Jun 11, 2026, 09:30 AM
The Global Schools / GIIS / GSG Leaks
33,088 passport numbers belonging to children and their parents across 66 nationalities • 9.4 million internal messages spanning 2006–2024 • 221 million student attendance records • 143,494 employee salary records • 107,603 transport users with home addresses and GPS coordinates • 12,303 teacher passwords (99.98% of which were "giis123") • 616,724 email attachments including medical records, identity documents, and report cards • 46,901 job applicant folders with 12,476 passport copies • 22,996 campus visitor photographs • 112 source code repositories • 168 AWS Secrets Manager entries • evidence of a prior ransomware attack from August 2022
Note: All children's names have been redacted across every file in this release. Unredacted copies were sent to students and their families.
33,088 passport numbers belonging to children and their parents across 66 nationalities • 9.4 million internal messages spanning 2006–2024 • 221 million student attendance records • 143,494 employee salary records • 107,603 transport users with home addresses and GPS coordinates • 12,303 teacher passwords (99.98% of which were "giis123") • 616,724 email attachments including medical records, identity documents, and report cards • 46,901 job applicant folders with 12,476 passport copies • 22,996 campus visitor photographs • 112 source code repositories • 168 AWS Secrets Manager entries • evidence of a prior ransomware attack from August 2022
Note: All children's names have been redacted across every file in this release. Unredacted copies were sent to students and their families.
Global Indian International School (GIIS) is the flagship brand of Global Schools Foundation -- known internally as GSG -- a K-12 education holding company headquartered in Singapore operating four school brands (GIIS, OWIS, Glendale, East Academy) across India, the UAE, Malaysia, Japan, Vietnam, and Saudi Arabia. GSG is backed by Apollo Global Management, which has committed approximately S$440 million in capital and described its plans to deploy US$1.5–2 billion in further school acquisitions.
They run 70+ campuses. They serve tens of thousands of children across 7 countries. They hold the most intimate data a school can hold: passport numbers, medical records, mental health crises, family communications that parents send in confidence believing they are private.
All of it was protected by the password "giis123". Default and reused credentials across their cloud environments. They were even hit by an automated ransomware attack in 2022 and never noticed, never cleaned up the READ_ME_TO_RECOVER_YOUR_DATA ransom note.
But it's even worse than that; they also engaged in the most absurd, illogical, and flat-out insane behaviour we have ever seen in negotiations, and likely ever will. It would almost be comical if the stakes weren't their own students' most sensitive data.
We gained initial access to GSG's AWS environment (account 199031240001, ap-southeast-1) in early April 2026. Shockingly, they still have not determined how, despite the very basic nature of the compromise, so we don't want to give it away here yet.
What we can say is what we found there. 67 S3 buckets across their mess of an AWS account. Five live MSSQL servers, all accessible with the same credentials, zero access controls: no VPC, no firewalls. Four MongoDB servers still running the credentials set in 2022. 168 secrets in AWS Secrets Manager, because of course they were using their root AWS account for literally everything.
The teacher/staff authentication database -- the system that controlled access to student records, parent communications, and administrative tools across every campus -- stored 12,303 passwords in plaintext. Not hashed. Not encrypted. Plaintext. And 12,301 of those passwords were identical: giis123. The remaining two were giis1234 and shail110.
We exfiltrated 4.8 terabytes over a week. Nobody noticed. If we hadn't contacted them, they probably never would have.
---
YEARS OF NEGLIGENCE
This was not GSG's first breach. This is a clearly demonstrated pattern of negligence for them.
On both MongoDB servers -- 13.250.47.35 and 13.212.148.158 -- we found a database named READ_ME_TO_RECOVER_YOUR_DATA containing four identical ransom notes. The ObjectID timestamps decode to August 5–9, 2022. A previous attacker compromised these servers nearly four years ago, partially wiped databases, and left ransom demands. Contact emails: [email protected] and [email protected]. BTC wallet: 12nx7Q6FAczH6yfhaEMJRmvRkavDTcwUJK. (Is this any of you guys lmao?)
The ransom note databases were never cleaned up. They were still there when we arrived in April 2026. Perhaps they were never noticed ; the attack was obviously automated and they didn't hit any critical data. But still. The MongoDB credentials -- mongostage / stagemongodb@0, root / testmongodb0 -- were the same ones valid in 2022. The staging server password was literally stagemongodb@0.
