Last Update: 09/22/2026 at 11:34 PM EST

School District Breaches Expose Student Data

Coverage from WSMV 4, Tnonline, and others

School District Breaches Expose Student Data topic image

U.

S. school districts are investigating a series of cybersecurity incidents and data disclosures involving student, parent, employee, and retiree information. Exposed or potentially exposed records include names, birth dates, addresses, identification numbers, contact details, financial information, and other sensitive education or household data. The incidents also show that school cyber events can disrupt enrollment and school schedules while investigations determine the scope of access and whether misuse occurred.

History
08/05/20260 new articles

The story has shifted from a set of separate district breach reports to a broader picture of varied school-data incidents, including system intrusions, third-party compromises, and accidental records disclosures. The current version also clarifies that investigators are still assessing misuse and scope, while emphasizing a wider set of affected stakeholders.

08/04/20260 new articles

The story now broadens from a set of school-record exposure incidents into a more varied cyber/privacy pattern, adding a vendor portal compromise and a separate public posting of unredacted Social Security and financial information. It also adds new actors and confirms operational disruption in at least one district.

  • PowerSchool portal incident affected multiple Connecticut districts.
  • Lehighton involved publicly posted unredacted Social Security numbers.
  • Lehighton also exposed pension or financial information.
  • School breaches can disrupt enrollment and operations.
  • FBI and D.C. technology officials are now involved.
08/02/20264 new articles

The story has expanded from a few named district incidents into a broader June-July 2026 cluster of school-record exposures, now emphasizing repeated patterns of personal-data exposure and varied access points. It also adds DCPS and Lehighton as notable new cases and sharpens the response picture with more explicit law-enforcement and operational actions.

  • Seven of eight reports are dated June or July 2026.
  • DCPS investigated exposure from a Summer Learning registration application.
  • Lehighton Area School District joined the story as a public-records exposure case.
  • Exposure channels now include registration applications and public-records workflows.
  • The FBI is now named as a participant in multiple investigations.
07/28/2026Topic Formed

U.S. school districts are managing a range of data-security incidents, from unauthorized network access and vendor-portal compromise to the public posting of unredacted employee and retiree records. Exposed information includes student identifiers, household contact details, lunch-program data, Social Security numbers, pension information, and potentially financial or medical records, while one Tennessee district delayed enrollment and the start of classes during its investigation. The incidents are prompting law-enforcement involvement, family notifications, tighter controls on records access, and reviews of data retention and third-party systems.