Frequently Asked Questions

Our investigation indicates that certain personal information (even though it is non-actionable data) stored within the affected SmartLearn environment was accessed and subsequently disclosed by unauthorised third parties. The information potentially affected may include certain personal information relating to students, parents, guardians, and staff that was stored within the SmartLearn platform. The specific information associated with each individual may differ and remains subject to ongoing forensic review.

Yes, our investigation indicates that certain personal information (even though it is non-actionable data) stored within the affected SmartLearn environment was accessed.  However, our investigation remains ongoing, and we are continuing to assess the full scope of the incident with the assistance of independent cybersecurity and forensic experts. If our investigation identifies any material developments requiring further notification, we will communicate them through our official channels.

The school does not store credit card, debit card, banking credentials, or other payment card information relating to parents or guardians within the SmartLearn platform or its systems. Accordingly, based on our current understanding, no such financial payment information has been affected by this incident.

While we encourage all families to remain vigilant against phishing attempts and suspicious communications, parents and guardians can be reassured that payment card information is not held by the school and has therefore not been impacted.

The incident was identified following the detection of unauthorised access to the SmartLearn environment around 12 May 2026. Upon discovery, the school immediately activated its incident response procedures, secured affected systems, and commenced a detailed investigation.

The investigation is being conducted with the assistance of independent cybersecurity and forensic specialists to determine the nature, scope, and impact of the incident. The precise circumstances surrounding the incident remains under investigation.

Upon becoming aware of the incident, the school:

  • Activated its incident response procedures;
  • Engaged independent cybersecurity and forensic experts;
  • Secured and isolated affected systems;
  • Notified relevant authorities where required;
  • Reported the matter to law enforcement authorities;
  • Decommissioned the affected SmartLearn environment; and
  • Commenced redevelopment of SmartLearn on new infrastructure with enhanced security controls.
  • Secured necessary injunction orders from various Courts in various jurisdictions alongwith filing of the complaints with authorities.
  • The website/data source hosting information was taken down/removed.
  • The intermediaries and platforms have been informed to prevent dissemination of the information basis the Court Orders.

The redevelopment of SmartLearn includes enhanced security controls, additional monitoring measures, and independent security reviews. Security enhancements are being implemented as part of the new environment, consistent with current cybersecurity best practices.

Yes. Relevant data protection and cybersecurity authorities have been notified where required under applicable laws. The matter has also been reported to regulators and law enforcement authorities in all the jurisdictions, and the school continues to cooperate fully with all ongoing inquiries and investigations.

On 12 June 2026, the Hon’ble Bombay High Court and on 13 June 2026, the High Court of Singapore granted a permanent injunction restraining any person from using, copying, publishing, distributing, transmitting, communicating, disclosing, selling, or leaking any internal data that was unlawfully obtained, including personal and sensitive information relating to students of Global Schools and their families.

Together, these injunctions by the High Courts of Bombay and Singapore provide important legal safeguards and reinforce the strong measures being taken to prevent the publication and dissemination of sensitive information worldwide. Both Courts have also directed the removal of such information from all identified platforms, including Google, all Meta platforms, X, etc.

The orders helped secure removal/taking down of the website/data source hosting such stolen information. Subsequently, efforts are ongoing with intermediaries and platforms to prevent dissemination of the information. These measures are intended to limit further public access to the data.

The school remains committed to supporting families and addressing concerns arising from this incident. We will continue to provide guidance, updates, and assistance through our designated support channels. Additional support measures will be communicated if considered necessary based on the findings of the ongoing investigation.

We recommend that families:

  • Change passwords associated with school and email accounts;
  • Enable two-factor authentication (2FA) where available;
  • Be cautious of unexpected emails, messages, or phone calls requesting personal information;
  • Monitor accounts for unusual activity; and
  • Avoid sharing passwords, verification codes, or payment information.

Schools are required to maintain certain records for educational, operational, safeguarding, legal, regulatory, and administrative purposes as per the laws of the specific jurisdiction. Retention periods vary depending on the nature of the information and applicable legal and regulatory requirements. The school regularly reviews its data retention practices to ensure they remain appropriate and compliant.

We will continue to provide updates through the Group's official communication channels as additional verified information becomes available. Families are encouraged to rely only on official communications and to treat messages from unknown sources with caution.

If you have questions, concerns, or believe that a school-related account may have been compromised, please contact the school's designated support team at dpo@globalschools.com.

Reach out now. The sooner we start, the more we can protect.

Subscribe to our newsletter for latest updates.

Copyright: © 2026 CyberSec Center. All rights reserved.