GSG was breached four years ago. They did not remediate. They did not rotate credentials. They did not notify anyone. They left the ransom notes sitting in their databases like participation trophies and carried on as if nothing had happened.
Instead, when we notified them of this fact, they tried to use the existence of the ransom notes as an excuse not to pay the price we named to delete the data. Their argument was they'd been breached before, so the data was out there. This is a common concern, but in this specific case, it is patently absurd.
The two databases that were breached contained only a few gigabytes of data. The cloud ransomware attempt was obviously part of an automated campaign (it wiped only a few tables, leaving the important ones) by an idiot -- the sort of mass exploitation that targets databases with extremely weak or default credentials, like the infosec masterwork that is stagemongodb@0.
They told us their data was "not worth" what we were asking. They said "people have short memory."
We disagree.
And now, since we have emailed all ~69,000 parents of students across their campuses, they are beginning to receive a wave of outrage, to the point where they sent us a meaningless, senseless cease and desist: https://fulcrum.st/gsg/ceasedesist.png
Which is pretty funny, since their moronic negotiator had just spent weeks babbling about how insensitive all of this data was. Guess they changed their minds?
In any case, we declined to comply: https://fulcrum.st/gsg/GSlawyers2.png
THE DATA
We created a curate highlights pack for your viewing pleasure:
GSG_highlights/ 111 GB
01_internal_messages/ 9.6 GB
Complete PG_Campus_Mails database from GSG's dedicated mail server.
Every parent-teacher-administrator message across all campuses since 2006.
dbo.ICSMail.jsonl.gz 1.6 GB 8,584,247 messages (main)
dbo.ICSMail_bk_04122024.jsonl.gz 9,423,882 messages (backup)
dbo.ICSMail_13032025.jsonl.gz 8,539,414 messages (snapshot)
dbo.ICSMail_New.jsonl.gz 3,494,952 messages
dbo.ICSMailDetail*.jsonl.gz 42,112,325 routing records (who sent to whom)
+ attachments, broadcast mails, settings, flags
02_student_databases/ 687 MB
The core identity databases.
ICSStuInfo_FULL_35938_STUDENTS.jsonl DECOMPRESSED, READY TO VIEW
35,938 student records, 197 columns each
14,908 student passports, 8,977 father passports, 9,203 mother passports
Home addresses, employer, income, medical conditions, religion, caste
TEACHER_PASSWORDS_PLAINTEXT_12303.jsonl DECOMPRESSED, READY TO VIEW
12,303 accounts. 12,301 passwords = "giis123". In plaintext.
PG_Campus_Users/ 68 tables
PG_Campus_Teachers/ 24 tables
SITUsers.json 71,547 user records across all campuses
03_applicants/ 92 GB
Complete gsf-career S3 bucket. Job applicant document storage.
ApplicantDocuments/ 46,901 individual folders
12,476 folders with passport scans (JPG/PDF)
6,139 folders with visa or work permit copies
142 folders with Aadhaar cards (Indian biometric ID)
163 folders with credit card statements
153 folders with medical certificates
20,881 folders with resumes/CVs
These are the actual scanned documents -- passport bio pages, visa stamps, government identity cards.
04_visitor_photos/ 2.3 GB
22,996 photographs of every person who entered a GSG campus.
05_employee_compensation/ 77 MB
143,494 salary records
8,416 Annual CTC records
25,332 performance appraisals with manager ratings
12,602 variable pay records
06_source_code/ 2.5 GB
112 CodeCommit repositories. Complete SmartLearn/MyGIIS platform.
Backend (C#/.NET), frontend (Angular/React), mobile (Android/iOS),
infrastructure (ArgoCD, IdentityService, GlobalLogin).
Hardcoded credentials throughout.
07_credentials/ 548 KB
168 AWS Secrets Manager entries
19 unique AWS access key pairs
22 unique SQL Server passwords
18 MongoDB connection strings with embedded credentials
JWT signing keys, AES-256 keys + IVs, SMTP passwords,
Twilio auth tokens, Google OAuth, Zoom OAuth, Firebase
08_mongodb/ 1.1 GB
4 MongoDB server dumps. 43 JSON files.
107,603 transport users with home addresses
183,731 daily trip attendance records with GPS coordinates
25,362 staff-parent messages
13,195 chat threads
268,968 helpdesk user accounts
READ_ME_TO_RECOVER_YOUR_DATA (the 2022 ransom notes, still there)
09_twilio_sms/ 1.5 GB
Complete Twilio account dump -- production SMS system.
