Security & AI news

School data breaches · By FireAI Security & Research Team · Published

Cyberattacks hit school districts in Springfield, Massachusetts and Burnaby, British Columbia within a month

Cyberattacks on schools in Springfield, Massachusetts and Burnaby, British Columbia exposed staff data and disrupted classes. What parents should watch for.

A school building icon with a warning mark, illustrating cyberattacks on school districts in Springfield, Massachusetts and Burnaby, British Columbia.

Two school districts on two continents reported cyberattacks within the same month. In Springfield, Massachusetts, a cyberattack stole staff and student data, and the School Committee has since voted to shorten this year’s Christmas break to make up lost teaching days. In Burnaby, British Columbia, a cyberattack knocked out internal networks and phone lines, and families are still waiting to learn whether any data leaked.

Background

School districts hold exactly the records that data-theft groups look for: names, addresses, dates of birth and, in some systems, Social Security numbers, for both children and staff. IT departments in public school systems are frequently smaller and less resourced than those of comparable-sized private employers. Two districts neighbouring Springfield, Everett and Sutton, reported similar attacks the same month, a pattern that suggests school systems in the region were targeted repeatedly rather than once.

Findings

Springfield Public Schools’ IT staff spotted suspicious activity on the district’s systems on 1 September and spent the following week trying to contain it, The Reminder reported. The district told the public on 11 September, and the FBI confirmed on 15 September that data had been stolen. According to the district, the stolen files include staff and student records, and possibly Social Security numbers belonging to current and former employees; student Social Security numbers were reportedly not stored in the affected system. Springfield Public Schools employs more than 4,800 people, all of whom are affected. The district has hired the identity-protection firm IDX to offer staff free credit and identity-theft monitoring, and is working with the FBI, outside lawyers and forensic investigators.

We’ll spend what we have to spend.

Mayor Domenic J. Sarno, quoted by The Reminder

Mayor Sarno has since written to Massachusetts’ federal delegation asking for help covering the cost of the cyberattack, Western Mass News reported, describing incidents like it as a cost every local government now has to budget for. MassLive reported that the School Committee voted to shorten the district’s nearly three-week Christmas break so students can make up instructional time lost while systems were down.

In Burnaby, the district told families on 21 September that "internal network services and phone lines" had been affected, and that student learning had not been disrupted, The Cyber Express reported. As of that report the district had not said whether any personal data was accessed, though the disruption to its systems raised concerns about a possible leak. Staff were still working to restore services days later.

Implications for families

Direct impact is limited to families in the districts named above. The pattern is what generalises: school districts hold the records a data-theft group wants, and, as Springfield’s reporting shows, there is often no clear reason one district is targeted over another. A breach notice from a family’s own school, this term or next, is a realistic thing to plan for.

Recommendations

  1. Read a school breach notice on the school’s own website or letterhead, not through a link in a text message or email. A genuine notice will not ask for a child’s Social Security number by clicking through.
  2. Expect a wave of messages that imitate the school after any local news of a breach: fake "update your emergency contact", "confirm your child’s enrolment" or "pay an overdue fee" messages are a common follow-on scam. Call the school office if in doubt.
  3. Sign up for free credit or identity-theft monitoring if a district offers it, as Springfield did through IDX. It costs nothing and can catch misuse of a stolen Social Security number early.
  4. Check which accounts are signed into a child’s school-issued laptop or Chromebook, and keep those separate from family accounts and passwords.
  5. Use unique passwords for the school portal and for family email accounts, and turn on two-factor authentication wherever the school or email provider offers it.
  6. Tell children not to click a link or open an attachment in an unexpected message claiming to be from school, and not to paste anything into a pop-up asking to "fix" a school app.

Relevance to FireAI

A school district’s own network and student information systems are entirely outside FireAI’s reach: it protects the Mac it runs on, not a district’s servers. What it can do is reduce the chance that a scam riding on this kind of news, or a dubious "homework helper" app, gets a foothold on a family Mac.

  • FireAI’s Parental Controls already block known phishing and scam sites across every browser on the Mac, which covers a share of the fake "school" pages this kind of story tends to bring.
  • If a suspicious app or browser extension appears after a breach notice, per-app rules can block that one app or company outright, and a single bad page can be cut off without touching the rest of a site.
  • The world map and Investigate a connection show, in plain language, where an app on the family Mac is actually sending data, rather than taking a login page at its word.
  • FireAI’s on-device AI, Ask FireAI, can explain a suspicious connection without sending anything about the Mac to a cloud service.

FireAI cannot recover data a district has already lost, does not scan files for information-stealing programs, and cannot say whether a specific child’s record was part of a breach; only the school or district can answer that. FireAI is made by HisnLabs.

Limitations

The Cyber Express had not, as of its report, confirmed whether personal data was accessed in the Burnaby incident. None of the four sources establish whether the attacks on Springfield, Everett and Sutton were carried out by the same actor, or whether the Burnaby incident is connected to the Massachusetts cases at all. The full scope of data taken from Springfield’s systems, beyond the categories the district has named, has not been published.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. The Reminder (Sarah Heinonen), 17 September 2026: Cyberattack on Springfield schools included data breach
  2. Western Mass News, 26 September 2026: Mayor Sarno seeks additional funding after cyberattack, macroburst
  3. The Cyber Express (Samiksha Jain), 25 September 2026: Burnaby School District cyberattack
  4. MassLive, reported 27 September 2026: Springfield schools’ holiday break will be shortened because of cyberattack