A researcher finds 800GB of data online tied to school software maker Raptor, used by 5,300+ US districts, including evacuation plans and student medical files
More than 4 million school records, including safety procedures, student medical files, and court documents, were also publicly accessible online.
Context & Ripple Effects
School systems have repeatedly faced exposure through education technology: an earlier investigation found ransomware groups publishing schoolchildren's sensitive information, while a later PowerSchool incident involving historical student and teacher data showed how a single vendor can concentrate records across many districts.
This case matters because the accessible material extends beyond ordinary student-directory data to operational safety and medical records. It adds a public-exposure route to a sector already affected by ransomware-related leaks of schoolchildren's data.
First-order effects
- Students, families, and staff tied to affected districts face immediate privacy and safety risk from publicly accessible medical, court, and evacuation-related records.
- Raptor and the districts using its software must determine which records were exposed and whether access pathways remain open.
Second-order effects
- Districts are likely to scrutinize vendor data inventories, access controls, and responsibility for records held in shared school-software systems.
- The exposure raises the operational cost of centralized school-data platforms: a weakness at one provider can create simultaneous remediation work for thousands of customers.
Third-order effects
- If this pattern persists, school-software procurement will increasingly turn on demonstrable data governance and clear accountability across vendors and districts, not just product functionality.
- The sector may move toward treating student-data platforms as shared critical infrastructure, because concentrated records can turn a single exposure into a system-wide incident.
The trend: Education technology is becoming a concentrated data-risk layer, making vendor security and accountability a district-wide governance issue.