122,862 SMS messages (through April 30, 2026)
34,708 unique phone numbers across 7 countries
5,211 unique student names linked to parent phones
3 GSG-owned phone numbers:
+14243519626 (US), +601130115667 (MY), +6582410436 (SG)
10_hrms/ 1.8 GB
Employee attendance, leave, reporting lines, HR files.
11_user_photos/ 62 MB
Staff and user profile photographs.
Links to download highlights:
Onion: http://4e3p3in2bl67hxchuwza7qvnpe7pyeloy...dacted.zip
Torrent: magnet:?xt=urn:btih:3273da3c058a121602cba0334d7500006f999b48&dn=GSG_highlights_redacted.zip&tr=udp%3A%2F%2Ftracker.opentrackr.org%3A1337%2Fannounce&tr=udp%3A%2F%2Fopen.stealth.si%3A80%2Fannounce&tr=udp%3A%2F%2Ftracker.torrent.eu.org%3A451%2Fannounce&tr=udp%3A%2F%2Fexodus.desync.com%3A6969%2Fannounce&tr=udp%3A%2F%2Ftracker.tiny-vps.com%3A6969%2Fannounce&tr=udp%3A%2F%2Fopen.tracker.cl%3A1337%2Fannounce&tr=udp%3A%2F%2Fp4p.arenabg.com%3A1337%2Fannounce
And here is a cut version we made for rapid downloads. The main part that’s removed is ~90 GB of applicant/employee ID and passport scans. We made this because dozens of students are emailing us asking for the data and having trouble pulling large files.
[URL unfurl="true"]http://4e3p3in2bl67hxchuwza7qvnpe7pyeloyztr5fnh257fxkovfhappjyd.onion/gsg-data-cut/GSG_highlights_redacted_cut_for_speed.zip[/URL]
[URL unfurl="true"]https://biteblob.com/Information/CKXL30nRvVOUSM/#GSG_highlights_redacted_cut_for_speed.zip[/URL]
[URL unfurl="true"]https://filebin.net/4t4tei8o6us8u9o0[/URL]
Keep an eye on the post on our site for the full 4.8 TB download, coming soon!
PASSPORT NUMBERS - 33,088 ACROSS 66 NATIONALITIES
The ICSStuInfo_FULL_35938_STUDENTS.jsonl file in 02_student_databases/ is decompressed and ready to open. One line per student. 197 fields per line. The passport columns are called Passport, FthPassport, and MthPassport. 14,908 student passports. 8,977 father passports. 9,203 mother passports. Indian, Singaporean, Emirati, Chinese, Japanese, Malaysian, American, British, Pakistani, Bangladeshi, Sri Lankan, Australian, Korean, Filipino, Iranian, Myanmar : 66 nationalities in total.
Some very prominent families go to these schools. Hopefully this will change after they learn of the breach, but at the moment, these families include: the Ambassador of Uzbekistan to Singapore (passport DA0006280, daughter's passport DA0006301, home address: 18 Tanglin Walk, Tanglin Hill Condominium). A Goldman Sachs Executive Director (passport Z6208645, son's passport V1146894, home: Block 297, Punggol Central, #14-485). A Vice President of GIC Special Investments -- Singapore's $800 billion sovereign wealth fund (passport F7623934, son's passport H8673949, home: 26 Bayshore Road, The Bayshore, #18-07). A JPMorgan Chase VP in Tokyo earning ¥10,000,000. A Facebook/Meta Director with Singaporean passport K0985142B. A Korean Army officer. An Egyptian diplomat from the Ministry of Foreign Affairs. 218 Standard Chartered Bank families. 239 Tata Consultancy Services families. 113 Accenture families.
These are not credit card numbers that can be easily cancelled. These are government identity documents belonging to children and their families. For many of these nationalities, passport replacement is expensive, slow, and bureaucratically painful. For some, it requires an embassy visit in a country they may not live in. But that's not actually a cause for concern, according to GSG's negotiator:
https://bf.st/attachments/2202/
See? Losing the passport data for every student and every family who ever attended their schools is no big deal; it'll all expire in 5–10 years. That's basically no time at all. Totally unimportant, just like the thousands of emails of parents talking about their children's mental health and behavioural problems and photocopies of the government IDs and passports for everyone who works for them or has applied for a job.
