The Bombay High Court has issued an urgent interim order preventing an alleged hacker collective from publishing confidential information belonging to children enrolled in schools operated by a charitable educational trust.
The protection was granted after the trust approached the Court alleging that a cybercriminal group identified as FulcrumSec had infiltrated its databases and was threatening to release sensitive records unless a ransom of $750,000 was paid.
While granting relief, Justice Arif S. Doctor underscored the potentially severe consequences of exposing such information, particularly details relating to students’ mental health. The Court observed that making such material public could cause significant harm and have lasting adverse effects on the children concerned.
The trust sought immediate intervention without prior notice to the alleged hackers, arguing that any delay or advance warning could undermine the purpose of the proceedings and increase the risk of disclosure. Accepting this concern, the Court concluded that the circumstances justified passing an ex parte order.
According to the trust, the cyberattack compromised a wide range of information, including students’ travel routines, medical records, mental-health details, and data relating to their parents’ occupations and income levels.
The trust informed the Court that it received an email in May allegedly demanding payment in exchange for keeping the data private. Matters escalated further when a parent reportedly received a communication containing confidential information about multiple students, including details linked to mental-health issues.
The Court noted that the material allegedly accessed by the hackers extended beyond academic records. Information concerning family backgrounds, financial details, and the daily movements of children, if exposed, could create serious safety concerns and place students at risk.
Taking note of these factors, the High Court restrained FulcrumSec and the other respondents from releasing, publishing, sharing, or otherwise disseminating any of the data allegedly obtained through the cyber breach.
The matter is scheduled for further consideration on July 1.



