San Diego District Breach Derails Data of More than 500,000

In late December, families in the San Diego Unified School District were notified of a data breach launched through successful phishing emails. The number of affected people totaled more than 500,000, according to the district. A phishing email is an online scam in which a message appears to be from a legitimate source to encourage recipients to click on a link that enables criminals to fraudulently capture the information provided.

The school system estimated that before it was discovered the viewing and copying of some of the personal data had gone on for nearly a year, beginning in January 2018. The incident was uncovered in October by internal IT staff investigating a flurry of phishing emails, which were used to gather log-in information of some 50 staff members throughout the district.

According to the district, school police have also identified a "subject of the investigation" and have blocked stolen credentials.

Among the data exposed:

  • Student and staff names, birth dates, addresses and phone numbers;
  • Enrollment information, including discipline incident, health and attendance data;
  • Social Security numbers and state student ID numbers;
  • Emergency contact information;
  • Staff benefits details, such as beneficiaries and dependents and savings or flexible spending account information; and
  • Payroll and compensation information, including paychecks and direct deposit and tax details.

The data file containing student information dated back to the 2008-2009 school year.

District police and IT staff reported that they've identified the methodology used to breach district systems. All staff members whose accounts were compromised had the security on their accounts reset immediately upon discovery. Additional data security measures have been implemented to help prevent these types of occurrences from happening in the future, they said.

All individuals affected by the breach have been notified by letter and advised to set up identity theft alerts and take advantage of free credit reporting.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • three silhouetted education technology leaders with thought bubbles containing AI-related icons

    Ed Tech Leaders Rank Generative AI as Top Tech Priority

    In a recent CoSN survey, an overwhelming majority of ed tech leaders (94%) said they see AI as having a positive impact on education. Respondents ranked generative AI as their top tech priority, with 80% reporting their districts have gen AI initiatives underway, or plan to in the current school year.

  • computer monitor with a bold AI search bar on the screen

    Google Rolls Out AI Mode in Search

    About a year after introducing AI Overviews for its flagship search offering, Google has announced broad availability of AI Mode in Search.

  • glowing shield hovers above a digital cloud platform with abstract data streams and cloud icons in the background

    Google to Acquire Cloud Security Firm Wiz in $32 Billion Deal

    Google has announced it will acquire cloud security startup Wiz for $32 billion. If completed, the acquisition — an all-cash deal — would mark the largest in Google's history.

  • students using digital devices, surrounded by abstract AI motifs and soft geometric design

    Ed Tech Startup Kira Launches AI-Native Learning Platform

    A new K-12 learning platform aims to bring personalized education to every student. Kira, one of the latest ed tech ventures from Andrew Ng, former director of Stanford's AI Lab and co-founder of Coursera and DeepLearning.AI, "integrates artificial intelligence directly into every educational workflow — from lesson planning and instruction to grading, intervention, and reporting," according to a news announcement.