9.4 MILLION INTERNAL MESSAGES (2006–2024)
The complete PG_Campus_Mails database: every message ever sent between parents, teachers, counsellors, coordinators, and administrators across every GSG campus for nearly two decades. 8,584,247 messages on the main table alone. Full HTML bodies, subjects, sender IDs, timestamps. ~42 million routing records mapping every sender-to-recipient relationship.
We ran keyword searches across the full corpus and verified the following:
- 14,236 medical disclosures naming specific children with specific conditions
- 2,115 bullying reports naming assailants and victims
- 4,242 incident reports (physical altercations between named students)
- 1,064 disciplinary actions (theft, misconduct, warning cards)
- 170 harassment complaints including physical and sexual harassment
- 550 accident reports
- 271 warning letters to parents about named children
- 618 salary grievances from teachers revealing individual pay ("my salary is 3200")
- 410 resignation letters with personal circumstances
- 70 suicide references
- 37 self-harm disclosures
- 184 messages explicitly flagged as confidential by senders
We include a sample of these in an appendix below the post on our site -- go ahead and take a look. GSG deemed these "not significant". We do not agree.
Parents send these messages in trust. They write to their child's teacher about a suicide attempt, a panic attack, a bullying incident, an abuse disclosure -- and they believe that communication is confidential. GSG stored it all in one database, behind one password, with no encryption, for eighteen years.
We extracted thousands of extraordinarily sensitive communications throughout the email databases. Below are a few samples. We have redacted students' names, because unlike GSG, we give a damn about children's safety.
A principal in Singapore, writing to a parent: "She shared that she overdosed on Ibuprofen the previous night and was also in possession of her prescription psychiatric medication (23 tablets in an unmarked bottle). She said that she has been experiencing feelings of self harm since a week. While waiting for you to reach school, she impulsively took cough syrup in the sick room as well."
A school counsellor in Singapore: "She insisted that she was feeling suicidal and somebody in her head was telling her to do harmful things. She even listed out examples such as while crossing the road to stand in front of the car. [REDACTED] and her friends had been in contact with me for the past two to three weeks explicitly mentioning her suicidal thoughts."
A parent writing about her daughter's hospitalisation: "I would like to advise you that [REDACTED] has been admitted to the hospital for observation due to her claims of being suicidal."
A teacher in Bangalore: "Today during the lunch break, [REDACTED] removed the blade from her sharpener and tried to self harm. She has got a few scratches on her hand."
A teacher's anecdotal record: "[REDACTED] has been increasingly talking about suicide, depression and is often heard making statements such as 'I want to cut myself,' 'I want to fake my death,' 'I want to jump off from a height to see if people care for me.' The frequency and intensity of these statements is alarming."
A parent from the Singapore campus: "She stated that she has been contemplating self-harm, including cutting her hands and throat. This is an extremely alarming situation."
A parent in Singapore writing about another child in her daughter's class: "She tried to cut her wrist with a fork in the school cafeteria."
A parent from Dubai: "My daughter developed severe depression because of the bullying suffered on the school. From June last year I am informing the school what is happening. [...] The school did nothing. This led my daughter to a state of depression up to the point to hurt herself."
A mother in Tokyo, writing matter-of-factly about her six-year-old daughter: "I believe it is thanks to Ms. Priyanka that even though she is kicked, molested and abused by her classmates, she does not miss school."
There are thousands more.
These children trusted their school. Their parents trusted their school. GSG stored their most vulnerable moments -- overdoses, self-harm, suicidal ideation, abuse, psychiatric hospitalisations -- in a database accessible to anyone with the password giis123, which was every teacher in the organisation.
TRANSPORT AND PHYSICAL TRACKING
107,603 transport user records with residential addresses, dates of birth, phone numbers. 183,731 daily trip attendance records mapping when children were picked up and dropped off. 1,925 bus stops with GPS coordinates. 1,079 bus routes.
Combined with the 221 million student attendance log entries, which track every day every student was present or absent at every campus, this data reconstructs the daily physical movements of tens of thousands of minors across seven countries.
EMPLOYEE DATA
143,494 salary records with annual CTC values. 25,332 performance appraisal records with manager ratings and comments. 12,602 variable pay records. 156,964 HRMS attendance records including check-in/out times and campus locations. 2,311 reporting line records with named managers. Complete organisational hierarchy. Salary amounts range from SGD 3,200/month for junior teachers to SGD 350,000+ per year for senior leadership.
