<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Site-Server v@build.version@ (http://www.squarespace.com) on Sat, 15 Aug 2026 03:30:59 GMT
--><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://www.rssboard.org/media-rss" version="2.0"><channel><title>K-12 Cybersecurity Insider - K12 SIX</title><link>https://www.k12six.org/k12-cybersecurity-insider/</link><lastBuildDate>Fri, 14 Aug 2026 20:41:19 +0000</lastBuildDate><language>en-US</language><generator>Site-Server v@build.version@ (http://www.squarespace.com)</generator><description><![CDATA[]]></description><item><title>K-12 Cybersecurity Insider | 8/3/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 03 Aug 2026 12:27:46 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/20268-3</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:6a6fe2696b329c1838643032</guid><description><![CDATA[A public newsletter providing curated cybersecurity news to the K-12 
community as a service of K12 SIX, the K-12 education ISAC.]]></description><content:encoded><![CDATA[<p data-rte-preserve-empty="true" class=""><em>A public newsletter providing curated cybersecurity news to the K-12 community as a service of K12 SIX, the K-12 education ISAC. Allowlist info[@]k12six[.]org - and sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> - to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3 data-rte-preserve-empty="true"><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="">8/13 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">Monthly Cross-Sector Threat Briefing</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">8/25 - <a target="_blank" href="https://www.grfbrc.org/ttxdisconnect">Disconnect/Reconnect Tabletop Exercise</a></p></li><li><p data-rte-preserve-empty="true" class="">8/26 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">9/8 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/lumu98">Inside the Attacker’s Playbook: How EDR Evasion Really Works</a>” Webinar</p></li></ul><h3 data-rte-preserve-empty="true"><strong>In the News</strong></h3><p data-rte-preserve-empty="true"><strong>In Like a Lion</strong></p><p data-rte-preserve-empty="true">While most K-12 school systems are still preparing to welcome students and teachers back for the kick-off of the fall semester, threat actors aren’t waiting. School systems in <a target="_blank" href="https://ncpipeline.substack.com/p/cyberattack-targets-oceanside-unified">California</a>, <a target="_blank" href="https://www.nbcwashington.com/news/local/dcps-data-breach-potentially-exposed-students-names-addresses-birthdays/4136249/">DC</a>, <a target="_blank" href="https://hoodline.com/2026/07/cyber-crooks-crash-newton-schools-as-fbi-swarms-in-days-before-first-bell-7061853/">Georgia</a>, and <a target="_blank" href="https://www.wsmv.com/2026/07/31/sumner-county-schools-network-restored-after-data-breach-delays-start-school-year-heres-what-you-need-know/">Tennessee</a>, for instance, have all reported recent incidents - to say nothing of the wave after wave of email-based phishing that school communities are <a target="_blank" href="https://www.lawtonps.org/live_feeds/12712423">currently</a><a target="_blank" href="https://star1025fm.com/moore-county-schools-email-scam-warning/ ">being</a><a target="_blank" href="https://www.minisink.com/article/3036939">battered</a><a target="_blank" href="https://www.facebook.com/groups/1428232187380759/posts/3260101777527115/">by</a>. It is no wonder that the <a target="_blank" href="https://www.aol.com/articles/irs-warns-back-school-scams-195707000.html">IRS is warning of back-to-school scams</a>. </p><p data-rte-preserve-empty="true"><strong>Schools Should Plan Now for Significant Security Changes Coming to Microsoft, Google</strong></p><p data-rte-preserve-empty="true">Microsoft is <a target="_blank" href="https://www.windowslatest.com/2026/07/22/microsoft-admits-sms-and-voice-mfa-cant-stop-ai-attacks-mandates-passkeys-in-entra-by-february-2027/">retiring SMS and voice-based multi-factor authentication (MFA) in Microsoft Entra ID</a> and replacing it with passkeys as the default. Starting September 1, 2026, users will be prompted to register a passkey during their next MFA challenge. By October 30, 2026, IT administrators will be forced to configure a supported telecom provider through the Microsoft Security Store if they can’t get off telephony-based MFA. On February 1, 2027, Microsoft-provided SMS and voice authentication will be officially dead. “<a target="_blank" href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement">There is no opt out from this February 1 behavior</a>,” Microsoft says, “It will be enforced for all tenants.” For its part, Google is deprecating the Google SCEP (Simple Certificate Enrollment Protocol) API at the end of 2026. After that date, <a target="_blank" href="https://securew2.com/documentation/google/chromeos-migration-google-scep-to-google-certificate-provisioning-api">Chromebooks and other ChromeOS devices will no longer be able to enroll in school-managed enterprises</a> if they have not migrated to another solution. Plan now to avoid (potentially significant) disruptions.</p><p data-rte-preserve-empty="true"><a href="https://learn.microsoft.com/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication%22%20target="><strong>K12 SIX J</strong></a><a target="_blank" href="https://www.nationalisacs.org/post/national-council-of-isacs-welcomes-k12-six-extending-critical-infrastructure-threat-intelligence-to"><strong>oins National Council of ISACs</strong></a></p><p data-rte-preserve-empty="true" class="">The National Council of ISACs (NCI) has welcomed K12 SIX to its membership, <strong>formally connecting the nation's K-12 education community to the broader network of critical infrastructure threat intelligence sharing</strong>. Formed in 2003, the NCI is a cross-sector partnership of Information Sharing and Analysis Centers (ISACs) that provides a forum for sharing all-hazards threats and mitigation strategies among the ISACs, as well as with government partners. "NCI is excited to welcome its latest member, K12 SIX," said Denise Anderson, Chair of NCI. "Schools face increasingly complex cyber threats in today’s environment. The involvement of K12 SIX in NCI extends vital threat intelligence and mitigation strategies to the K-12 community while strengthening cross-sector collaboration across all of the nation's critical infrastructure sectors." To learn more, read the accompanying <a target="_blank" href="https://www.nationalisacs.org/post/national-council-of-isacs-welcomes-k12-six-extending-critical-infrastructure-threat-intelligence-to">press release</a>.</p><p data-rte-preserve-empty="true" class=""><strong>Practical Vendor Risk Management for Districts and Schools</strong></p><p data-rte-preserve-empty="true">While some sectors and organizations outside of K-12 education have a deep history implementing third-party/vendor risk management programs, practical guidance for school and district technology leaders about how to implement and operate a K-12 vendor risk management program has been lacking. K12 SIX is pleased to help address that guidance gap. Developed by practicing K-12 cybersecurity practitioners serving on the K12 SIX Technical Working Group, <em>Practical Vendor Risk Management for Districts and Schools</em> can be accessed <a target="_blank" href="https://www.k12six.org/s/Practical-K12Vendor-Risk-Management.pdf">here</a>. Other K-12 cybersecurity guidance, including our popular K12 SIX Essential Cybersecurity Protections, can always be found <a target="_blank" href="https://www.k12six.org/essentials-series">here</a>.</p><h3 data-rte-preserve-empty="true"><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></h3><p data-rte-preserve-empty="true" class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 8/3/2026 edition</media:title></media:content></item><item><title>Cybersecurity for Schools: The Summer Break Action Plan</title><category>Sponsored</category><category>Guidance</category><dc:creator>Doug Levin</dc:creator><pubDate>Tue, 07 Jul 2026 20:15:34 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/ms-bln4h</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:6a4d57f467c3725a2d8b2023</guid><description><![CDATA[Summer break is a high-risk period in cybersecurity for schools. Discover 
practical cybersecurity solutions for how to secure school networks over 
the summer]]></description><content:encoded><![CDATA[<hr />
  
    

    



  


  
  <h4 data-rte-preserve-empty="true"><strong>The Summer Cybersecurity Challenge</strong></h4>


  










  
  <p data-rte-preserve-empty="true">While students and staff look forward to summer vacation, cybercriminals view empty hallways as prime operational time.&nbsp;According to the 2026 Lumu Report on Cybersecurity for Education, schools are now the #1 cybercrime target in the US. The&nbsp;summer break creates a "perfect storm" of skeleton IT crews, reduced network monitoring, and unpatched vulnerabilities. School IT environments are uniquely complex, managing thousands of on-campus student devices alongside on-campus IoT infrastructure (like smartboards and security cameras). </p><p data-rte-preserve-empty="true">Compounding this challenge, many school tech leads are actually teachers or coaches roped into the role, leaving teams understaffed. Recent high-profile breaches—such as the 2026 Canvas platform shutdown by ShinyHunters—highlight that threat actors actively exploit these exact operational gaps. </p><p data-rte-preserve-empty="true">Click <a target="_blank" href="https://www.k12six.org/s/lumu-Cybersecurity-for-Schools-The-Guide-to-Summer-Break-pdf-blog-v2-1.pdf">here</a> to access Lumu's complete Summer Break Action Plan for Schools including tips on: </p><ul data-rte-list="default"><li><p data-rte-preserve-empty="true">Pre-Break Priorities: Inventory and Audit</p></li><li><p data-rte-preserve-empty="true">Summer Housekeeping: Securing the Quiet Months</p></li><li><p data-rte-preserve-empty="true">Turning Vulnerability into Advantage</p><p data-rte-preserve-empty="true"></p></li></ul>]]></content:encoded><media:content type="image/png" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1783455539786-TRUDWZ3ZCESBZON4T89M/lumu+2.png?format=1500w" medium="image" isDefault="true" width="800" height="445"><media:title type="plain">Cybersecurity for Schools: The Summer Break Action Plan</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 6/8/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 08 Jun 2026 11:00:11 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2026-6-8</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:6a25bf4dd8c9092abdaea294</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p data-rte-preserve-empty="true" class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Allowlist info[@]k12six[.]org - and sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> - to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3 data-rte-preserve-empty="true"><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="">6/10 - <a target="_blank" href="https://www.grfbrc.org/virtual2026">BRC Virtual Cross-Sector Summit</a></p></li><li><p data-rte-preserve-empty="true" class="">6/11 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">Monthly Cross-Sector Threat Briefing</a><a href="https://k12six.cyware.com/webapp/user/events">(member-only)</a></p></li><li><p data-rte-preserve-empty="true" class="">6/24 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">6/24 - <a target="_blank" href="https://www.grfbrc.org/orf-exercise-reg">AI Interrupted: A Multi-Sector Tabletop Exercise</a></p></li><li><p data-rte-preserve-empty="true" class="">7/7 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/idauto77">Identity Orchestration: The Missing Layer in Your District's Digital Learning Environment</a>” webinar </p></li></ul><h3 data-rte-preserve-empty="true"><strong>In the News</strong></h3><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://www.k12six.org/k12-cybersecurity-insider/k12-six-canvas-incident-response"><strong>Pulling Back the Curtain on the Canvas Cyber Incident</strong></a></p><p data-rte-preserve-empty="true">Since the lion’s share of K12 SIX’s work with our members involves handling the sensitive operational details of defending schools from active cyber threats, it remains out of the public eye. The downside: our role and the value of our work remains opaque to the wider education community. The recent Canvas LMS cyber incident, however, provides a chance for us to pull back that proverbial curtain and offer a peek into our efforts. </p><p data-rte-preserve-empty="true"><a target="_blank" href="https://youtu.be/E2EBR3kAdeg?si=qNksCUo7fc--f7ib"><strong>Strengthening K-12 Cybersecurity: Simple Steps for Safer Schools</strong></a></p><p data-rte-preserve-empty="true" class="">On May 28, the Cybersecurity and Infrastructure Security Agency (CISA) School Safety Task Force held a virtual training, entitled “Strengthening K-12 Cybersecurity: Simple Steps for Safer Schools.”</p>


  










  


  
    <iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen src="https://www.youtube-nocookie.com/embed/E2EBR3kAdeg?si=vbtTzQM_qQAd629t" width="560" frameborder="0" title="YouTube video player" height="315"></iframe>
  
  








