Stolen Credentials Disrupt Schools and Networks
Coverage from BleepingComputer, WKBW 7 News Buffalo, and others

The topic centers on attackers using administrator, contractor, or retained employee credentials to compromise school districts, education platforms, and enterprise networks.
The incidents include account deletion, password changes, device-management disruption, large-scale student-data exposure, and an attempted ransom demand. Criminal prosecutions and prison sentences underscore the legal consequences, while the cases show how credential controls remain central to protecting systems with broad operational or personal-data access.
The update sharpens the story around named perpetrators and specific credential pathways, especially retained school IT access and stolen contractor credentials, while adding that prosecutions have progressed to guilty pleas and sentencing. It also reframes the incidents as attacks on identity and administration layers across education systems, not just isolated breaches.
The story now extends from insider abuse of retained credentials to a broader credential-compromise pattern, adding the PowerSchool breach as a major example of stolen contractor access leading to massive education-record exposure. It also strengthens the enforcement angle by emphasizing federal penalties and the scale of operational and privacy harm.