JOB APPLICANTS
46,901 applicant folders in 03_applicants/. These contain passport photocopies, work permit photocopies. Indian Aadhaar biometric ID cards. 163 contain credit card statements. 153 contain medical certificates.
EVERYTHING ELSE
- 22,996 campus visitor photographs across 14 campuses
- 616,724 email attachments (254 GB) including report cards, bonafide letters with passport and NRIC numbers, medical certificates with government IDs
- 122,862 Twilio SMS messages to 34,708 unique phone numbers -- GSG's own phone numbers, including branded UAE sender IDs (GIIS DXB, GIISAUH, EASCHOOLSHJ, GIS-DXB, GLOBALSA)
- 112 CodeCommit source code repositories -- complete SmartLearn platform with hardcoded AWS keys
---
THE WORLD'S DUMBEST NEGOTIATORS
We do not normally publish our correspondence with breached companies. We have only done this once before, with youX when they served us with an injunction after we took down our posts. But GSG's conduct was so extraordinary -- so dishonest, so stupid, so contemptuous of the process, which every company but them takes with the utmost seriousness -- that we are making an exception.
We contacted GSG in early May and offered them a fair settlement of $750k. For context, our ask was less than what a single year's tuition costs for a classroom of students at their Singapore campus. It was 0.17% of Apollo's committed capital. It was, by any measure, a fraction of the regulatory and legal exposure GSG now faces.
GSG's response was to lie. Repeatedly. About everything.
LIE #1: "MANY OF OUR BRANCHES ARE FRANCHISEES"
GSG claimed their campuses were independent franchisees, not company-owned. This was false. In July 2023, their own press release announced that Apollo had nearly doubled its commitment to S$440 million, funding "over US$650 million" in investments and "over 25 acquisitions" -- described as "100% acquisition." Dwight School Seoul, Glendale Academy Hyderabad, Silveroaks Bangalore, Regent International Malaysia. Full acquisitions. Not franchise agreements. There are dozens of articles and announcements making this fact very clear.
The franchise model ended years ago. GIIS Chinchwad became Elpro International School when the franchise expired. GIIS Dubai's original partner, Scoreplus Education, split from GSG in 2012. GIIS Surat closed. We laid all of this out. GSG's negotiator responded with obfuscation and dumb bluster, and pivoted to another angle in their attempt to lower the price.
LIE #2: "SHINYHUNTERS IS EXTORTING US"
GSG initially claimed ShinyHunters had taken the same data at an earlier date and were also extorting them. They said ShinyHunters had "showed them the entire database" (as if it were a single database that we had taken), so they "knew they had it", unlike us. We contacted ShinyHunters directly to ask them about this. They said they had never heard of them.
https://bf.st/attachments/2206/
When we relayed this, GSG did not miss a beat; they simply swapped out ShinyHunters for unnamed "other groups" — conveniently unverifiable.
But sure, okay, we thought. With their abysmal security, it was not impossible for multiple attackers to have gotten overlapping data. Maybe they were just confused about how data, breaches, and data breaches worked. We were ready to chalk it up to ignorance rather than deceit.
But that was before we realized what sort of deranged pathological liars we were dealing with.
LIE #3: "OVER 99% OF THE DATA IS ALREADY ON THE DARK WEB OR HAVE I BEEN PWNED"
You can see this claim in the screenshot above. They repeatedly made this claim, which is bizarre, because all it takes is subscribing to HIBP to see that this is completely and utterly false. Some of the emails are in there, true, because the fact is everyone's email has been in multiple data breaches. But that's it: just emails. Maybe a few addresses, though we couldn't find any. What certainly was not present: a single passport number of their students or parents, a single government ID card of any of their applicants, and of course, not a single sensitive email discussing their students' most personal issues.
LIE #4: THE FABRICATED DARK WEB LISTING
This is where it gets truly insane.
GSG's negotiator sent us a screenshot of a dark web forum post allegedly showing our data being sold by a user called "LedgerWraith" for $250,000. They claimed it was discovered by a monitoring service called "CloudSec."
https://bf.st/attachments/2207/
The listing was fake. Every number in it -- the 4.8 TB, the 35,938 student records, the 33,000 passport numbers, the 9.4 million messages, the 221 million attendance rows, the 143,000 salary records -- was copied directly from our own communications with GSG. Our exact deduped numbers. Even if another actor had gained access to precisely the same services we had, we deduped and quantified it in an idiosyncratic fashion. There is close to zero percent chance that they would have the same counts for a single data source, let alone all of them. The language, also, mimicked the emails we had sent them. The phrase "random file selection supported for scope verification" was lifted from our verification offer.