  
  <p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://www.yourvalley.net/stories/cybersecurity-is-becoming-a-core-school-safety-issue,693433"><strong>K-12 Cybersecurity is a Core School Safety Issue</strong></a></p><p data-rte-preserve-empty="true">For years, school safety discussions focused largely on physical security — campus entrances, emergency drills and school resource officers. Today, education leaders say cybersecurity must become part of that same conversation. A single cyberattack can disrupt learning across entire districts, expose thousands of student records and interrupt operations for days or weeks. As schools continue integrating technology into nearly every aspect of instruction, cybersecurity preparedness is increasingly becoming as essential as any other infrastructure investment.</p><p data-rte-preserve-empty="true" class=""><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></p><p data-rte-preserve-empty="true" class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 6/8/2026 edition</media:title></media:content></item><item><title>Pulling Back the Curtain on the Canvas Cyber Incident</title><category>Commentary</category><dc:creator>Doug Levin</dc:creator><pubDate>Fri, 05 Jun 2026 18:36:19 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/k12-six-canvas-incident-response</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:6a22f76deedee9194add11bb</guid><description><![CDATA[Since the lion’s share of K12 SIX’s work with our members involves handling 
sensitive information, it remains out of the public eye. The Canvas cyber 
incident provides a chance for us to pull back that proverbial curtain and 
share more.]]></description><content:encoded><![CDATA[<p data-rte-preserve-empty="true">Since the lion’s share of K12 SIX’s work with our members involves handling the sensitive operational details of defending schools from active cyber threats, it remains out of the public eye. The downside: our role and the value of our work remains opaque to the wider education community. The recent Canvas LMS cyber incident, however, provides a chance for us to pull back that proverbial curtain and offer a peek into our efforts. The scope and rapid evolution of the incident required significant effort by K12 SIX and its members to determine ground truth and recommend appropriate responses.</p><p data-rte-preserve-empty="true" class="MsoNormal">Over three weeks, starting Friday, May 1 <a target="_blank" href="https://www.bleepingcomputer.com/news/security/edu-tech-firm-instructure-discloses-cyber-incident-probes-impact/">when Instructure first disclosed it had experienced a security incident</a>, K12 SIX and its members immediately started coordinating and taking collective action:</p><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="MsoListParagraphCxSpFirst">K12 SIX organized and led four separate confidential member briefings to provide updates on incident developments, including—at the invitation of K12 SIX—a briefing joined by Instructure’s CISO</p></li><li><p data-rte-preserve-empty="true" class="MsoListParagraphCxSpFirst">K12 SIX also conducted, and confidentially shared the results of, a quick-turnaround survey of members to assess their operational status and actions taken as part of incident response</p></li><li><p data-rte-preserve-empty="true" class="MsoListParagraphCxSpFirst">Members submitted threat intelligence that was vetted, enhanced, anonymized, and converted into confidential alerts by K12 SIX analysts who then shared them with the wider membership</p></li><li><p data-rte-preserve-empty="true" class="MsoListParagraphCxSpFirst">Other members discussed developments, insights, and questions via secure, real-time chat communications channels established for this purpose</p></li></ul><p data-rte-preserve-empty="true" class="MsoNormal">In parallel, the K12 SIX team:</p><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="MsoListParagraphCxSpFirst">Monitored the dark web leak site operated by the threat actor</p></li><li><p data-rte-preserve-empty="true" class="MsoListParagraphCxSpFirst">Reviewed historical issues and public discussions raised in GitHub, and discussion forums organized around <a target="_blank" href="https://code.instructure.com/">Canvas’ open-source code</a>, as well as relevant information about the <a target="_blank" href="https://www.1edtech.org/standards/lti">Learning Tools Interoperability</a> (LTI) standard and security model</p></li><li><p data-rte-preserve-empty="true" class="MsoListParagraphCxSpFirst">Collaborated and shared threat intelligence with representatives of the community of organizations participating in the Institute for Security and Technology’s <a target="_blank" href="https://securityandtechnology.org/blog/announcing-the-k12-cyber-defense-coalition/">K-12 Cyber Defense Coalition</a>, as well as with trusted security researchers and federal partners</p></li><li><p data-rte-preserve-empty="true" class="MsoListParagraphCxSpFirst">To ensure accuracy, responded to numerous requests for context and commentary from education and general news reporters, resulting in seven <a target="_blank" href="https://www.k12six.org/all-news/#2026">media mentions</a> including a live TV interview with LiveNOW from FOX</p></li></ul><p data-rte-preserve-empty="true" class="MsoNormal">While some questions remain unanswered and breach notifications remain in progress, the active cyber-attack against Instructure seems to have come to a conclusion. However, K12 SIX will continue to work with partners to monitor the dark web for leaked credentials or other personally identifiable information associated with the incident, as well as the results of both regulatory and legal challenges stemming from the incident.</p><p data-rte-preserve-empty="true" class="MsoNormal"><strong>When we at K12 SIX say ‘members get more’ this is what we mean. </strong>The guidance and resources on our public-facing website represent only a small portion of the work we do. The real work is side-by-side with our member community, day in and day out.</p><p data-rte-preserve-empty="true" class="MsoNormal">K12 SIX was founded out of the belief that schools both needed and deserved a trusted cybersecurity partner—one that was laser-focused on the unique needs and context of the K-12 education community. <a target="_blank" href="https://www.k12six.org/member-benefits">We invite eligible education organizations to join us in our work</a>. We are stronger when we work together.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1780676602012-WP1Q2AL6XYKVYFP0TWCE/max-harlynking-jqyIMfUyF84-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="844"><media:title type="plain">Pulling Back the Curtain on the Canvas Cyber Incident</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 5/18/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 18 May 2026 11:30:55 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2026-5-18</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:6a09ef3e2ee49b1a21d46ebe</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p data-rte-preserve-empty="true" class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Allowlist info[@]k12six[.]org - and sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> - to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3 data-rte-preserve-empty="true"><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="">5/18 - “<a target="_blank" href="https://www.instructure.com/resources/webinar/technical-deep-dive-recent-security-incident">Instructure: Technical Deep Dive on Recent Security Incident</a>” (intended for customers)</p></li><li><p data-rte-preserve-empty="true" class="">5/21 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">“When the Screens Go Dark:” K-12 Cybersecurity Virtual TableTop Exercise</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">5/27 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li></ul><h3 data-rte-preserve-empty="true"><strong>On the Soapbox</strong></h3><p data-rte-preserve-empty="true" class=""><strong>Reflecting on  a Decade of K-12 Cyber Incidents</strong></p>


  










  
  <p data-rte-preserve-empty="true">On May 18, 2016 - exactly a decade ago to the day - the U.S. Senate Committee on the Judiciary, Subcommittee on Crime and Terrorism held a hearing entitled, “<a target="_blank" href="https://www.judiciary.senate.gov/committee-activity/hearings/ransomware-understanding-the-threat-and-exploring-solutions">Ransomware: Understanding the Threat and Exploring Solutions</a>.” Charles Hucks, Executive Director of Technology, Horry County Schools provided testimony and answered questions regarding the <a target="_blank" href="https://www.k12dive.com/news/south-carolina-district-paid-8000-for-ransomed-datas-return/420646/">recent ransomware attack against the South Carolina school district</a>.</p>


  










  


  
  
    
    
      
        
        
        
          
          
            
        
        
          <iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen src="https://www.youtube-nocookie.com/embed/O_WH2B7OzpQ?si=45URTLrICpjYkqr5" width="560" frameborder="0" title="YouTube video player" height="315"></iframe>
        
        
            
          
        
        
      
    
  
  
    



  



  



  
  <p data-rte-preserve-empty="true" class="">Much has changed in education, technology, and cyber crime since that time. Schools use more technology than ever - for teaching and learning, but also for administration and operations. The software schools rely on is no longer run in school-managed data centers, but as vendor-managed SaaS applications in ‘the cloud.’ Threat actors often exfiltrate terabytes of sensitive data in lieu of encrypting it - with extortion demands now reaching seven figures or more. And, while school systems <a target="_blank" href="https://www.wric.com/news/local-news/hanover-county/hcps-data-breach-attempted-ransomware-attack/">still fall prey to ransomware attacks</a>, threat actors are moving upstream to focus on bigger fish: education vendors, such as <a target="_blank" href="https://www.instructure.com/incident_update">Instructure</a>, <a target="_blank" href="https://www.powerschool.com/security/sis-incident/">PowerSchool</a>, and <a target="_blank" href="https://www.ftc.gov/news-events/news/press-releases/2025/12/ftc-takes-action-against-education-technology-provider-failing-secure-students-personal-data">Illuminate</a>.</p><p data-rte-preserve-empty="true" class="">One is left to wonder:</p><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="">Are students and families safer and more secure today than a decade ago? </p></li><li><p data-rte-preserve-empty="true" class="">Is the technology used in education safer and more secure? Does it respect the privacy and agency of children and youth? Is it free from vulnerabilities and exploits? </p></li><li><p data-rte-preserve-empty="true" class="">Have schools - and their vendors and partners - allocated sufficient resources and attention to cybersecurity?</p></li><li><p data-rte-preserve-empty="true" class="">Is the sector more resilient today to cybersecurity incidents than a decade ago? </p></li><li><p data-rte-preserve-empty="true" class="">Has the response from education leaders and policymakers been sufficient?</p></li></ul><p data-rte-preserve-empty="true" class="">Nothing that has occured over the last decade was unpredictable. We can enumerate the problems and issues. Only by working together can we hope to make a meaningful change. Let us not miss the moment to act.</p><p data-rte-preserve-empty="true" class=""><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></p><p data-rte-preserve-empty="true" class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 5/18/2026 edition</media:title></media:content></item><item><title>From Guesswork to Guardrails: How K‑12 Schools Can Predict and Control Microsoft Sentinel Costs</title><category>Sponsored</category><category>White Paper</category><dc:creator>Doug Levin</dc:creator><pubDate>Tue, 05 May 2026 14:20:17 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/ms</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:69f9fb8bde6cff021c71a611</guid><description><![CDATA[One of the first questions a school district asks when considering 
Microsoft Sentinel is: “What will this actually cost us?"]]></description><content:encoded><![CDATA[<hr />
  
    

    



  


