Skip to content
Back to Blog
high severity September 18, 2026 · 3 min read Unverified claim — what this is

BeLi Teacher / FSC education centers (AWS) Listed by N0n Ransomware Group

If you are a customer of BeLi Teacher / FSC education centers, here’s what is being claimed, and what it would mean for you.

Education / edtech · Vietnam What will be published if no settlement is reached The complete CRM lead database: 152,044 contact records — names, emails, +84 phone numbers, cities, study interests, engagement history The CRM file archive (tasks, forums, comments, customer files) migrated from GetFly CRM Publication proceeds in batches after the deadline.

— from N0n’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
BeLi Teacher / FSC education centers (AWS) Listed by N0n Ransomware Group

The N0n ransomware group has listed BeLi Teacher and FSC education centers on its leak site, claiming it holds the complete CRM lead database of 152,044 contact records along with a migrated CRM file archive. The group says it will publish the material in batches if no settlement is reached. As of writing, neither BeLi Teacher nor FSC education centers has publicly confirmed any incident.

Watch BeLi Teacher / FSC education centers

Get alerted the next time BeLi Teacher / FSC education centers files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about BeLi Teacher / FSC education centers’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.

This means the organisation has been named in an unverified extortion listing. The record provides no proof that any data was actually taken, and it does not disclose how the group obtained the claimed material, if at all. For you as someone who may have interacted with these Vietnamese education centres, the immediate question is whether any of your information is genuinely at risk and what that risk actually looks like.

Your Information Is Not Automatically Public

The listing claims names, emails, Vietnamese phone numbers, cities, study interests, and engagement history from the CRM system, plus tasks, forums, comments and customer files. However, these are the attackers’ own words, not an audited inventory. No permanent government identifiers such as national ID numbers or passports appear in the record. That absence removes several of the most damaging long-term risks that often accompany education-sector claims.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

Because the storage scheme for any passwords was not disclosed, treat any account you have with BeLi Teacher or FSC as potentially compromised. Change your password there immediately using a unique, strong value you have never used elsewhere. This single step limits what an attacker could do even if credentials were part of the claimed material.

What a Leak-Site Listing Actually Establishes

Ransomware and extortion groups frequently post organisations on leak sites to create pressure. The listing itself is marketing material designed to frighten both the target and its customers. Many such postings turn out to be recycled data from older incidents, exaggerated claims, or cases where the group never obtained the volume or sensitivity of information they advertise.

Real confirmation would require the company to issue a formal statement, regulators to acknowledge the incident, or direct notification to affected individuals. None of those have occurred here. The September 18, 2026 filing date tells us only when the group chose to list the organisation, not when or whether any compromise took place. Until independent evidence appears, this remains an accusation, not an established breach.

The Education Sector Pattern N0n Is Following

Groups targeting Vietnamese edtech and language centres have repeatedly used leak-site pressure tactics. The pattern often mixes genuine compromises with inflated or reused databases to force payment. Claiming an entire CRM lead list of over 152,000 records is common in these campaigns because the volume sounds alarming even when the actual risk to any single person is modest.

Knowing this pattern helps you calibrate your concern with the next similar listing you see. The presence of a leak-site post should prompt basic account hygiene but does not, by itself, mean your full personal history is circulating on criminal forums.

What You Can Still Control

Even if some of your contact details were included, you retain practical leverage. Most of the claimed data consists of information you can monitor and partially neutralise.

  • Change your BeLi Teacher and FSC passwords now and enable two-factor authentication everywhere the option exists. This closes the account-level route even if credentials were taken.
  • Watch for unexpected login attempts or password-reset emails from any service where you reuse elements of your BeLi contact information.
  • Be wary of phishing attempts that reference your study interests or past engagement with these centres. Attackers sometimes use such details to make fraudulent messages appear legitimate.
  • Review recent bank and email statements for any charges or sign-ups you do not recognise. Early detection limits damage from any downstream identity misuse.

Absence of a direct notification letter from the organisation usually indicates your records were not part of any affected group, though anyone who has changed address since the claimed events should contact BeLi Teacher or FSC directly to confirm their status.

GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, with identity-chain mapping and specialist remediation support.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
BeLi Teacher / FSC education centers is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High the filing does not enumerate what was exposed
Disclosed September 18, 2026
Last reviewed September 18, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email