got in through an internet-facing remote-access connection, and said it had reported the incident to the ACSC, Queensland Police and the OAIC. Nothing comparable is on the public record here. A leak-site listing and a confirmed attack are two different things, and a school that has not yet spoken is not evidence either way. Some listings turn out to be real incidents the victim is still working through; others turn out to be inflated or misattributed. Until the school publishes something, or a regulator or police confirm it, the honest position is that a criminal group has made a claim and we do not yet know if it is true.

Who The Gentlemen are

The Gentlemen is a ransomware-as-a-service (RaaS) operation that ransomware.live’s group page (which also lists it as Storm-2697) describes as having emerged in July–August 2025 and grown quickly by offering its affiliates a 90% revenue share. The same page counts 960 victims attributed to the group across 90 countries, with most activity in manufacturing, technology, professional services, healthcare and retail. It describes a Go-based locker used against Windows, Linux, NAS and BSD systems, and the techniques it lists for the group include both exfiltrating data and encrypting it, the familiar double-extortion pattern of taking data, locking systems and threatening to publish.

CI-ISAC Australia’s threat advisory (posted 28 August 2026) ranks the group as the second most active ransomware operation globally. It says its affiliates do not specifically target Australia but are opportunistic and sector-agnostic, which has given them access to several Australian organisations in 2026, and it lists education among the sectors hit this year. Most usefully for organisations here, CI-ISAC says initial access is “not overly-sophisticated” and is typically opportunistic exploitation of unpatched edge devices: internet-facing FortiGate and FortiOS devices that have not been patched, exposed RDP and remote-management tooling, reused or default credentials with weak admin controls, and flat Windows networks with LDAP-integrated VPN accounts.

The group’s other Australian listings are claims too. ransomware.live lists the Alchin Long Group, an Australian hardware group, under The Gentlemen with a discovery date of 15 September 2026, and RansomLook lists a post naming the Mandurah State Emergency Service in Western Australia dated 2 October 2026. In every case these are leak-site claims, subject to the same caveat as the entry above.

Why a boarding school’s records are sensitive

Whatever the truth of this specific claim, it is worth being clear about why a regional boarding school appears on a target list at all.

A school like All Souls St Gabriels typically holds a deeper and more sensitive record set than most businesses of its size: enrolment data, family and emergency contacts, medical and allergy information, health plans, boarding rolls and room allocations, student reports and wellbeing notes, fee and direct-debit details, passport and visa copies for international students, and identity documents for staff, volunteers and contractors. A boarding school also holds a live, frequently updated picture of where young people physically sleep and who is responsible for them, which is exactly the kind of information that makes a dataset dangerous in the wrong hands.

That matters in Charters Towers in particular. The school’s boarding page says its boarders come from across northern Australia and nearby countries, and family details inside a student record can include sensitive information: a parent’s address that should not circulate, custody arrangements, or the location of a student in care. The Canvas entry that opened this series made a related point: even names, email addresses and school affiliations are enough for convincing follow-on phishing, so exposure of “just” contact details is not a low-risk outcome. A school’s full record set goes well beyond that. A school is a data custodian for people who cannot consent on their own behalf, and that raises the stakes on everything from vendor access to how long old records are kept.

What families, students and staff should do

There is nothing to panic about yet. If you are a parent, student, boarder or staff member at All Souls St Gabriels, the sensible steps are:

  • Watch for direct contact from the school before believing anything you read on a tracking site or social media. The school is the only party that can tell you whether your information is affected.
  • Be wary of unexpected emails, texts or calls that mention the incident. A leak-site claim is a gift to scammers: they can reference it to sound plausible while asking for a “fee”, a “verification” or a password. Treat any such message as a scam until the school confirms otherwise.
  • Do not act through links in an email or text. If something claims to be from the school, phone the school on the number on its website, or open its app or portal yourself.
  • Never give a password, card number or one-time code to someone who contacts you. A genuine breach notification will not ask for these.
  • If identity documents are later confirmed as involved (a licence, passport or Medicare card), consider a free credit ban with the credit bureaus, and contact IDCARE (1800 595 160), Australia’s free national identity and cyber support service, for a plan tailored to you.
  • Report suspicious contact to Scamwatch, and keep any direct notice the school sends you.

The lesson for North Queensland organisations

Whether or not this particular claim is confirmed, the pattern is one every regional organisation should be able to answer for. CI-ISAC’s description of how The Gentlemen typically gets in (unpatched edge devices, exposed remote access, weak credentials, flat networks) is a checklist, not a mystery. Nothing public says how, or whether, anyone got into this school’s systems, so this is a prompt for everyone else, not a diagnosis of All Souls St Gabriels.