  
  <p data-rte-preserve-empty="true">One of the first questions a school district asks when considering <a target="_blank" href="https://learn.microsoft.com/en-us/azure/sentinel/overview?tabs=defender-portal">Microsoft Sentinel</a> is:<strong> “What will this actually cost us?"</strong></p><p data-rte-preserve-empty="true">Many Microsoft customers and partners today estimate Sentinel costs using the Azure Pricing Calculator, but that calculator doesn't provide the Sentinel-specific usage guidance needed to understand how each Sentinel meter contributes to overall spend. For K‑12 education, where budgets are fixed, IT teams are stretched thin, and adoption is necessarily phased, that kind of uncertainty can slow deployment or derail a pilot entirely.&nbsp;</p><p data-rte-preserve-empty="true" class="Paragraph SCXW237482404 BCX8">The “<a target="_blank" href="https://www.k12six.org/s/Guesswork-to-Guardrails.pdf">From Guesswork to Guardrails: How K‑12 Schools Can Predict and Control Microsoft Sentinel Costs</a>” white paper presents a practical, end-to-end approach for K‑12 districts to <strong>predict, control, and manage</strong> Microsoft Sentinel costs from pilot through full production. It covers the new Sentinel Cost Estimator, the role of data ingestion as the dominant cost driver, phased deployment strategy, Azure budget alerts and automation, ingestion monitoring, and the careful use of Log Analytics daily caps.&nbsp;</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1777991738390-BIIQJSVQUJ000OBOTFHD/Security-Diagram.jpg?format=1500w" medium="image" isDefault="true" width="900" height="506"><media:title type="plain">From Guesswork to Guardrails: How K‑12 Schools Can Predict and Control Microsoft Sentinel Costs</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 5/4/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 04 May 2026 11:30:14 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2026-5-4</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:69f760a4fcb0a60006e7865f</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3 data-rte-preserve-empty="true"><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="">5/4 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">K12 SIX Essential Cybersecurity Protections Workshop</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">5/5 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/ms55">Leveraging Defender XDR &amp; Sentinel Automations</a>” webinar (sponsored by Microsoft) | Free and open to the K-12 community</p></li><li><p data-rte-preserve-empty="true" class="">5/14 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">Monthly Cross-Sector Threat Briefing</a> (member-only)</p></li><li><p data-rte-preserve-empty="true">5/21 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">“When the Screens Go Dark:” K-12 Cybersecurity Virtual TableTop Exercise</a> (member-only)</p></li></ul><h3 data-rte-preserve-empty="true"><a href="https://k12six.cyware.com/webapp/user/events"><strong>In the News</strong></a></h3><p data-rte-preserve-empty="true" class=""><strong>EdTech Companies - Like Most Small/Medium Businesses - Under Frequent Cyber Attack</strong></p><p data-rte-preserve-empty="true" class="">Small and medium businesses - including the majority of U.S. K-12 education software businesses - are frequent cybersecurity targets: <a target="_blank" href="https://www.hiscoxgroup.com/sites/group/files/documents/2025-10/HSX374%20%E2%80%93%202025%20CRR%20Report%20Final.pdf">59 percent of small and medium businesses experienced a cyber attack in the last year</a>, according to one insurance company’s research. Yet, for many, the reaction to a K-12 vendor experiencing a cyber attack is one of shock and surprise. In the last several months, we’ve seen new reports of incidents affecting: <a target="_blank" href="https://cyberscoop.com/maps360-student-data-breach-senate-investigation/">Navigate360</a> (ongoing), <a target="_blank" href="https://linqdataincident.com/">LINQ</a>, <a target="_blank" href="https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/">Infinite Campus</a>, <a target="_blank" href="https://databreaches.net/2026/05/03/instructure-discloses-second-data-breach-in-less-than-a-year/">Instructure</a> (again, ongoing), <a target="_blank" href="https://www.bleepingcomputer.com/news/security/data-breach-at-edtech-giant-mcgraw-hill-affects-135-million-accounts/">McGraw Hill</a>, <a target="_blank" href="https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-follett-software-llc/">Follet</a> (ongoing), <a target="_blank" href="https://databreaches.net/2025/10/04/powerschool-hit-by-by-salesloft-drift-campaign-but-hackers-claim-that-there-is-no-risk-or-harm-or-ransom/">PowerSchool</a> (largely missed, given the prior <a target="_blank" href="https://www.powerschool.com/security/sis-incident/">well-publicized incident</a>), <a target="_blank" href="https://www.claimdepot.com/data-breach/kaplan-2026">Kaplan</a>, and <a target="_blank" href="https://techcrunch.com/2026/01/20/ustrive-security-lapse-exposed-personal-data-of-its-users-including-children/">UStrive</a>, among others. We’ve also seen settlements with regulators (<a target="_blank" href="https://www.ftc.gov/news-events/news/press-releases/2025/12/ftc-takes-action-against-education-technology-provider-failing-secure-students-personal-data">Illuminate</a>) and ongoing court cases (<a target="_blank" href="https://databreaches.net/2026/05/01/unprecedented-private-equity-firm-potentially-on-hook-for-powerschools-data-breach/">Bain/PowerSchool</a>) that, while likely to shape market behavior, won’t do enough in and of themselves to stem the tide. Clever’s most recent K-12 cybersecurity report highlighted the surge in K-12 vendor incidents, writing: “<a target="_blank" href="https://www.clever.com/wp-content/uploads/2026/03/Cybersecure-2026-Report_Clever.pdf">For cybersecurity measures to be most effective, districts and vendors will have to work together</a>.” Indeed, if we make that mental shift from being surprised by an edtech vendor incident to instead expecting that they are likely to occur - because that is what evidence shows - what else may need to change?</p><p data-rte-preserve-empty="true" class=""><strong>Student Credentials Deserve Protection, Too</strong></p><p data-rte-preserve-empty="true" class="">Who cares about Johnny’s grades or homework assignments, you may wonder? Probably not many people - and certainly not most threat actors. Instead, they have other uses they can put that access to, as several Connecticut communities have recently learned. State and local police in and around Putnam have been investigating a string of threats against local schools, many of which officials say are likely <a target="_blank" href="https://quietcorneralerts.com/2026/03/27/police-regional-school-threats-likely-linked-to-compromised-student-accounts/">linked to compromised student email accounts</a> and scam-related activity originating from foreign domains. One has to imagine that local law enforcement - <a target="_blank" href="https://www.ctinsider.com/news/article/putnam-police-investigate-3rd-threat-hacked-22216458.php">having to spend time and resources in responding</a> - would vehemently agree that stronger student account protections are warranted. </p><p data-rte-preserve-empty="true" class=""><strong>Millions Stolen from Schools Via Business Email Compromise Attacks</strong></p><p data-rte-preserve-empty="true" class="">Two recent stories that drive home the seriousness of the issue: <a target="_blank" href="https://katv.com/news/local/pine-bluff-school-district-scammed-out-of-more-than-32-million-after-cybersecurity-hack">In Arkansas, one school system was bilked out of more than $3.2 million</a>, while <a target="_blank" href="https://bismarcktribune.com/news/state-regional/crime-courts/article_08a11cb3-eb41-4740-b53e-90625f748557.html">a North Dakota school system had nearly $5 million stolen</a>. The kicker: the techniques used by threat actors to carry out these attacks are well-understood as are the ways to stop them. One spot of good news: when perpetrators are based in the U.S., law enforcement can and does act - <a target="_blank" href="https://www.justice.gov/usao-md/pr/washington-dc-woman-sentenced-role-hstf-multi-million-dollar-money-laundering-conspiracy">sometimes resulting in jail time and financial penalties for the perpetrators</a>. </p><p data-rte-preserve-empty="true" class=""><strong>Save the Date: 2027 K12 SIX Annual Conference </strong></p><p data-rte-preserve-empty="true" class="">K12 SIX is pleased to announce that the next edition of the premier event for K-12 cybersecurity practitioners will be held from <strong>February 17-19, 2027 in Atlanta, Georgia</strong>. Mark your calendars and stay tuned for more information on speaker submissions, registration, and sponsorship opportunities. </p><h3 data-rte-preserve-empty="true"><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></h3><p data-rte-preserve-empty="true" class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 5/4/2026 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 4/20/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 20 Apr 2026 12:07:21 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/20264-9-s23xt</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:69e528a05dbf246e1f332731</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3 data-rte-preserve-empty="true"><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="">4/21 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/clever421">Beyond the Breach: Setting a New Security Standard for Vendor Partnerships</a>” webinar (sponsored by Clever)</p></li><li><p data-rte-preserve-empty="true" class="">4/22 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">5/5 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/ms55">Leveraging Defender XDR &amp; Sentinel Automations</a>” webinar (sponsored by Microsoft)</p></li></ul><h3 data-rte-preserve-empty="true"><strong>In the News</strong></h3><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://www.k12six.org/news/k12-six-updates-k-12-cybersecurity-recommendations-for-2024-25-school-year-wpy9b"><strong>K12 SIX Essential Cybersecurity Protections: Updated for 2026!</strong></a></p><p data-rte-preserve-empty="true" class="">Developed by K-12 IT practitioners, for K-12 IT practitioners—and aligned to cybersecurity risk management best practices—the K12 SIX Essentials series establishes baseline cybersecurity standards for U.S. school systems and provides guidance and tools to support their implementation. K12 SIX-recommended practices are designed to defend against the most common cyber threats facing school districts, including those identified by K12 SIX, the Federal Bureau of Investigation (FBI), the Cybersecurity &amp; Infrastructure Security Agency (CISA), the U.S. Department of Education (ED), school insurance carriers, and other experts. <a target="_blank" href="https://www.k12six.org/k12six-webinars/essentials26">ICYMI: a recent webinar provided an overview of the K12 SIX Essential Cybersecurity Protections and how to use them</a>.</p><p data-rte-preserve-empty="true" class=""><strong>Spring Showers Bring K-12 Cyber Incidents</strong></p><p data-rte-preserve-empty="true" class="">Public reports of threat actors targeting schools tend to spike at a few specific times in the school calendar. One of those coincides with Spring Break season (March/April) and - unfortunately - this year does not appear to be an exception to that larger trend. <a target="_blank" href="https://www.cbsnews.com/minnesota/news/spring-lake-park-schools-closed-ransomware-attack/">Spring Lake Park (MN) Schools</a> recently closed for two days to respond to a alleged ransomware incident. Previously, <a target="_blank" href="https://www.govtech.com/education/k-12/alamo-heights-isd-declines-to-say-whether-it-paid-ransom">Alamo Heights Independent School District</a> (TX) experienced wide scale internet outages as it worked to recover from its own alleged ransomware incident. Meanwhile, the <a target="_blank" href="https://databreaches.net/2026/04/18/tax-documents-for-school-employees-potentially-stolen-across-los-angeles-county/">Los Angeles (CA) County Office of Education</a> is currently investigating the possibility that bad actors gained access to the electronic tax documents of teachers and administrators after employees at schools around the county received letters indicating fraudulent tax filings had been submitted in their names. Since not every K-12 cyber incident makes the national news, some may wonder whether the sector remains at elevated risk of breaches and cyber extortion. In short, <strong>the steady drumbeat of K-12 cybersecurity incidents continues</strong>.</p><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://databreaches.net/2026/04/16/p3-advertised-20-years-and-0-security-breaches-you-can-guess-what-happened-next/"><strong> P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.</strong></a></p><p data-rte-preserve-empty="true">“<a target="_blank" href="https://infosec.exchange/@PogoWasRight/116414263456926915">This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades</a>,” writes the author of this must-read post. Fair warning: as an application designed to collect anonymous tips, unsurprisingly there are myriad references to abuse and assault in the stolen files (which - at least as of a few days ago - were still up for sale on cybercriminal forums). Doug Levin, Director of K12 SIX added: “<strong>Harm reduction must be the primary goal, including for those who may continue to use the system</strong>. Disclosures to school, non-profit, and government partners must be prompt and forthright, and necessary mitigations must be implemented and validated by independent experts with urgency. Nearly a month has passed since credible claims of a security incident were made about Navigate360’s anonymous tip line service. The lack of communication from the company is simply unacceptable.”