Los Angeles School Board investigating possible major data theft

School Bus
(Image credit: Marcelo Cidrack / Unsplash)

The Los Angeles Unified School District (LAUSD) has said it is investigating a possible data breach after a hacker revealed data for sale on a dark web forum.

LAUSD is the second-largest public school district in the United States, counting more than half a million students for the 2023-2024 school year. Furthermore, it has almost 50,000 employees, including almost 26,000 teachers.

According to BleepingComputer, a hacker is asking for $1,000, for a batch of CSV files containing 11GB of sensitive data. The data includes 26 million records with student information, more than 24,000 teacher records, and around 500 containing staff information.

Data from an old attack?

The attacker also shared two samples with some 1,000 student records, to prove the legitimacy of the claims. These records contained people’s Social Security Numbers (SSN), postal addresses, parent addresses, email addresses, contact information, as well as birth dates.

The publication says the information could be legitimate, but could also be old. LAUSD suffered a ransomware attack back in 2020, and since the organization declined to pay the ransom demand, the hackers sold the data on the dark web. 

Indeed, the information in the sample is old, BleepingComputer added. However, the sample is also relatively small (just 1,000 records), so the rest of the database could still be fresh. After reaching out to LAUSD, the publication was told that an investigation is currently underway:

"We are looking into this and will get back to you if we have further information to share," LAUSD Public Information Officer Britt Vaughan told the publication.

In early September 2022, LAUSD confirmed suffering a ransomware attack which was big enough to catch the attention of the White House. The official residence and workplace of the president of the United States alerted the Department of Education, the FBI, and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) and demanded a combined effort to "provide rapid, incident response support".

Schools across the district opened on September 6 as planned, with little impact on everyday learning, although LAUSD warned some institutions may encounter disruption in their "business operations".

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
How to prevent cyberattacks
PowerSchool breach worse than thought, company says "all" student and teacher data accessed
A digital representation of a lock
PowerSchool hit by cyberattack which saw student and teacher data stolen
security
PowerSchool hack keeps getting worse - 62 million students now thought to be affected
Red padlock open on electric circuits network dark red background
Publishing giant Scholastic hit by hackers, data on 8 million people stolen
Classroom
Schools are facing greater cybersecurity threats than ever before
Doctor working on laptop
Another major US hospital hacked, data on 1.4 million patients leaked
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection