In September 2025, Rectory School experienced a network disruption and launched an investigation with the help of cybersecurity experts. The investigation revealed that certain files were potentially acquired without authorization, and a detailed review identified that personal information may have been involved.
The school completed its review and began notifying affected individuals on July 9, 2026. The Qilin ransomware group claimed responsibility for the attack, stating they obtained 143 GB of data and posted evidence on a dark web portal on September 30, 2025. Exposed data types include names, Social Security numbers, driver’s license numbers, and state identification numbers. Medical and financial information may also have been affected, but this was not clearly confirmed in the primary reporting.
Details regarding the total number of affected individuals have not been publicly disclosed by Rectory School, though one regulator filing indicates 8 individuals were affected in Vermont. Further details may emerge as the situation develops, and notification processes may still be ongoing.