</p><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://this.weekinsecurity.com/that-big-company-hack-probably-was-not-an-employees-fault/"><strong>The Weakest Link in Security Isn’t Your Employees</strong></a></p><p data-rte-preserve-empty="true" class="">People click links and download files. They create weak passwords and re-use or share them. Given this inevitability, perhaps the weakest link isn’t the employees’ predictable behavior but the system itself. After all, if common, well-understood employee mistakes can result in show-stopping cyber incidents perhaps our IT systems are too fragile. Food for thought. </p><p data-rte-preserve-empty="true" class=""><strong>Save the Date: 2027 K12 SIX Annual Conference </strong></p><p data-rte-preserve-empty="true" class="">K12 SIX is pleased to announce that the next edition of the premier event for K-12 cybersecurity practitioners will be held from <strong>February 17-19, 2027 in Atlanta, Georgia</strong>. Mark your calendars and stay tuned for more information on speaker submissions, registration, and sponsorship opportunities. </p><h3 data-rte-preserve-empty="true"><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></h3><p data-rte-preserve-empty="true" class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 4/20/2026 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 4/9/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Thu, 09 Apr 2026 18:38:44 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/20264-9</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:69d7b43905d7b700d16b9206</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3 data-rte-preserve-empty="true"><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="">4/16 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/essentials26">The K12 SIX Essential Cybersecurity Protections: Cyber Defense for Every K-12 Organization</a>” webinar</p></li><li><p data-rte-preserve-empty="true" class="">4/21 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/clever421">Beyond the Breach: Setting a New Security Standard for Vendor Partnerships</a>” webinar (sponsored by Clever)</p></li><li><p data-rte-preserve-empty="true" class="">4/22 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">5/5 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/ms55">Leveraging Defender XDR &amp; Sentinel Automations</a>” webinar (sponsored by Microsoft)</p></li></ul><h3 data-rte-preserve-empty="true"><strong>In the News</strong></h3><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/"><strong>Et tu, Infinite Campus? </strong></a></p><p data-rte-preserve-empty="true" class="">For a sector still reeling from last year’s news about a PowerSchool student information system breach, comes <a target="_blank" href="https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/">a breach notification from another leading provider: Infinite Campus</a>. While some have been quick to compare this most recent incident to PowerSchool’s December 2024 incident, it actually more closely resembles <a target="_blank" href="https://databreaches.net/2025/10/04/powerschool-hit-by-by-salesloft-drift-campaign-but-hackers-claim-that-there-is-no-risk-or-harm-or-ransom/">PowerSchool’s August 2025 incident</a>, which admittedly flew under a lot of people’s radar. Both the Infinite Campus incident and the August PowerSchool incident centered on their use of a third-party application, Salesforce (which is typically used by companies in both the sales and customer support functions). Indeed, <a target="_blank" href="https://www.securityweek.com/hundreds-of-salesforce-customers-allegedly-targeted-in-new-data-theft-campaign/">Salesforce and its customers have been the subject of sustained and targeted attacks over the last two years</a>. The good news: data exfiltrated in these K-12 related incidents <a target="_blank" href="https://databreaches.net/2026/03/28/thankfully-the-infinite-campus-incident-did-not-involve-a-lot-of-non-directory-student-information/">do not contain large amounts of personally identifiable information</a>. The bad news: <a target="_blank" href="https://k12techpro.com/infinite-campus-salesforce-breach-revisit/">more to-do’s for K-12 privacy and security practitioners</a>. In reflecting on the root cause of these incidents, one has to wonder what it will take to ensure that <a target="_blank" href="https://www.sans.org/blog/what-is-phishing-resistant-mfa">phishing-resistant MFA</a> becomes the standard for ‘reasonable’ vendor cybersecurity.</p><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://youtu.be/1A3PYxOuT5E?si=tOIZ9lBXkknbGjSe"><strong>Settle, Settle, Settle</strong></a><strong>*</strong></p><p data-rte-preserve-empty="true" class="">The U.S. is a litigious society, so it was only a matter of time before class action lawsuits - brought about school edtech products, but not by school systems directly - to result in settlements that nonetheless affect schools. In the last week, we’ve seen two such settlements. The first settlement involves <a target="_blank" href="https://www.powerschool.com/solutions/college-career-and-life-readiness/naviance-cclr/">Naviance</a>, the popular college and career planning tool, and the second involves <a target="_blank" href="https://www.linq.com/">LINQ</a>, which is an ERP and school lunch management application. The <a target="_blank" href="https://powerschoolnaviancesettlement.com/">Q.J. v. PowerSchool Holdings LLC, et al. settlement</a> covers students who “logged into the Naviance Platform offered by Hobsons and, later PowerSchool, at least once during the period beginning on August 18, 2021, and continuing through January 23, 2026.” The <a target="_blank" href="https://linqdataincident.com/">Connor Law v. EMS LINQ, LLC. settlement</a> only covers those who were previously sent written notification by LINQ that their personal information “was potentially accessed, viewed, and/or obtained as a result of the Data Security Incident which occurred between September 12, 2023, and May 13, 2024.” (Of note, the instigating LINQ incident does not appear to have been publicly disclosed prior to this settlement.) What do these settlements have in common? Settlement administrators are reaching out to covered parties directly - including students and staff - without any prior to notification to the K-12 organizations that hold the contracts with Naviance and/or LINQ. The result: <a target="_blank" href="https://www.k12dive.com/news/what-the-1725m-naviance-settlement-means-for-school-districts/816496/">tough questions to school districts about their technology vendors</a> (and lawsuits about which they were wholly unaware). One can only hope that class members don’t get too excited about the pennies that may come their way by opting in to these settlements.</p><p data-rte-preserve-empty="true" class=""> * <em>Courtesy of “Liar Liar” (1997), featuring Jim Carrey.</em></p><p data-rte-preserve-empty="true" class=""><strong>A Plea for Responsible Attribution</strong></p><p data-rte-preserve-empty="true" class="">When school systems fall victim to cyber attacks, they would do well not to make public attribution to specific threat actors, including nation states or APTs. Why? First, <a target="_blank" href="https://falconfeeds.io/blogs/the-cyber-forensics-trap-when-attribution-becomes-a-weapon/">attribution is notoriously hard</a> and can <a target="_blank" href="https://www.cybersecuritydive.com/news/cyberattack-attribution-decisions/815587/">invite retaliation and unwanted attention</a>, and - second - spurious claims of attribution (for instance, during a time of heightened geopolitical conflict) can make it more difficult for those on the front lines of critical infrastructure and national security to triage and prioritize their work - especially when those claims may be magnified by the media. After all, who is more likely to be behind a recent denial-of-service attack against a school system? Iranian actors lashing out against U.S. aggression or a bored student seeking to avoid taking this year’s battery of state-mandated achievement tests?  </p><p data-rte-preserve-empty="true" class=""><strong>Save the Date: 2027 K12 SIX Annual Conference </strong></p><p data-rte-preserve-empty="true" class="">K12 SIX is pleased to announce that the next edition of the premier event for K-12 cybersecurity practitioners will be held from <strong>February 17-19, 2027 in Atlanta, Georgia</strong>. Mark your calendars and stay tuned for more information on speaker submissions, registration, and sponsorship opportunities. </p><h3 data-rte-preserve-empty="true"><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></h3><p data-rte-preserve-empty="true" class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 4/9/2026 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 3/23/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Sun, 22 Mar 2026 19:47:38 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2026-3-23</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:69c0475acadc056ef117274e</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3 data-rte-preserve-empty="true"><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p data-rte-preserve-empty="true" class="">3/25 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">4/9 - <a target="_blank" href="https://k12six.cyware.com/webapp/user/events">Monthly Cross-Sector Threat Briefing</a> (member-only)</p></li><li><p data-rte-preserve-empty="true" class="">4/21 - “<a target="_blank" href="https://www.k12six.org/k12six-webinars/clever421">Beyond the Breach: Setting a New Security Standard for Vendor Partnerships</a>” Webinar</p></li></ul><h3 data-rte-preserve-empty="true"><strong>In the News</strong></h3><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://www.edweek.org/technology/a-potential-breach-of-an-anonymous-tip-app-could-have-exposed-sensitive-student-data/2026/03"><strong>Hacktivists Claim Breach of P3 School Security/Anonymous Tip App </strong></a></p><p data-rte-preserve-empty="true" class="">In a story first reported by Mikael Thalen of Straight Arrow News (SAN), <a target="_blank" href="https://san.com/cc/millions-of-anonymous-crime-tips-exposed-in-massive-crime-stoppers-hack-exclusive/">hacktivist(s) apparently stole data from P3 Global Intel, a cloud-based tip and intelligence management platform</a>. Readers unfamiliar with P3 Global Intel may be more familiar with <a target="_blank" href="https://www.p3campus.com/campus/index.htm">P3 Campus</a> (the school-branded version of the platform) or with the parent company, <a target="_blank" href="https://navigate360.com/">Navigate360</a> (which offers a complete suite of integrated school safety solutions). Over 8 million records are claimed to have been exfiltrated, including tip submissions and narratives, two-way chat communications, personal identifiers (names, phone numbers, emails, addresses), and other highly sensitive data (such as Social Security numbers). Thalen writes: “Many school-related messages viewed by SAN involved highly sensitive matters, such as self-harm, suicide and threats of violence.” This one has the potential to be very bad, folks - and offers a cautionary tale about the cybersecurity practices of physical security software and device companies. </p><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://www.claimdepot.com/data-breach/kaplan-2026"><strong>Test-Prep Provider Kaplan Breached</strong></a></p><p data-rte-preserve-empty="true" class="">Three months after unauthorized access was first determined to have occurred, Kaplan is now notifying affected parties of a breach of data that may include some combination of names, social security numbers, driver’s license numbers, and more. While they also serve higher education and business customers, they are well known in K-12 for providing SAT/ACT/AP test preparation services to schools and individual students. The threat actor maintained access to Kaplan’s servers over a 3 week period between Oct 30 and Nov 18, 2025. In their (Maine) notification letter, Kaplan writes: “<a target="_blank" href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/74143000-0a5a-4df2-81c9-5f41ef75619e.html">To help prevent a similar incident from happening again, Kaplan will continue to invest in the security of its computer systems and has implemented additional measures to further enhance the security of the Kaplan IT network</a>.” A fine statement for what it is, but is it enough?</p><p data-rte-preserve-empty="true" class=""><a target="_blank" href="https://www.nbcnews.com/news/us-news/moms-liberty-teachers-unions-schools-tech-screen-time-rcna263931"><strong>Conservative Parents and Teachers Unions Become Unlikely Allies Fighting Tech in Schools</strong></a></p><p data-rte-preserve-empty="true" class="">The critiques of the use and adoption of technology in U.S. K-12 are myriad: consumerism/advertising, inappropriate content, online bullying and harassment, invasive monitoring, anti-intellectual distraction machines, cheating, scams, data breaches, student health/screen time - and that’s just the tip of the iceberg. Some will argue these critiques are about consumer technology or technology used by children and youth outside of school and not tools and devices designed specifically for and used in K-12 settings. Yet, that has long seemed a distinction without a difference, especially because the firewall between consumer/enterprise and education technology in schools is so weak and porous. While there has long been a counter-movement to technology in K-12, it has more recently gained momentum - and brought some unlikely parties together over shared concerns. Where this all goes is unclear (and whether any remedies may be worse than the harm), but it may presage the end of the ‘anything goes’ era of technology use in schools - and that may not be such a bad outcome.</p><h3 data-rte-preserve-empty="true"><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></h3><p data-rte-preserve-empty="true" class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 3/23/2026 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 2/9/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 09 Feb 2026 12:30:01 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2026-2-9</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:6988f29d4317a939c8a19a0c</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">2/12 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">Monthly Cross-Sector Threat Briefing</a> (member-only)</p></li><li><p class="">2/17 - “<a href="https://www.k12six.org/k12six-webinars/microsoft2027" target="_blank">Securing the Future of Education: Updating the Cybersecurity Playbook</a>” webinar (sponsored by Microsoft)</p></li><li><p class="">2/18 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li><li><p class="">2/24 - 2/26 - <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a></p></li></ul><h3><strong>2026 National K-12 Cybersecurity Leadership Conference</strong></h3><p class="">Hosted by the K12 Security Information eXchange (K12 SIX), the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a> is a unique event designed for all K-12 cybersecurity practitioners to identify and share solutions and best practices to better defend school communities from emerging cybersecurity threats, such as ransomware and data breaches. The fourth annual conference will be held <strong>February 24-26</strong> in Albuquerque, New Mexico. <strong><em>Advance registration required.</em></strong></p><ul data-rte-list="default"><li><p class=""><a href="https://www.k12six.org/s/2026-National-K-12-Cybersecurity-Leadership-Conference_2026-2-4.pdf">Preliminary agenda</a>, updated 2/4.