A story we hear too often
The morning a school’s student files showed up in a parent’s inbox
the head of a 300-student private K-8 school and its after-school tutoring program
Sister Anne has run the school on Ashland for fourteen years. Three hundred students, thirty staff, a tutoring program that fills the building until six. The student information system holds grades, health forms, custody orders and the notes teachers write when a child is struggling.
On a Wednesday in October a parent forwards an email. It is addressed to her by name, mentions her son’s reading plan and the family’s tuition balance, and asks her to pay a ‘late fee’ by gift card. Two more parents forward the same email by nine. The attacker did not guess; the attacker read.
In the version that goes badly, the export tool on the student system was used the week before with a contractor’s stolen password, every family’s data is gone, the custody orders are on a leak site, and the school’s reputation, built over sixty years, is a local news segment.
In Sister Anne’s version, the contractor’s login had been cut when it appeared from a country the school has never worked with, the export never ran, and the three emails came from an old parent-directory PDF a former staffer had kept. The engineer traces it in an hour. The school tells the parents the truth by lunch, and the truth is small.
The attacker did not guess; the attacker read.
What changes the ending
- Contractor and vendor access scoped, time-limited and watched, including the export tool (CIS Controls 15 and 6, Service Provider Management and Access Control)
- Student data encrypted, kept only as long as needed and never in a PDF on a home laptop (CIS Control 3, Data Protection)
- Login monitoring that cuts a session from the wrong country before the export runs (CIS Control 13, Network Monitoring and Defense)