They also apparently fed the AI several of our leak posts, since some styling appears to be poor, inane, cringeworthy imitations of our own writing on our site. The line "Centralised means one key, everything. The inbox was the front door" bookended by idiotic emojis, in particular, is one of the most cringe things we have ever seen generated by AI. The fact that it was used with a straight face -- to apparently convince us that we had written it ourselves -- absolutely boggles the mind.
Furthermore, as posters here will know who knows the underground market ecosystem will notice that the price is absurd: $250,000 as a "starting bid" for school data on a "dark web forum" -- this is not a price this sort of data would ever go for. Period. Not even 10% that price. Maybe 5%. As a comparison, we recently saw TeamPCP's listing for the entirety of Eli Lilly's source code -- ~1,400 GitHub repositories -- for $70,000. And that's one of the highest listings we have ever seen. $250k is exactly what it looks like, a fictitious number hallucinated by an LLM and used by morons who couldn't be bothered even to lie properly.
The account "LedgerWraith" does not exist on any dark web forum. The monitoring service "CloudSec" does not perform dark web monitoring ; it is a Thai penetration testing firm with no relationship with GSG. GSG does not even operate in Thailand. They fabricated the name, in other words, because it sounded like a cloud security company: CloudSec. Brilliant.
GSG fabricated a dark web listing using an AI chatbot fed with our own correspondence, attributed it to a fictional vendor and sent it to us expecting that 1) we would believe them and 2) the alleged sale would result in a lower price. Their argument: why pay if your own members are out there selling it? Just like their "why pay if ShinyHunters or whoever has it as well?" argument.
This is, without exaggeration, the single dumbest thing we have ever encountered in this line of work. And we encounter a lot of it. This level of senseless self-sabotage, however, is truly next level stupid. The fact that they thought this would be a successful ploy to get us to lower the price makes us wonder how they manage to run a school at all, let alone a chain of them.
These are not the best and the brightest. As if there were not a hundred red flags about the fake listing they sent -- including that there are no such sales posts or users on any underground forum, they could not even get the details right between the two ostensible "screenshots" of the fictitious listing. We're limited on how many images we can attach here, so see the post on our site, but they couldn't even keep the forgery consistent.
THE AFTERMATH
When we confronted GSG about their fabricated "evidence", their response was to say that they knew we would claim it was a fake, and pivot into using the alleged "sale" as a reason not to pay the full price for deletion -- as they had planned all along.
They then offered us $100,000. Again. But at that point, we were so disgusted that no amount of money would have gotten them off the hook. The fake post was a step too far, and in using it and doubling down on the lie, they torpedoed any chance of a settlement and condemned themselves to face the consequences.
https://bf.st/attachments/2208/
The entire chain of events has been difficult for us to believe. A school holding 33,000 children's passport numbers, mental health records documenting suicide attempts and self-harm, and 9.4 million private parent-teacher communications -- a school backed by $440 million in Apollo capital -- was offered the chance to resolve this for a relative pittance and instead chose to fabricate evidence, lie about their corporate structure, invent phantom threat actors, and completely fictionalise the presence of the data on data leak / dark web tracking sites like Have I Been Pwned.
WHAT WE ARE RELEASING TODAY -- A DETAILED MAP OF THE HIGHLIGHTS PACK
We are releasing a curated 111 GB highlights pack. The full 4.8 TB dump will follow soon.
Children's names are redacted throughout. We do this not for GSG's sake, but in spite of them. We take no pleasure in publishing any of this. We are doing so because we believe parents have a right to know what their school allowed to be exposed, and the way it was "protected", if you can even call it that.
We will share the complete unredacted dataset with:
- Verified journalists investigating the breach
- The Singapore PDPC, India's Data Protection Authority, and the UAE data protection office
- Attorneys representing affected families
- Verified researchers
If you would like a copy, send us an email (use your company domain) at [email protected].