</p></li><li><p class="">Featuring: Workshops, Tabletop exercise, Birds of a Feather networking, Peer-led educational sessions, Capture the Flag contest, Exhibit hall</p></li><li><p class="">Learn from experts at the Cybersecurity &amp; Infrastructure Security Agency (CISA/DHS) and U.S. Department of Education/Privacy Technical Assistance Center (PTAC)</p></li><li><p class="">And <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">much more</a></p></li></ul><h3><strong>On the Soapbox</strong></h3><p class=""><a href="https://www.k12dive.com/news/ransomware-attacks-against-education-sector-slow-worldwide/811133/" target="_blank"><strong>Lies, Damned Lies, and K-12 Cybersecurity Statistics</strong></a></p><p class="">While it may defy belief by those not as close to the work, no one has comprehensive, reliable data on cybersecurity incidents at scale, including about those that impact U.S. K-12 organizations. There are several reasons for this:</p><ul data-rte-list="default"><li><p class="">First, let us acknowledge that 1/ incident victims have every incentive to not voluntarily disclose anything and 2/ existing public reporting requirements are variable and quite weak. Absent a national, uniform public reporting requirement for cyber incidents,<em>**</em> no one has a comprehensive dataset upon which to base conclusions. What few reporting requirements exist vary across states by organization type, incident type, and incident severity. Plus, none of the existing requirements include much, if anything, on the subject of public disclosure. Even when invoking freedom of information requests, investigative reporters have been stymied in obtaining incident reports from state entities that are repositories for such data. Others with select insights—such as cybersecurity insurance providers—treat their knowledge as proprietary and a trade secret.</p></li><li><p class="">Second, many cybersecurity incidents do not fit into neat definitions—and organizations routinely apply definitions in different ways. Case in point: a threat actor sends a phishing email to steal credentials from a K-12 administrator that are then used to exfiltrate sensitive data about the school system from the school system’s vendor. The threat actor then extorts the school system, attempting to intimidate the district to pay a ransom demand or risk the abuse of the stolen data. How would one categorize the incident? As social engineering? Yes, but not that alone. As ransomware? A ransom is being sought but no malware was deployed, and access to IT systems remains uninterrupted. Is this even an incident that one would associate with the school system or would the vendor be blamed? Unclear. The categories of incidents used in common parlance simply do not hold up to even cursory scrutiny. Every organization making statistical claims about K-12 cybersecurity applies their own methodology to source and categorize incidents, including—in some cases—by counting claims of cyber criminals as gospel fact.</p></li><li><p class="">Third, cybersecurity industry reports on the ‘education sector’ take a laughably large number and type of organizations and treat them as if they are the same: universities, community colleges and trade schools, school districts (large and small), elite private schools, religious schools, and charter schools; public and private; across states, in the U.S., and abroad. What lessons could U.S. K-12 IT practitioners (or policymakers) take from <a href="https://securityaffairs.com/187702/cyber-crime/italian-university-la-sapienza-still-offline-to-mitigate-recent-cyber-attack.html" target="_blank">a recent attack on an Italian university</a>? They operate under different governance and legal regimes, are resourced differently, use different vendors, and serve a different population. There is precious little actionable for the K-12 practitioner here.</p></li></ul><p class="">Spurious K-12 cybersecurity claims lead under-resourced school systems to purchase solutions mismatched to their needs and spend precious time defending against imaginary threats. They also lead policymakers to the wrong solutions, resulting in waste, fraud, and abuse of government investments. Yet, so long as news stories get clicks and cybersecurity vendors move product, here we’ll remain.</p><p class="">As a reader, hold those making claims to a higher standard and ask them to show their work. Look for information about what types of organizations are included and over what time frame. Look for details about how incidents are sourced, defined, and classified. If a survey was conducted, demand information about the sample and generalizability. Call BS on conference presenters repeating myths about K-12 cybersecurity trends and data—and on reporters who repeat it uncritically and without context. </p><p class=""><em>** While </em><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia" target="_blank"><em>CIRCIA</em></a><em> is an important step forward—and </em><a href="https://www.regulations.gov/comment/CISA-2022-0010-0200" target="_blank"><em>K12 SIX is on record supporting the regulation’s application to the K-12 sector</em></a><em>—it is neither designed nor intended to address the issue of research and reporting in the public domain.</em></p><h3><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 2/9/2026 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 1/26/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 26 Jan 2026 12:30:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2026-1-26</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:697656f42971631502ec1550</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">1/27 - <a href="https://www.k12six.org/k12six-webinars/abnormal26" target="_blank">‘Cybersecurity in the Classroom: From Reactive Recovery to Proactive Prevention’ Webinar</a> (sponsored by <a href="https://abnormal.ai/" target="_blank">Abnormal AI</a>)</p></li></ul><ul data-rte-list="default"><li><p class="">1/28 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li><li><p class="">1/28 -  <a href="https://www.grfbrc.org/orf-exercise-reg" target="_blank">AI Interrupted: A Multi-Sector Tabletop Exercise</a> </p></li></ul><h3><strong>2026 National K-12 Cybersecurity Leadership Conference</strong></h3><p class="">Hosted by the K12 Security Information eXchange (K12 SIX), the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a> is a unique event designed for all K-12 cybersecurity practitioners to identify and share solutions and best practices to better defend school communities from emerging cybersecurity threats, such as ransomware and data breaches. The fourth annual conference will be held <strong>February 24-26</strong> in Albuquerque, New Mexico. <strong><em>Advance registration required.</em></strong></p><ul data-rte-list="default"><li><p class=""><a href="https://www.k12six.org/s/2026-National-K-12-Cybersecurity-Leadership-Conference_-Preliminary-2026-1-11.pdf" target="_blank">Preliminary agenda posted</a> (updated 1/11).</p></li><li><p class="">Featuring: Workshops, Tabletop exercise, Birds of a Feather networking, Peer-led educational sessions, Capture the Flag contest, Exhibit hall</p></li><li><p class="">Learn from experts at the Cybersecurity &amp; Infrastructure Security Agency (CISA/DHS) and U.S. Department of Education/Privacy Technical Assistance Center (PTAC)</p></li><li><p class="">And <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">much more</a></p></li></ul><h3><strong>In the News</strong></h3><p class=""><a href="https://www.mypanhandle.com/news/florida/florida-man-arrested-for-251k-louisiana-school-fraud/" target="_blank"><strong> Florida Man Arrested for Defrauding Louisiana School District, Stealing $251k</strong></a></p><p class="">Agents with the Louisiana Bureau of Investigation recently arrested a 58-year-old man from Florida for taking part in a November 2024 scheme to defraud the Sabine Parish School Board (LA) out of more than $250,000. As part of the scheme, a school board employee was persuaded to, unwittingly, send an ACH payment in the amount of $251,972.00 to an out of state bank account controlled by the perpetrator(s). This payment was made to a vendor, believed to be legitimate, for the purchase of metal detectors intended to be placed at Sabine Parish school campuses. <a href="https://www.ag.state.la.us/Article/411" target="_blank">The investigation is ongoing</a>.</p><p class=""><a href="https://www.nj.com/education/2026/01/nj-school-district-says-178k-in-taxpayer-money-vanished-in-email-scam.html" target="_blank"><strong>NJ School District Sends $178K in Payments for School Construction Project to Cyber Criminals Instead</strong></a></p><p class="">Nearly $178,000 in payments made by Princeton Public Schools (NJ) to a vendor working on a construction project appear to have been lost in a wire fraud scam. District officials said they alerted authorities last month after they were told three payments sent to a vendor 15 months earlier were never received. <a href="https://nj1015.com/wire-fraud-princeton-schools/" target="_blank">Although the incident occurred in September 2024, school board members did not learn about the missing funds until roughly 15 months later, in early December 2025</a>. While the School Board president asserted that the vendor, not the district is ultimately liable for the loss in a recent public meeting, time will tell how it gets sorted out. </p><p class=""><a href="https://techcrunch.com/2026/01/20/ustrive-security-lapse-exposed-personal-data-of-its-users-including-children/" target="_blank"><strong>Security Lapse at Online Mentoring Company Exposed Student Data</strong></a></p><p class="">Online mentoring site <a href="https://ustrive.org/" target="_blank">UStrive</a> has resolved a vulnerability that exposed the personal information of its users, including students. The exposed data included the full names, email addresses, phone numbers, and other non-public and user-provided information of UStrive users, which was accessible to any other logged-in user. According to reporting by TechCrunch, a vulnerable GraphQL endpoint — a type of query database interface — allowed access to reams of user data stored on UStrive’s servers. While UStrive claims “1.1 million students have opted in for a UStrive mentor,” only 238,000 user records were observed at the time of discovery. </p><h3><span class="sqsrte-text-color--accent"><strong>Members Get More</strong></span></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 1/26/2026 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 1/12/2026 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 12 Jan 2026 12:29:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2026-1-12</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:6963dc4014ae7d00859f9c41</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><p class="">~~ Happy new year! ~~</p><ul data-rte-list="default"><li><p class="">1/27 - <a href="https://www.k12six.org/k12six-webinars/abnormal26" target="_blank">‘Cybersecurity in the Classroom: From Reactive Recovery to Proactive Prevention’ Webinar</a> (sponsored by <a href="https://abnormal.ai/" target="_blank">Abnormal AI</a>)</p></li><li><p class="">1/28 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li></ul><h3><strong>2026 National K-12 Cybersecurity Leadership Conference</strong></h3><p class="">Hosted by the K12 Security Information eXchange (K12 SIX), the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a> is a unique event designed for all K-12 cybersecurity practitioners to identify and share solutions and best practices to better defend school communities from emerging cybersecurity threats, such as ransomware and data breaches. The fourth annual conference will be held February 24-26 in Albuquerque, New Mexico. Named a “<a href="https://www.k12dive.com/news/top-k12-events-2026/761523/" target="_blank">top K-12 conference to attend in 2026</a>” by K-12 Dive. <strong><em>Advance registration required; conference room block selling out fast.</em></strong></p><ul data-rte-list="default"><li><p class=""><a href="https://www.k12six.org/s/2026-National-K-12-Cybersecurity-Leadership-Conference_-Preliminary-2026-1-11.pdf" target="_blank">Preliminary agenda posted</a> (updated 1/11).</p></li><li><p class="">Featuring: Workshops, Tabletop exercise, Birds of a Feather networking, Peer-led educational sessions, Exhibit hall</p></li><li><p class="">Learn from experts at the Cybersecurity &amp; Infrastructure Security Agency (CISA/DHS) and U.S. Department of Education/Privacy Technical Assistance Center (PTAC)</p></li><li><p class="">And <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">much more</a></p></li></ul><h3><strong>In the News</strong></h3><p class=""><a href="https://www.republicanherald.com/2025/12/24/minersville-schools-reopen-as-district-investigates-ransomware-attack/" target="_blank"><strong>PA School District Suffers Holiday Cyber Attack, School Closures: “We hope to start 2026 more positively”</strong></a></p><p class="">On December 15, 2025, Minersville Area School District (PA) was victimized by a cyber attack. Upon discovery of the incident, which included attempts to install malware on school system devices, the district shut down all IT systems - resulting in <a href="https://www.republicanherald.com/2025/12/24/minersville-schools-reopen-as-district-investigates-ransomware-attack/" target="_blank">a four day school closure</a> right before the holiday break. According to the Superintendent, schools were closed not only because instruction would have been affected by the loss of technology, but because the district’s computer system and the internet are also crucial to running security and communications in the buildings. In <a href="https://resources.finalsite.net/images/v1766182470/battlinminerscom/vtjg8pw6wkxip05shs2n/WebsiteNoticeMinersville19Dec2025.pdf" target="_blank">a communication to the school community</a>, the district acknowledges the possibility of a data breach and the wisdom of <a href="https://www.usa.gov/credit-freeze" target="_blank">implementing a credit freeze at each of the three major credit reporting bureaus</a>. </p><p class=""><a href="https://www.wbrc.com/2026/01/07/pell-city-school-system-data-breached-by-cyber-attack/" target="_blank"><strong>AL School District Notifies Parents of Holiday Cyber Attack, Data Breach</strong></a></p><p class="">Also victimized this holiday season, Pell City (AL) School System reported a recent ‘security incident’ to school community members. The Superintendent said that while the student information system did not appear to be affected, some data had been exfiltrated from district servers. Comparitech notes that <a href="https://www.comparitech.com/news/alabama-school-district-warns-parents-of-data-breach-claimed-by-ransomware-gang/" target="_blank">the cyber criminal group SafePay</a> did take credit for the December 2025 incident on their dark web leak site. <em>NOTE: K12 SIX analyses identify SafePay as being the most prolific in targeting the U.S. K-12 education sector during the 2025 calendar year. For more on SafePay, see “</em><a href="https://www.infosecurity-magazine.com/news-features/unmasking-safepay-ransomware-group/" target="_blank"><em>Unmasking the SafePay Ransomware Group</em></a><a href="https://Unmasking the SafePay Ransomware Group" target="_blank"><em>.