A useful review covers:

  • your internet-facing edge: firewalls, VPNs, remote-desktop gateways and any vendor appliance reachable from the internet. Are they patched to the current vendor version, and do you actually run the patch cycle, not just the policy?
  • remote access: is RDP or remote-management tooling exposed to the internet at all, and where it is needed, is it behind multi-factor authentication and a hardened gateway?
  • credentials: no shared admin accounts, no default or reused passwords, and MFA on email, cloud admin and any remote-access path;
  • your network shape: flat Windows networks with LDAP-integrated VPN accounts are on CI-ISAC’s list, so segment administration away from the general estate;
  • detection: logging and alerting on new admin accounts, new remote-access tools and unusual bulk data movement, because “living off the land” techniques blend in with normal administration;
  • backups: offline or immutable copies, and a restore you have actually tested;
  • your data map: knowing which systems hold student, family, health, boarding and identity records, who can export them, and how long old records are kept;
  • an incident response and notification plan: who decides, who notifies the OAIC, families and staff, and who speaks publicly, decided before an incident rather than during one.

The data map point is easy to underestimate. Publicly indexed data (Shodan and certificate-transparency logs, checked 10 October 2026) shows that All Souls St Gabriels, like most schools, runs on a mix of outside platforms: separate cloud services for enrolments, the intranet, the student information system, bulk email and email, plus a website run by a hosting company. Each one is a supplier holding part of the school’s records. That says nothing about this claim or how, or whether, anyone got in, but it is a reminder that your data map has to cover every supplier, not just the systems on your own network.

ASD’s Australian Cyber Security Centre publishes the Essential Eight as a baseline for making systems harder to compromise, and the OAIC’s Notifiable Data Breaches guidance sets out when an incident like this has to be reported. Neither is a substitute for actually knowing where your student and family data flows.

If your organisation wants an independent, practical look at edge devices, remote access, identity, Microsoft 365 hygiene and incident readiness, Suburban Secure works with organisations in Townsville and Cairns. The review is designed as an independent second opinion: the findings belong to the organisation, and the organisation chooses who acts on them.

The accurate headline for now is narrow. A criminal ransomware group has claimed All Souls St Gabriels School as a victim on its leak site, and public trackers have indexed that claim. The school has not confirmed a breach, I could find no police or regulator statement, and it is not known publicly whether any data was taken. That uncertainty is exactly why the useful response is not to wait for confirmation, but to go and check the things this group is known to exploit.


References

All Souls St Gabriels School. (n.d.). Homepage, News and Boarding pages (no cyber-incident, ransomware or data-breach statement on the homepage or news page). https://www.allsouls.qld.edu.au/, https://www.allsouls.qld.edu.au/news/ and https://www.allsouls.qld.edu.au/boarding/ (checked 10 October 2026, 22:41 AEST).

Ransomware.live. (n.d.). All Souls St Gabriels School (victim page; group Thegentlemen; discovered 2026-10-09 19:24 UTC; est. attack date 2026-10-06; sector Education). https://www.ransomware.live/id/QWxsIFNvdWxzIFN0IEdhYnJpZWxzIFNjaG9vbEB0aGVnZW50bGVtZW4= (checked 10 October 2026, 12:40 UTC).

Ransomware.live. (n.d.). Education (sector activity page). https://www.ransomware.live/activity/Education (checked 10 October 2026, 12:40 UTC).

Ransomware.live. (n.d.). Thegentlemen / Storm-2697 (group page). https://www.ransomware.live/group/thegentlemen (checked 10 October 2026, 12:40 UTC).

Ransomware.live. (n.d.). Alchin Long Group (victim page; group Thegentlemen; discovered 2026-09-15). https://www.ransomware.live/id/QWxjaGluIExvbmcgR3JvdXBAdGhlZ2VudGxlbWVu (checked 10 October 2026, 12:40 UTC).

SOCRadar. (n.d.). All Souls St Gabriels School ransomware attack by Thegentlemen (ransomware intelligence; status “Claimed”). https://socradar.io/free-tools/ransomware-intelligence/victims/all-souls-st-gabriels-school-thegentlemen-c78afcd6 (checked 10 October 2026, about 12:38 UTC).

CyberStack. (2026, October 9). All Souls St Gabriels School (Charters Towers QLD): The Gentlemen ransomware leak-site claim. https://cyberstack.org/n/all-souls-st-gabriels-gentlemen-20261009 (checked 10 October 2026, about 12:38 UTC).

RansomLook. (n.d.). The Gentlemen (group page). https://www.ransomlook.io/group/the%20gentlemen (checked 10 October 2026, 12:40 UTC).

Breach House. (n.d.). Thegentlemen (group page). https://www.breach.house/groups/thegentlemen (checked 10 October 2026, 12:40 UTC).

Webber Insurance. (n.d.). The complete list of data breaches in Australia. https://www.webberinsurance.com.au/data-breaches-list (checked 10 October 2026, 12:40 UTC).

CI-ISAC Australia. (2026, August 28). The Gentlemen, a rapidly proliferating ransomware-as-a-service syndicate (threat advisory). https://ci-isac.org.au/threat-advisory-gentlemen/

Office of the Australian Information Commissioner. (n.d.). Notifiable Data Breaches scheme. https://www.oaic.gov.au/privacy/notifiable-data-breaches

Australian Signals Directorate, Australian Cyber Security Centre. (n.d.). Essential Eight explained. https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-explained

IDCARE. (n.d.). Get support. https://www.idcare.org/

This post is licensed under CC BY-NC-ND 4.0 by the author.