RANSOMWARE VICTIMEDUCATIONDUPLICATE CLAIM

Richard Alibon Primary School

www.r-alibon.bardaglea.org.uk
beast📍 United Kingdom (GB)📅 January 8, 2026
8
same group

Attack Intelligence

Richard Alibon Primary School was compromised in a ransomware attack attributed to beast in January 2026. The organization, operating in the Education sector in United Kingdom, was added to the group's data leak site as part of an extortion campaign.

beast operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Richard Alibon Primary is a school where all individuals are valued and helped to achieve their personal best. Confidence � Perseverance � Ambition � Curiousity � Respect � Happiness While we are a large school, every child is important to us. Children are supported in becoming confident and independent young people. We want all our children to have a strong voice. We want each child to be safe and happy at school; to be at their best as learners and as a citizen within our community. We believe that the �special feel� at Richard Alibon comes from our caring, supportive and friendly environment. If you visit Richard Alibon, you will see just how well children and staff get on together; the good behaviour of our children and how pupils live out our school values of: The excellent start begins in Nursery and continues through the school. As a school that has children and staff with family connections around the world we have a strong international outlook. A good day of learning in school is supported by frequent trips and visits, community activities and a wide range of after-school clubs which further add to the opportunities available to children.

Additional Details

data_size
400GB

Other Victims — beast (8)

Quick Facts

CountryUnited Kingdom (GB)
SectorEducation
Attack DateJan 8, 2026
Domainwww.r-alibon.bardaglea.org.uk
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

beast
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.