FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022 MongoDB Credentials — Threadlinqs Intelligence
As of 2026-07-11, FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022 MongoDB Credentials is a high-severity ransomware threat attributed to FulcrumSec, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1209 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: FulcrumSec · FINANCIAL
Cloud-native data-extortion group FulcrumSec breached Global Schools Foundation (GSF), a Singapore-headquartered international school network operating as Global Indian International School across
FulcrumSec is a financially motivated, data-theft-only extortion group active since approximately September 2025 that has claimed roughly 25 named victims across 11+ countries without ever deploying a file-encrypting payload. The group's operating model — publicly documented across the Novo Nordisk, LexisNexis, and youX (formerly DRIVE IQ) intrusions — is 'steal and squeeze': gain access through one of three recurring doors (hardcoded/unrotated credentials in client-side JavaScript or source repositories, unpatched internet-facing applications such as the CVE-2025-55182 'React2Shell' React Server Components RCE, or openly misconfigured cloud storage/database services), enumerate and harvest cloud secrets (especially AWS Secrets Manager), move laterally across SaaS/cloud control planes (AWS, Azure, GCP, Databricks, MongoDB Atlas, GitHub, Hugging Face), sustain low-and-slow database reads over weeks to months of dwell time, exfiltrate bulk data with legitimate tooling (rclone) rather than custom malware, and finally extort victims through a branded leak site (fulcrumsec.net, clearnet + Tor mirror) organized into themed campaigns ('Index of /Shame', 'The Hardcoded Horror Show', 'Slopocalypse Now').
In the GSF case specifically, FulcrumSec identified that GSF (operating under the Global Indian International School brand, and legally referenced elsewhere as Global Schools Group / Global Schools Holdings) had suffered a prior ransomware intrusion in August 2022 that was never fully remediated: FulcrumSec found partially wiped MongoDB databases and the original 2022 ransom notes still present, and — critically — the MongoDB authentication credentials in use in 2026 were identical to the credentials valid in 2022. This is a textbook Valid Accounts (T1078) initial-access failure compounding a historical incident-response gap, consistent with FulcrumSec's broader 'Door 1' pattern of exploiting stale, unrotated secrets rather than developing novel exploits.
FulcrumSec made initial ransom contact with GSF in early May 2026 and disrupted GSF systems across multiple countries in early June 2026. GSF's negotiator conduct was independently characterized by investigative outlet DataBreaches.Net as erratic ('the most bizarre behaviour probably in the history of ransom negotiations'), and negotiations broke down without payment. FulcrumSec's ransom framing publicly compared the demand to 'less than the cost of a single year's tuition for a classroom.' GSF/Global Schools Group subsequently sought an ad-interim injunction from the High Court of Bombay (dated June 12, 2026) and a further injunction from the High Court of the Republic of Singapore (June 13, 2026) attempting to suppress reporting on the breach; DataBreaches.Net reported continuing to publish despite both injunctions.
The exposed dataset is unusually sensitive for a K-12/international-school population: 33,088 passport numbers spanning 66 nationalities (including minors and parents), 221 million student attendance records, 107,603 transport users' home addresses and GPS coordinates, 616,724 email attachments containing medical records and identity documents, 46,901 job applicant folders with 12,476 passport copies, 22,996 campus visitor photographs, 12,303 teacher passwords (99.98% of which were identical to one another, indicating shared/default credential hygiene failures), 9.4 million internal messages spanning 2006–2024, 143,494 employee salary records, 112 source-code repositories, and 168 AWS Secrets Manager entries — the latter giving FulcrumSec a plausible path to pivot into further GSF cloud infrastructure or downstream tenants.
GSF is one node in a broader FulcrumSec 2026 campaign that also compromised Novo Nordisk (approximately 1.3TB / 700,000 files, $25M demand, leak begun June 15, 2026, via a JavaScript-exposed AWS subdomain), LexisNexis Legal & Professional (February 24, 2026, via CVE-2025-55182 React2Shell RCE against an unpatched React frontend on AWS, yielding 3.
Weaknesses (CWE)
CWE-798, CWE-521, CWE-262, CWE-284
Target sectors: education, government administration, finance, health, legal, technology, manufacturing
Target regions: Asia, Middle East, singapore, australia, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1596, T1589, T1588.002, T1078, T1190, T1552.001, T1552.005, T1552.007, T1555, T1580