</em></a><em>”</em></p><p class=""><a href="https://wcyb.com/news/local/fbi-helps-washington-county-tenn-schools-recover-more-than-300k-after-phishing-scheme" target="_blank"><strong>FBI Recovers More than $300k Scammed from TN School System</strong></a></p><p class="">About a year ago, Washington County (TN) Public Schools staff were tricked into sending a wire transfer of $335,215 to cyber criminals instead of the company the district had hired to undertake $1.5 million in security system renovations. Within three days, the error was discovered and officials were notified - and that made all the difference. A recently released financial audit (November 2025) classified the incident as a material weakness in internal controls, noting that existing policy lacked guidance to verify payment method changes and wire transfers before processing disbursements. Going forward, verbal confirmation of any bank routing changes will be made using verified vendor telephone numbers. <em>Readers would do well to note that </em><span><em>these type of phishing scams targeting K-12 accounts payable staff are common</em></span><em> and have resulted in some of the largest direct financial losses attributable to cyber crime that school systems have experienced.</em></p><h3><strong>Members Get More</strong></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 1/12/2026 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 12/15/2025 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 15 Dec 2025 12:30:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2025-12-15</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:693f1f02234f14788be7362e</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">12/17 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">K12 SIX Monthly Membership Meeting</a> (member-only)</p><p class="">~~ Happy holidays! ~~</p></li></ul><p class=""><a href="https://www.nbcchicago.com/news/local/north-suburban-elementary-school-closed-for-days-due-to-cyber-security-incident/3858233/" target="_blank"><strong>IL School District Closed for Three Days Due to Cybersecurity Incident</strong></a></p><p class="">On Sunday, November 30, 2025, Zion Elementary School District 6 (IL) was impacted by a cybersecurity incident that resulted in the suspension of teaching and learning - and extracurriculars - for three days the following week. Students and teachers were welcomed back from Thanksgiving on Thursday, December 4. On its website, district leadership sought to reassure its community that the privacy and security of its students and staff remains their highest priority: “<a href="https://www.zion6.org/district/departments/communications/alert-tracker" target="_blank">ZESD 6 has multiple safeguards in place to prevent cyberattacks on district systems, including usernames, passwords, and multi-factor authentication (MFA)</a>.”</p><p class=""><a href="https://www.ftc.gov/news-events/news/press-releases/2025/12/ftc-takes-action-against-education-technology-provider-failing-secure-students-personal-data" target="_blank"><strong>FTC Takes Action Against Illuminate (Renaissance) for Negligent Cybersecurity Practices</strong></a></p><p class="">Before the PowerSchool incident, there was <a href="https://thejournal.com/articles/2022/05/15/list-of-all-schools-confirmed-impacted-by-illuminate-education-data-breach.aspx" target="_blank">Illuminate’s</a>. Following on the heels of a joint settlement with three different state attorneys general (<a href="https://oag.ca.gov/news/press-releases/attorney-general-bonta-joins-states-securing-51-million-settlements-education" target="_blank">CA</a>, <a href="https://portal.ct.gov/ag/press-releases/2025-press-releases/attorney-general-tong-enters-into-settlement-in-first-action-under-student-data-privacy-law" target="_blank">CT</a>, and <a href="https://ag.ny.gov/press-release/2025/attorney-general-james-and-multistate-coalition-secure-51-million-education" target="_blank">NY</a>), the federal government is now seeking to levy additional penalties against the firm, which was <a href="https://www.edsurge.com/news/2022-08-29-after-recent-high-profile-data-breaches-illuminate-education-quietly-gets-acquired" target="_blank">acquired by Renaissance</a> on the heels of the incident. The <a href="https://www.ftc.gov/system/files/ftc_gov/pdf/2223105illuminatecomplaint.pdf" target="_blank">FTC complaint</a> details facts about the cyber incident that heretofore had not been public knowledge. For instance, the threat actor compromised still-active credentials held by an IT administrator who had left the company over three years prior. After nearly two weeks of unfettered access to Illuminate systems, the threat actor also extorted the company to prevent the release of the data they had exfiltrated and - like PowerSchool - the company paid the threat actor to delete the data. The FTC complaint is worth the read as it does a good job of debunking the company’s public claims about its privacy and security practices vs reality. Remember folks: trust <em>and</em> verify. Both steps are necessary, especially for your critical vendors.</p><p class=""><a href="https://www.nbcnews.com/tech/tech-news/ai-toys-gift-present-safe-kids-robot-child-miko-grok-alilo-miiloo-rcna246956" target="_blank"><strong>Friends Don’t Let Friends Buy AI Toys for the Holidays</strong></a></p><p class="">In news that really shouldn’t be a surprise to any of us following this more closely, it turns out that integrating AI chatbots into children’s toys is a recipe for…raised eyebrows, if not a lot more. Interested in digging deeper? Read the full report from U.S. PIRG <a href="https://pirg.org/edfund/resources/ai-toys/" target="_blank">here</a>.</p><p class=""><a href="https://www.k12six.org/2026-k12six-conference"><strong>4th Annual National K-12 Cybersecurity Leadership Conference (Feb 2026)</strong></a></p><p class="">Hosted by the K12 Security Information eXchange (K12 SIX), the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a> is a unique event designed to identify and share solutions and best practices to better defend the K-12 education sector from emerging cybersecurity threats, such as ransomware and data breaches. The fourth annual conference will be held February 24-26, 2026 in Albuquerque, New Mexico. Named a “<a href="https://www.k12dive.com/news/top-k12-events-2026/761523/" target="_blank">top K-12 conference to attend in 2026</a>” by K-12 Dive.</p><h3><strong>Members Get More</strong></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 12/15/2025 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 12/1/2025 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 01 Dec 2025 12:30:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2025-12-1</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:692c6e23c6f971644a878d8e</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">12/9 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">AI Cyber Espionage Campaign Briefing - featuring CISO, Anthropic</a> (member-only) </p></li><li><p class="">12/11 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">Monthly Cross-Sector Threat Briefing</a> (member-only)</p></li><li><p class="">12/17 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li></ul><h3><strong>In the News</strong></h3><p class=""><a href="https://www.charlotteobserver.com/news/state/north-carolina/article313125049.html" target="_blank"><strong>Pre-Thanksgiving Cyber Incident Closes NC School District </strong></a></p><p class="">Attacked over the weekend prior to Thanksgiving, Jackson County (NC) Public Schools closed their district for holiday break early to facilitate remediation and recovery. In so doing, IT staff cancelled vacations and worked overtime to shut down their entire network, including internet, Wi-Fi, phones, camera/door access systems, and all other network services.  While the incident was more severe than originally believed, at this time district officials do not believe any sensitive data is at risk. Rather, <a href="https://wlos.com/news/local/no-data-breach-detected-accessed-district-technology-system-cyberattack-forced-jackson-county-public-schools-close-tuesday-november-25-weekend-it-team-network-errors" target="_blank">they believe they were affected by a DDoS attack</a> - for which they were not even the intended target. </p><p class=""><a href="https://www.k12dive.com/news/powerschool-hacker-sentencing-lessons-learned-data-breach/803053/" target="_blank"><strong>US Policy Response to K-12 Cyber Incidents Lagging </strong></a></p><p class="">While <a href="https://www.linkedin.com/posts/douglaslevin_gta-school-boards-did-not-have-reasonable-activity-7397313822493024256-_hDJ?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAAZPKoBafm7-InJHSg6yNJntK99II1XwPk" target="_blank">some K-12 edtech experts are downright pessimistic</a> about the lessons we’ve learned and changes we’ve implemented to shore up K-12 cybersecurity post-PowerSchool cyber incident, strikingly our neighbors to the north are taking a different approach. Case in point: a blog post entitled “<a href="https://www.ipc.on.ca/en/media-centre/blog/use-edtech-schools-children-should-not-have-swap-their-privacy-education" target="_blank">Use of edtech in schools: Children should not have to swap their privacy for an education</a>” by Patricia Kosseim, Information and Privacy Commissioner of Ontario, which details several streams of work happening in Canada. For K-12 cybersecurity advocates, there is much to like in her description of actions and recommendations. Meanwhile, in the US, what focus there is remains on <a href="https://www.hbsslaw.com/cases/powerschool-data-breach" target="_blank">penalizing PowerSchool</a> for yesterday’s behavior instead of <em>taking the steps necessary to preventing future incidents</em>. Make it make sense. </p><p class=""><a href="https://www.hacklore.org/" target="_blank"><strong>Hacking + Folklore = Hacklore (and it’s not good, folks)</strong></a></p><p class="">Don’t believe everything you read. Turns out that <a href="https://www.theregister.com/2025/11/24/hacklore_launch/" target="_blank">a lot of cybersecurity advice being peddled to everyday users is actually…wrong</a>. Bob Lord, who may be remembered for his time at CISA spearheading their Secure by Design initiative (alongside Lauren Zabierek and Jack Cable), is the force behind a new site, entitled ‘Stop Hacklore!’ Importantly, the site not only debunks unhelpful security advice but calls out specific security practices that actually work, like installing security patches, MFA, long passphrases, and password managers. Don’t trust, Bob? Nearly a hundred other prominent CISOs have endorsed the effort so far. </p><p class=""><a href="https://www.k12six.org/2026-k12six-conference"><strong>4th Annual National K-12 Cybersecurity Leadership Conference (Feb 2026)</strong></a></p><p class="">Hosted by the K12 Security Information eXchange (K12 SIX), the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a> is a unique event designed to identify and share solutions and best practices to better defend the K-12 education sector from emerging cybersecurity threats, such as ransomware and data breaches. The fourth annual conference will be held February 24-26, 2026 in Albuquerque, New Mexico. Named a “<a href="https://www.k12dive.com/news/top-k12-events-2026/761523/" target="_blank">top K-12 conference to attend in 2026</a>” by K-12 Dive.</p><h3><strong>Members Get More</strong></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 12/1/2025 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 11/17/2025 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 17 Nov 2025 12:30:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2025-11-17</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:691a50e09baaf129b6d7666d</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">11/18 - <a href="https://www.k12six.org/k12six-webinars/infosec1118">From ABC to PhD: Building K-12 Cyber Defense from Kindergarten to Staff Room</a> (sponsored by Infosec Institute)</p></li><li><p class="">11/19 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li></ul><h3><strong>In the News</strong></h3><p class=""><a href="https://www.fox5dc.com/news/manassas-city-schools-closed-after-cybersecurity-incident-set-reopen-wednesday" target="_blank"><strong>VA School District Recovering from Cyber Incident that Forced Districtwide Closures</strong></a></p><p class="">Manassas City (VA) Public Schools <a href="https://www.facebook.com/manassascitypublicschools/posts/pfbid0pBvXKfjA3fAU15PmZXpvPGbGezW4bgUid1pnvwgQ1iYY2sqfbcuYq8v7dmH5QwVxl" target="_blank">continue their efforts</a> to recover from a significant cyber incident experienced on or about November 9 that disrupted internet and phone service and led to school closures across the district. (The proximity of the incident to a national holiday may have helped avoid even greater disruption.) Phone service was interrupted for about 5 days while ‘some technology tools’ may still remain offline as recovery efforts continue. The threat actor has not been publicly identified, nor has there been a confirmation of an extortion demand. </p><p class=""><a href="https://greenbushk12tech.blogspot.com/2025/11/why-securing-things-backwards-is-so.html" target="_blank"><strong>Implementing a Comprehensive K-12 Cybersecurity Cybersecurity Program: Building the Plane While Flying It</strong></a></p><p class="">In a blog post entitled “Why Securing Things ‘Backwards’ Is So Difficult in K–12 IT,” Brad Cornell drops some wisdom on the challenges of trying to overhaul a school system’s cybersecurity posture without disrupting learning (too much). As he writes: “<em>Transitioning from ‘anything goes’ to ‘secured by design’ is one of the hardest shifts for schools to make. Not because people don’t care about security, but because securing things backwards means undoing years of habits, expectations, and legacy decisions</em>.” The post concludes with some good tips on tactics that can help pave the path toward greater buy-in and ultimately resilience.</p><p class=""><a href="https://meritalk.com/articles/cyber-grant-program-gets-short-term-extension-after-shutdown/" target="_blank"><strong>Good News, Bad News: SLCGP Reauthorized in Government Funding Deal </strong></a></p><p class="">Good news: the end of the longest federal government shutdown in history late Wednesday night also reauthorized a popular federal cybersecurity grant program for state and local governments: the State and Local Cybersecurity Grant Program (SLCGP). The bad news: the reauthorization only extends the program until January 30. What the program looks like the future - including funding levels - all remains open for debate. <a href="https://www.nascio.org/press-releases/nascio-statement-on-inclusion-of-cyber-legislation-in-shutdown-agreement/" target="_blank">The National Association of State Chief Information Officers (NASCIO) response</a>: “<em>Congress should act swiftly to provide certainty and stability for state governments by passing a long-term extension…, combined with adequate levels of funding, that will allow stakeholders to strengthen their cyber defenses and meet the challenges of the future.