The pack contains the following:
01 - Internal Messages (9.6 GB). The complete PG_Campus_Mails database from GSG's dedicated mail server. Every message ever sent between parents, teachers, counsellors, and administrators across every campus since 2006. 8.5 million messages on the main table, with multiple temporal snapshots (December 2024 backup, March 2025 snapshot) enabling forensic comparison. 42 million routing records mapping every sender-to-recipient relationship. 3,489 mail attachment records with S3 URLs. This is where the suicide disclosures, bullying reports, salary grievances, harassment complaints, and confidential-flagged messages live.
02 - Student Databases (687 MB). The core identity databases for every student, parent, and teacher across all GSG campuses. The centrepiece is ICSStuInfo_FULL_35938_STUDENTS.jsonl -- decompressed, one student per line, 197 columns, ready to open in any text editor. 35,938 students, 33,088 passport numbers (student, father, mother). Home addresses with block/unit/postal code. Both parents' employers, positions, and income brackets. Medical conditions, religion, caste, emergency contacts. Also includes 12,303 teacher accounts with passwords stored in plaintext - 12,301 of which are giis123 - decompressed as TEACHER_PASSWORDS_PLAINTEXT_12303.jsonl. Plus the 71,547-record SITUsers.json user directory spanning all campuses and brands.
03 - Applicant Documents (92 GB). The complete gsf-career S3 bucket. 46,901 individual folders, one per job applicant. These are not database records -- these are the actual scanned documents. Photographs of passport bio pages, visa stamps, and government-issued identity cards. 12,476 folders contain passport scans. 6,139 contain visa or work permit copies. 142 contain Aadhaar cards (Indian biometric national ID). 163 contain credit card statements. 153 contain medical certificates. In addition to Indian applicants, citizens of Korea, America, the UK, Japan, and Australia are impacted, to name a few. This is the largest component of the pack by size.
04 - Visitor Photos (2.3 GB). 22,996 photographs of every person who physically entered a GSG campus - parents, visitors, delivery personnel, contractors. Each linked to a visitor record with name, phone, email, government ID, purpose of visit, and blacklist status.
05 - Employee Compensation (77 MB). Complete salary and performance data for every GSG employee across all campuses. 143,494 salary records with individual amounts per salary head. 8,416 Annual CTC records. 25,332 performance appraisals with manager ratings, comments, and targets. 12,602 variable pay records with increment percentages. 957 PMS Excel files and 25 HR letters. Salary amounts range from SGD 3,200/month for junior teachers to SGD 350,000+/year for leadership.
06 - Source Code (2.5 GB). 112 CodeCommit repositories comprising the complete SmartLearn/MyGIIS platform -- backend (C#/.NET), frontend (Angular/React), mobile (Android/iOS), and infrastructure (ArgoCD, IdentityService, GlobalLogin). Hardcoded credentials throughout: AWS access keys in Angular environment files visible to any browser, database connection strings with Encrypt=false, JWT signing keys, AES-256 encryption keys.
07 - Credentials (548 KB). The full AWS Secrets Manager dump. 168 entries covering every microservice across all environments. These are rotated now -- it took them several weeks after we contacted them -- but we want to show the scale of the exposure.
08 - MongoDB (1.1 GB). Dumps from 4 MongoDB servers. 107,603 transport users with home addresses. 183,731 daily trip records with GPS coordinates. 1,925 bus stops, 1,079 routes. 25,362 staff-parent messages. 13,195 chat threads. 268,968 helpdesk accounts. And READ_ME_TO_RECOVER_YOUR_DATA -- the 2022 ransom notes, still sitting there four years later.
09 - Twilio SMS (1.5 GB). Complete production Twilio account dump. 122,862 SMS messages up through April 2026. 34,708 unique phone numbers across 7 countries. 5,211 unique student names linked to parent phones. GSG's 3 owned phone numbers (+14243519626 US, +601130115667 Malaysia, +6582410436 Singapore) and 6 branded UAE sender IDs (GIIS DXB, GIISAUH, EASCHOOLSHJ, GIS-DXB, EASCHOOL, GLOBALSA).
10 - HRMS (1.8 GB). Human Resources Management System data. 156,964 employee attendance records. Leave balances. 2,311 reporting line records with named managers. 2,916 HR files from the gsg-hrms S3 bucket.
11 - User Photos (62 MB). Staff and user profile photographs from the gsg-users S3 bucket.
We hope the takeaway here is a clear one: If you cannot afford to protect your students' data, you cannot afford to collect it.
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Ban Reason: Contact Administration.
