San Diego District Breach Derails Data of More than 500,000

In late December, families in the San Diego Unified School District were notified of a data breach launched through successful phishing emails. The number of affected people totaled more than 500,000, according to the district. A phishing email is an online scam in which a message appears to be from a legitimate source to encourage recipients to click on a link that enables criminals to fraudulently capture the information provided.

The school system estimated that before it was discovered the viewing and copying of some of the personal data had gone on for nearly a year, beginning in January 2018. The incident was uncovered in October by internal IT staff investigating a flurry of phishing emails, which were used to gather log-in information of some 50 staff members throughout the district.

According to the district, school police have also identified a "subject of the investigation" and have blocked stolen credentials.

Among the data exposed:

  • Student and staff names, birth dates, addresses and phone numbers;
  • Enrollment information, including discipline incident, health and attendance data;
  • Social Security numbers and state student ID numbers;
  • Emergency contact information;
  • Staff benefits details, such as beneficiaries and dependents and savings or flexible spending account information; and
  • Payroll and compensation information, including paychecks and direct deposit and tax details.

The data file containing student information dated back to the 2008-2009 school year.

District police and IT staff reported that they've identified the methodology used to breach district systems. All staff members whose accounts were compromised had the security on their accounts reset immediately upon discovery. Additional data security measures have been implemented to help prevent these types of occurrences from happening in the future, they said.

All individuals affected by the breach have been notified by letter and advised to set up identity theft alerts and take advantage of free credit reporting.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • magnifying glass highlighting a human profile silhouette, set over a collage of framed icons including landscapes, charts, and education symbols

    New AI Detector Identifies AI-Generated Multimedia Content

    Amazon Web Services and DeepBrain AI have launched AI Detector, an enterprise-grade solution designed to identify and manage AI-generated content across multiple media types. The collaboration targets organizations in government, finance, media, law, and education sectors that need to validate content authenticity at scale.

  • open laptop with various educational materials like charts, quizzes, and documents emerging from the screen

    Pear Deck Learning Debuts New AI Features

    GoGuardian recently introduced new artificial intelligence features within its Pear Deck Learning curriculum and instruction platform, designed to aid educators throughout their teaching journey — from lesson planning to assessment.

  • interconnected gears and cogs

    Integration Brings Anthropic Claude AI Models to Copilot

    Microsoft has integrated Anthropic's Claude artificial intelligence models to its Microsoft 365 Copilot platform, giving enterprise users another option beyond OpenAI's models for powering workplace AI experiences.

  • woman using network-connected printer

    The Hidden Cyber Risk in Schools

    Printers may not be glamorous, but they are an often-overlooked attack vector that should be part of every district's cybersecurity strategy.