</em>”</p><p class=""><a href="https://www.k12six.org/2026-k12six-conference"><strong>4th Annual National K-12 Cybersecurity Leadership Conference (Feb 2026)</strong></a></p><p class="">Hosted by the K12 Security Information eXchange (K12 SIX), the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a> is a unique event designed to identify and share solutions and best practices to better defend the K-12 education sector from emerging cybersecurity threats, such as ransomware and data breaches. The fourth annual conference will be held February 24-26, 2026 in Albuquerque, New Mexico. Named a “<a href="https://www.k12dive.com/news/top-k12-events-2026/761523/" target="_blank">top K-12 conference to attend in 2026</a>” by K-12 Dive.</p><h3><strong>Members Get More</strong></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 11/17/2025 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 11/3/2025 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 03 Nov 2025 12:30:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2025-11-3</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:6907b98c35c12805638540c7</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">11/3-5 - <a href="https://www.grf.org/summit2025" target="_blank">Cross-Sector Summit on Security &amp; Third-Party Risk</a></p></li><li><p class="">11/13 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">Monthly Cross-Sector Threat Briefing</a> (member-only)</p></li><li><p class="">11/18 - <a href="https://www.k12six.org/k12six-webinars/infosec1118" target="_blank">From ABC to PhD: Building K-12 Cyber Defense from Kindergarten to Staff Room</a> (sponsored by Infosec Institute)</p></li><li><p class="">11/19 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">K12 SIX Monthly Membership Meeting</a> (member-only)</p></li></ul><h3><strong>In the News</strong></h3><p class=""><a href="https://www.fitsnews.com/2025/10/24/cyberattack-fallout-lawsuit-targets-south-carolina-school-district/" target="_blank"><strong>Cyberattack Fallout: Lawsuit Targets South Carolina School District</strong></a></p><p class="">A former employee and parent of students attending the Lexington-Richland School District Five (SC) has retained a California-based data-privacy law firm to file a class-action lawsuit against the district, alleging the district failed to protect sensitive student and employee data during a <a href="https://www.lexrich5.org/resources/data-security-incident-information" target="_blank">June 2025 ransomware attack</a> that compromised the personal information of thousands of individuals. Investigators determined that the breach exposed personally identifiable information – including names, birthdates, employee and student records, Social Security numbers and internal financial files – impacting more than 31,000 students, parents, alumni and staff. Add this to growing list of cybersecurity-related legal cases being brought by employees, parents, and students against K-12 school systems around the country - for better and worse. </p><p class=""><a href="https://www.grandforksherald.com/news/no-updates-on-the-840-000-lost-by-the-grand-forks-school-district-after-a-phishing-scam-last-year" target="_blank"><strong>ND School System Writes Off $840,000 Loss from 2024 Phishing Scam</strong></a></p><p class="">Despite a still ongoing investigation, the Grand Forks Public Schools officially recorded the missing funds as a loss when books were closed in June. On Sept. 13, 2024, <a href="https://www.govtech.com/education/k-12/grand-forks-public-schools-loses-2-2m-to-phishing-scam" target="_blank">the district first disclosed it lost $2.2 million</a> in what was later revealed to be a phishing scam. Five months later, the school board was informed that <a href="https://www.govtech.com/education/k-12/grand-forks-schools-recovered-half-of-loss-to-phishing-scam" target="_blank">authorities were able to recover $1,296,935 of the stolen funds</a>. That coupled with a $100,000 payout from their insurance company reduced the total loss to $842,730. Reflecting on the incident, a district official remarked: “It’s not a matter of if it happens, it's a matter of when. You can't write off and say ‘those are the types of problems that are for big organizations.’ I think it's only a matter of time – we all are targeted individuals alike. And I think that the greatest single safeguard, in so many ways, is to slow down, be thoughtful, be very careful.”</p><p class=""><a href="https://socket.dev/blog/security-community-slams-mit-linked-report-claiming-ai-powers-80-of-ransomware" target="_blank"><strong>No, AI Does Not Power 80% of Ransomware</strong></a></p><p class="">The security community is debating new claims from MIT Sloan researchers and Safe Security this week, after a jointly authored paper asserted that 80 percent of ransomware attacks are AI-driven. The MIT paper isn’t an isolated case of fictional narratives about artificial intelligence, though. Similar claims are appearing across the security industry, often tied to surveys or marketing campaigns rather than incident data. For a more evidence-based look at AI use by threat actors, the European Union Agency for Cybersecurity (ENISA) may <a href="https://www.enisa.europa.eu/sites/default/files/2025-10/ENISA%20Threat%20Landscape%202025_0.pdf" target="_blank">be the best current source</a>. Here’s to more facts and less FUD in cybersecurity marketing.</p><p class=""><a href="https://www.k12six.org/2026-k12six-conference"><strong>4th Annual National K-12 Cybersecurity Leadership Conference (Feb 2026)</strong></a></p><p class="">Hosted by the K12 Security Information eXchange (K12 SIX), the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a> is a unique event designed to identify and share solutions and best practices to better defend the K-12 education sector from emerging cybersecurity threats, such as ransomware and data breaches. The fourth annual conference will be held February 24-26, 2026 in Albuquerque, New Mexico. Named a “<a href="https://www.k12dive.com/news/top-k12-events-2026/761523/" target="_blank">top K-12 conference to attend in 2026</a>” by K-12 Dive.</p><h3><strong>Members Get More</strong></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 11/3/2025 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 10/20/2025 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 20 Oct 2025 19:30:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2025-10-20</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:68f6737a3118197cce0399f7</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">10/21 - <a href="https://www.k12six.org/k12six-webinars/jamf1021" target="_blank">Pressure Building: Why All Districts Need a Solid Foundational Cybersecurity Program</a> (sponsored by Identity Automation, a Jamf company)</p></li><li><p class="">10/22 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">K12 SIX Monthly Membership Meeting</a> (members-only)</p></li><li><p class="">10/28 - <a href="https://www.k12six.org/k12six-webinars/clever1028" target="_blank">Passwords Must Go: The Future of Authentication in K-12</a> (sponsored by Clever)</p></li><li><p class="">10/31 - Deadline for submission of <a href="https://www.k12six.org/2026-call-for-speakers" target="_blank">speaking proposals</a> - and Early Bird Registration - for the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a></p></li></ul><h3><strong>In the News</strong></h3><p class=""><a href="https://www.k12dive.com/news/powerschool-hacker-sentencing-lessons-learned-data-breach/803053/" target="_blank"><strong>Lessons Learned from the PowerSchool Incident</strong></a></p><p class="">After pleading guilty to hacking and extorting from ed tech giant PowerSchool, 19-year-old Matthew Lane was recently sentenced to four years in prison and nearly $14.1 million in restitution.  Although Lane has been held accountable for the PowerSchool cyberattack and sentenced to prison, “the damage is done” from the leak of the school districts’ sensitive data, Doug Levin, K12 SIX Director said. “There’s no putting the genie back in the bottle.” K-12 cybersecurity remains “an ongoing problem,” and cyberattacks against schools won’t stop just because someone was held accountable for the PowerSchool incident, Levin said. </p><p class=""><a href="https://www.hstoday.us/subject-matter-areas/cybersecurity/around-1-million-stolen-from-new-yorks-voorheesville-central-school-district-in-cyber-fraud-incident/" target="_blank"><strong>Yet Another $1M+ Victim of a BEC Attack Targeting a School Construction Project</strong></a></p><p class="">This one victimizing a <a href="https://www.timesunion.com/education/article/cyber-criminals-steal-1-million-voorheesville-21104937.php" target="_blank">New York school system</a>. The frustration: this is a well-established tactic with a long history of claiming U.S. school district victims. Case in point: Here is K12 SIX Director Doug Levin expressing <a href="https://www.k12dive.com/news/texas-district-loses-23m-to-phishing-scam/570373/" target="_blank">these same thoughts</a> in a story about another victim in - wait for it - January of 2020. We know how to prevent these attacks, but it requires cooperation of school system finance/accounts payable offices, strong policies for verification of ACH account routing change requests, and a no-exceptions adherence to that policy. </p><p class=""><a href="https://www.johnsoncitypress.com/news/state-audit-finds-fault-in-education-dept-data-protections/article_0a568ea8-8c16-4ad1-966c-165100a1b5b1.html" target="_blank"><strong>Audit: TN Department of Education Lacks Critical Controls Over Statewide Information Systems</strong></a></p><p class="">In an <a href="https://comptroller.tn.gov/content/dam/cot/sa/advanced-search/2025/pa25005.pdf" target="_blank">audit</a> conducted by Tennessee Comptroller of the Treasury/Division of State Audit and published earlier this month, the Department of Education was found to lack sufficient controls for managing information systems responsible for the oversight of “billions of dollars in state and federal funds.” These information systems are integral to managing student data, allocating education funding, licensing educators, administering assessments, and supporting statewide planning and reporting. While the specific nature of the audit finding was redacted due to the sensitivity of the concern, the Department concurred with the finding: “We concur. The Department recognizes and understands the criticality of ensuring adherence to the general controls over the information systems….The Department is taking all steps to ensure the ongoing security of data and all associated systems.”</p><p class=""><a href="https://www.k12six.org/2026-k12six-conference"><strong>4th Annual National K-12 Cybersecurity Leadership Conference (Feb 2026): Call for Speakers, Early Bird Registration Closes 10/31&nbsp;</strong></a></p><p class="">The National K-12 Cybersecurity Leadership Conference is a unique event designed to identify and share solutions and best practices to better defend the K-12 education sector from emerging cybersecurity threats, such as ransomware and data breaches. Participants from past conferences report overwhelmingly positive feedback about the conference: “I just wanted to reach out to say thank you again for an amazing conference. My team and I all agreed that was by far one of our best conferences any of us have ever attended.” <a href="https://www.k12six.org/2026-k12six-conference">The 4th Annual conference will be held February 24-26, 2026 in Albuquerque, NM</a>.</p><h3><strong>Members Get More</strong></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 10/20/2025 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 9/29/2025 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 29 Sep 2025 11:30:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2025-9-29</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:68d2e6ef59ed514dd79e35fb</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">10/7 - <a href="https://www.k12six.org/k12six-webinars/gtkk12six25" target="_blank">Get to Know K12 SIX: Core Benefits of Membership</a></p></li><li><p class="">10/9 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">Monthly Cross-Sector Threat Briefing</a> (member-only)</p></li><li><p class="">10/14 - <a href="https://www.k12six.org/k12six-webinars/fortinet1025" target="_blank">Cybersecurity Education for K-12: Putting CISA’s Guidance into Action</a> (sponsored by Fortinet)</p></li><li><p class="">10/21 - <a href="https://www.k12six.org/k12six-webinars/jamf1021" target="_blank">Pressure Building: Why All Districts Need a Solid Foundational Cybersecurity Program</a> (sponsored by Identity Automation, a Jamf company)</p></li><li><p class="">10/28 - <a href="https://www.k12six.org/k12six-webinars/clever1028" target="_blank">Passwords Must Go: The Future of Authentication in K-12</a> (sponsored by Clever)</p></li><li><p class="">10/31 - Deadline for submission of <a href="https://www.k12six.org/2026-call-for-speakers" target="_blank">speaking proposals</a> for the <a href="https://www.k12six.org/2026-k12six-conference" target="_blank">2026 National K-12 Cybersecurity Leadership Conference</a></p></li></ul><h3><strong>In the News</strong></h3><p class=""><a href="https://www.tpr.org/education/2025-09-14/cyberattack-prompts-closure-of-uvalde-schools" target="_blank"><strong>Insult to Injury: Cyberattack prompts closure of Uvalde (TX) schools</strong></a></p><p class="">The Uvalde Consolidated Independent School District - yes, that <a href="https://en.wikipedia.org/wiki/Uvalde_school_shooting" target="_blank">Uvalde </a>- had to close their school system for a week while responding to a significant ransomware incident experienced on September 13. District officials notified teachers and students that due to the attack, essential systems will be unavailable, including phones, thermostats, camera monitoring and other systems deemed necessary. The attack also took out the district’s payroll system, affecting bus drivers, maintenance staff and custodians. Officials said paychecks could possibly be delayed. District officials claim to have found <a href="https://foxsanantonio.com/newsletter-daily/no-data-breached-in-uvalde-cisd-attack-according-to-district-ransomware-robb-elementary-local-education" target="_blank">no evidence of unauthorized access to sensitive data</a>, but time will tell.</p><p class=""><a href="https://www.bbc.com/news/articles/c62ldyvpwv9o" target="_blank"><strong>“An Absolute New Low” - Extorting Nursery School Parents in the UK</strong></a></p><p class="">Hackers say they have stolen the pictures, names and addresses of around 8,000 children from the Kido nursery chain. The gang of cyber criminals is using the highly sensitive information to demand a ransom from the company, which has 18 sites in and around London, with more in the US and India. The criminals also claim to have contacted some parents by phone as part of their extortion tactics.</p>


