INC Ransom Claims Attack on Richmond School for Students with Dyslexia

A criminal ransomware group has listed The New Community School on its dark-web pressure site. The school has not confirmed any incident, and the claim cannot be independently verified.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 3 min read
Illustration: An empty school hallway lined with lockers, natural light coming through windows at the far end
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • INC Ransom listed The New Community School, a Richmond, Virginia school serving students with dyslexia in grades 5 to 12, on its dark-web leak site on 7 October 2026.
  • The listing is an unverified criminal claim made to pressure the school into paying; the school has not publicly confirmed any incident.
  • Ransomware groups sometimes exaggerate or fabricate listings entirely; this one could not be independently verified at publication time.
  • INC Ransom is the same group we reported on 28 September 2026 when it listed a remote Alaska school district on its pressure site.

A criminal gang called INC Ransom, which uses ransomware (malicious software that locks an organisation's files and demands payment to restore them), posted The New Community School to its dark-web pressure site on 7 October 2026. Ransomware.live, a monitoring service, first observed the listing.

The New Community School is an independent co-educational day school in Richmond, Virginia, specialising in students with dyslexia across grades 5 to 12.

The school hasn't publicly confirmed any incident, and the claim couldn't be independently verified at publication.

How does this kind of listing work?

Ransomware groups run leak sites, hidden corners of the internet, where they name organisations they claim to have attacked. The tactic is a pressure move: pay up, or we publish what we took. Listings sometimes appear days or weeks before any public confirmation, are occasionally exaggerated, and are sometimes outright false.

The description INC Ransom posted reads as a flattering summary of the school's mission, typical boilerplate copied from public websites to make a listing look credible. It says nothing specific about what data the group allegedly holds.

How active is INC Ransom right now?

Active enough to warrant watching. Threat Vectr has covered INC Ransom twice in the past 90 days, and schools have featured in both cases. Education is a recurring target for the group, and it's not hard to see why: schools tend to run lean IT teams against a large surface of student and staff records.

These figures are aggregate counts of unverified criminal claims, not confirmed breaches.

Metric Figure
School listing date 7 October 2026
School location Richmond, Virginia, US
Threat Vectr INC Ransom stories (last 90 days) 2
Threat Vectr education stories (last 90 days) 5

Should you worry?

Because this is an unconfirmed claim, there's no established breach to respond to. That said, a few sensible precautions cost nothing.

Watch for phishing attempts: fraudulent emails or messages designed to trick you into handing over a password or clicking a harmful link. Criminals sometimes use news like this to craft convincing fakes, posing as the school or as a data-protection authority.

If you reuse the same password across your school account and other services, change it now on all of them. A password manager makes that practical.

Be sceptical of any call or message claiming you're owed compensation for a data breach. No legitimate breach-response process asks you to pay a fee or hand over banking details.

© 2026 Threat Vectr