What happened
San Diego Unified School District disclosed in December 2018 that an intruder had used phishing emails to harvest staff network credentials and had access to district systems from January to November 2018. More than 500,000 students, parents and employees were affected, including students going back to the 2008-2009 school year. Exposed data included Social Security numbers, health data, payroll and bank account details.
How the deception worked
The attacker sent phishing emails to district staff that led to pages designed to capture network log-in credentials. Because a school district's staff population is large, distributed across many sites and generally does not have dedicated security support, a broad credential-harvesting campaign only had to work on a handful of recipients. The stolen log-ins gave ordinary authenticated access to district systems, which is why the intrusion looked like normal staff activity for eleven months. It was detected in October 2018 only because multiple employees independently reported the phishing emails, which prompted the investigation that revealed the wider access.
The control that would have caught it· our reading, not a claim from the sources
Multi-factor authentication on staff single sign-on, plus alerting on anomalous access to student information systems, is what turns an eleven-month intrusion into a same-day one.
Sources (2)
- Info on Over 500,000 Students and Staff Exposed in San Diego School District HackBleepingComputer·bleepingcomputer.comOpen ↗
- San Diego Schools Say Phishing Scam Caused Cyber BreachNewsweek·newsweek.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.