  










  


  
    <iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen src="https://www.youtube-nocookie.com/embed/7Q9SHh4-4r8?si=StAHL3bdJPlq9-12" width="560" frameborder="0" title="YouTube video player" height="315"></iframe>
  
  








  
    
  
  <p class=""><a href="https://www.ksl.com/article/51380881/audit-utahs-k-12-and-higher-education-systems-could-improve-cybersecurity-practices" target="_blank"><strong>Audit: Utah's K-12 systems could improve cybersecurity practices</strong></a></p><p class="">Utah’s local education agencies (LEAs) are not fully implementing baseline cybersecurity practices, leaving school systems vulnerable. Recent attacks in Utah exposed data from hundreds of thousands of students and employees and cost districts over $150,000. Testing and statewide surveys found significant gaps in incident response planning, training, and patch management, with smaller districts lagging furthest behind. Barriers such as insufficient staffing, limited resources, and lack of prioritization continue to hinder progress. Among the recommendations to the Utah legislature: minimum cybersecurity standards for local education agencies. Direct link to the audit report <a href="https://le.utah.gov/interim/2025/pdf/00003683.pdf" target="_blank">here</a>.</p><p class=""><a href="https://www.k12six.org/news/2025ocam"><strong>K12 SIX Announces Expert-Led Webinar Series for 2025 Cybersecurity Awareness Month</strong></a></p><p class="">This October, in recognition of Cybersecurity Awareness Month, K12 SIX presents a series of weekly webinars designed to help schools strengthen their defenses against modern cyber threats. This series features the voices of industry experts and K-12 practitioners, collaborating to offer school technology leaders and administrators actionable strategies and essential guidance. Our goal is to empower school communities with the knowledge and tools needed to build a resilient and secure digital environment.</p><p class=""><a href="https://www.k12six.org/news/call-for-speakers-registration-opens-for-4th-annual-national-k-12-cybersecurity-leadership-conference-5k5a4"><strong>4th Annual National K-12 Cybersecurity Leadership Conference (Feb 2026): Call for Speakers, Registration Open</strong></a></p><p class="">The National K-12 Cybersecurity Leadership Conference is a unique event designed to identify and share solutions and best practices to better defend the K-12 education sector from emerging cybersecurity threats, such as ransomware and data breaches. Participants from past conferences report overwhelmingly positive feedback about the conference: “I just wanted to reach out to say thank you again for an amazing conference. My team and I all agreed that was by far one of our best conferences any of us have ever attended.” <a href="https://www.k12six.org/2026-k12six-conference">The 4th Annual conference will be held February 24-26, 2026 in Albuquerque, NM</a>.</p><h3><strong>Fast Facts</strong></h3><ul data-rte-list="default"><li><p class=""><span data-text-attribute-id="127015a6-5815-4966-be63-49720490921f" class="sqsrte-text-highlight"><strong>52</strong></span>: U.S. K-12 ransomware victims claimed by threat actors (2025 to date) (<a href="https://k12six.cyware.com/webapp/user/myfeeds/680b9516" target="_blank">source</a>)</p></li><li><p class=""><span data-text-attribute-id="37b31e14-5bb6-42d1-8ff8-1aabdc792ae3" class="sqsrte-text-highlight"><strong>72</strong></span>: Severe information technology vulnerabilities (<a href="https://www.first.org/cvss/v3-1/specification-document" target="_blank">CVSS</a> Base Score 7.0+) disclosed in past week (<a href="https://k12six.cyware.com/webapp/user/myfeeds/e7429673" target="_blank">source</a>)</p></li></ul><h3><strong>Members Get More</strong></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 9/29/2025 edition</media:title></media:content></item><item><title>K-12 Cybersecurity Insider | 9/8/2025 edition</title><category>Newsletter</category><dc:creator>Doug Levin</dc:creator><pubDate>Mon, 08 Sep 2025 11:30:00 +0000</pubDate><link>https://www.k12six.org/k12-cybersecurity-insider/2025-9-8</link><guid isPermaLink="false">5e441b46adfb340b05008fe7:68518b2d974b160cfa04dd51:68bdc7da26ad71491135db74</guid><description><![CDATA[A biweekly newsletter providing curated cybersecurity news to the K-12 
community, as a public service of K12 SIX.]]></description><content:encoded><![CDATA[<p class=""><em>A biweekly newsletter providing curated cybersecurity news to the K-12 community, as a public service of K12 SIX. Sign up for the </em><a href="https://www.k12six.org/all-news"><em>K12 SIX mailing list</em></a><em> to have future editions delivered to your inbox.</em></p>


  










  



  <hr />
  
    

    



  


  
    
  
  <h3><strong>Mark Your Calendar</strong></h3><ul data-rte-list="default"><li><p class="">9/9 - <a href="https://cdt.org/event/nonconsensual-deep-fakes-surfacing-tech-powered-harassment-in-k-12-schools/" target="_blank">Nonconsensual Deep Fakes: Surfacing Tech-Powered Harassment in K-12 Schools</a> (Center for Democracy &amp; Technology)</p></li><li><p class="">9/10 - <a href="https://events.gcc.teams.microsoft.com/event/f9b5799a-5b30-48ea-a643-27d74dba0def@bd5d4514-84de-4928-a9fd-6ae10bbad677" target="_blank">Hack to School: Cyber Threats and Smarter Defenses for K-12 &amp; Higher Ed</a> (Privacy Technical Assistance Center/US Department of Education)</p></li><li><p class="">9/11 - <a href="https://k12six.cyware.com/webapp/user/events" target="_blank">Monthly Cross-Sector Threat Briefing</a> (member-only)</p></li><li><p class="">9/17 - <a href="https://events.gcc.teams.microsoft.com/event/b0c39008-68be-4189-9dbd-167de8ee188c@bd5d4514-84de-4928-a9fd-6ae10bbad677" target="_blank">Data Breach Apocalypse: Incident Response in an Ever-Changing Threat Landscape</a> (Privacy Technical Assistance Center/US Department of Education)</p></li></ul><h3><strong>In the News</strong></h3><p class=""><a href="https://www.thestate.com/news/local/education/article311857645.html" target="_blank"><strong>Hackers demanded SC school district pay ransom. They refused.</strong></a></p><p class="">A June cyber attack against the Lexington-Richland 5 school district <a href="https://www.thestate.com/news/local/education/article307974885.html" target="_blank">delayed the start of summer school, affected pay for teachers and staff</a>, and <a href="https://www.comparitech.com/news/south-carolina-school-district-notifies-31000-people-of-data-breach-that-leaked-ssns-and-financial-info/" target="_blank">exfiltrated more than 1 TB of&nbsp; data, including personal information of more than 31,000 individuals</a>. The State reports that the district received an extortion demand related to the attack but refused to pay. The threat actor <a href="https://arcticwolf.com/resources/blog/threat-actor-profile-interlock-ransomware/" target="_blank">Interlock</a> has claimed responsibility for the attack. </p><p class=""><a href="https://cybersecuritynews.com/threat-actors-using-stealerium-malware/" target="_blank"><strong>Threat Actors Using Stealerium Malware to Attack Educational Organizations</strong></a></p><p class="">Readily available to low-sophistication actors, commodity information stealers—such as Stealerium—have been deployed via phishing campaigns targeting universities and K-12 networks, with volumes ranging from hundreds to tens of thousands of emails per campaign. The information stealer Stealerium, e.g., has the capability to exfiltrate: keylogging and clipboard data; banking/credit card data (scraped from web forms); browser cookies, cache, and stored credentials; session tokens from gaming services (like Steam, Minecraft, BattleNet, and Uplay); email and chat data (Outlook, Signal, Discord, etc.); system data such as installed apps, hardware info, and Windows product keys; VPN services data (NordVPN, OpenVPN, ProtonVPN, etc.); Wi-Fi network information and passwords, crypto wallet data; and, other files deemed interesting (such as various types of images, source code, databases, and documents). Proofpoint finds that threat actors are increasingly seeking compromised identities, which is why they’ve observed <a href="https://www.proofpoint.com/us/blog/threat-insight/not-safe-work-tracking-and-investigating-stealerium-and-phantom-infostealers" target="_blank">a rise in the use of information stealers</a>.  </p><p class=""><a href="https://www.k12six.org/news/k12-six-comments-on-secretarys-supplemental-priority-on-advancing-artificial-intelligence-in-education"><strong>K12 SIX Calls on Secretary of Education to Enhance K-12 Cybersecurity <em>with</em> AI, <em>for</em> AI, and <em>from</em> AI </strong></a></p><p class="">K12 SIX submitted comments regarding the U.S. Department of Education's new proposed funding priority—<a href="https://www.regulations.gov/docket/ED-2025-OS-0118" target="_blank">Advancing Artificial Intelligence in Education</a>—for use in currently authorized discretionary grant programs, or such programs that may be authorized in the future. K12 SIX comments can be read <a href="https://www.k12six.org/s/K12SIX-ED-2025-OS-0118_Comments-2025-8.pdf" target="_blank">here</a>. Many other submissions are posted online at: <a href="https://www.regulations.gov/docket/ED-2025-OS-0118/comments" target="_blank">https://www.regulations.gov/docket/ED-2025-OS-0118/comments</a></p><p class=""><a href="https://www.k12six.org/news/call-for-speakers-registration-opens-for-4th-annual-national-k-12-cybersecurity-leadership-conference-5k5a4"><strong>4th Annual National K-12 Cybersecurity Leadership Conference (Feb 2026): Call for Speakers, Registration Open</strong></a></p><p class="">The National K-12 Cybersecurity Leadership Conference is a unique event designed to identify and share solutions and best practices to better defend the K-12 education sector from emerging cybersecurity threats, such as ransomware and data breaches. Participants from past conferences report overwhelmingly positive feedback about the conference: “I just wanted to reach out to say thank you again for an amazing conference. My team and I all agreed that was by far one of our best conferences any of us have ever attended.” <a href="https://www.k12six.org/2026-k12six-conference">The 4th Annual conference will be held February 24-26, 2026 in Albuquerque, NM</a>.</p><h3><strong>Fast Facts</strong></h3><ul data-rte-list="default"><li><p class=""><span data-text-attribute-id="127015a6-5815-4966-be63-49720490921f" class="sqsrte-text-highlight"><strong>51</strong></span>: U.S. K-12 ransomware victims claimed by threat actors (2025 to date) (<a href="https://k12six.cyware.com/webapp/user/myfeeds/024dad6e" target="_blank">source</a>)</p></li><li><p class=""><span data-text-attribute-id="37b31e14-5bb6-42d1-8ff8-1aabdc792ae3" class="sqsrte-text-highlight"><strong>32</strong></span>: Severe information technology vulnerabilities (<a href="https://www.first.org/cvss/v3-1/specification-document" target="_blank">CVSS</a> Base Score 7.0+) disclosed in past week (<a href="https://k12six.cyware.com/webapp/user/myfeeds/49b271cc" target="_blank">source</a>)</p></li></ul><h3><strong>Members Get More</strong></h3><p class="">The K12 Security Information eXchange (K12 SIX) operates as the information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. <a href="https://www.k12six.org/member-benefits">K12 SIX members get more</a>.</p>]]></content:encoded><media:content type="image/jpeg" url="https://images.squarespace-cdn.com/content/v1/5e441b46adfb340b05008fe7/1750175944248-TFNZ2JCOBLFRFX9B2Y1J/reba-spike-Jrrc7wXIy-E-unsplash.jpg?format=1500w" medium="image" isDefault="true" width="1500" height="2250"><media:title type="plain">K-12 Cybersecurity Insider | 9/8/2025 edition</media:title></media:content></item></channel></rss>