ThreeAM have listed St James Anglican School (stjames.wa.edu.au) a Western Australian school with a role of 1,100 students as a victim on their ransomware blog and the school has also posted a notice on their website.
"St James’ Anglican School recently identified a cyber security incident involving unauthorised access to its computer systems.
The School acted immediately to contain the incident, secured its systems, and is performing a thorough cyber-security audit.
The investigation has identified that personal information relating to members of the School community was involved. The School has notified families and provided them with information about the incident and practical steps they can take to protect their information.
We have reported the incident to the Australian Cyber Security Centre (ACSC) and the Office of the Australian Information Commissioner.
The School is continuing to work closely with its cyber security advisers and will provide further information directly to affected members of our community where appropriate.
Our priority is supporting our students, families and staff while ensuring the security of the School’s systems.
As the investigation remains ongoing, the School will not comment on specific technical or security matters."
Who is ThreeAM?
The first known mention of ThreeAM (3 AM) came about when Symantec posted a blog article in mid-September about a failed LockBit ransomware deployment (see references). Apparently, during this deployment, the LockBit affiliate attempted to deploy LockBit, failed, and deployed a novel ransomware called ThreeAM instead
ThreeAM Ransomware Group, also known as 3AM Ransomware Group and ThreeAM Ransomware Gang, has maintained recent activity across multiple regions. Other reporting links the group to claims involving Newman Tractor in the United States on September 20, and Twin States News in August. Earlier activity targeted healthcare, education, manufacturing, logistics, and professional services.
The group operates a ransomware and extortion model centered on 3AM Ransomware. Reporting also associates its operations with T1041, Exfiltration Over C2 Channel, and T1005, Data from Local System. In May 2025, Sophos documented an email-bombing and vishing campaign in which operators impersonated IT support, used Microsoft Quick Assist, deployed QDoor, and leveraged remote encryption.