Investigation finds ransomware hackers are publishing sensitive information of schoolchildren on the dark web; over 1,200 US K-12 schools had data leaks in 2021
Most don't have bank passwords. Few have credit scores yet. And still, parts of the internet are awash in the personal information of millions of schoolchildren. Tweets: @kevincollier , @kevincollier , @kevincollier , and @hacks4pancakes Tweets: Kevin Collier / @kevincollier : NEW: The epidemic of ransomware gangs hacking school districts and leaking files means they're dumping tons of incredibly sensitive information on children online for anyone to read: https://www.nbcnews.com/... Kevin Collier / @kevincollier : I looked through a ton of doxed school files and found incredibly invasive information. For one district, a list of which students were on free or reduced meals. Parents weren't told. https://www.nbcnews.com/... https://twitter.com/... Kevin Collier / @kevincollier : What can a parent do? First off, they should immediately freeze their child's credit, which is a bit of a hassle (links in the story). Besides that...there is precious little they can. That stuff is out there, and there's really no getting it back. https://www.nbcnews.com/... Lesley Carhart / @hacks4pancakes : Wow. There were parents during my childhood who ruined their own kids' credit but I don't envy today's parents needing to freeze and monitor their kids'. https://twitter.com/...
Context & Ripple Effects
The pandemic pushed US school districts online fast, and ransomware crews followed: a Wall Street Journal analysis counted nearly three dozen district attacks covering 700,000+ students by late 2020 alone. The escalation point came when Las Vegas-area officials refused to pay and hackers answered by publishing students' social security numbers and grades — establishing leak-the-kids as a working pressure tactic.
This investigation shows that tactic is now industrial-scale rather than retaliatory: with over 1,200 US K-12 schools suffering leaks in 2021, gangs are mass-dumping children's personal files on the dark web regardless of whether a ransom was demanded, because the sensitive material — health notes, family details, disciplinary records — is invasive even for people with no credit history to steal.
First-order effects
- Students and parents in breached districts face exposure of deeply personal records with no financial fraud to alert them to it — most victims will never learn their data was published.
- Districts' refusal-to-pay decisions no longer just risk one dump; the tactic's demonstrated effectiveness makes every non-payment negotiation costlier.
Second-order effects
- Vendors holding centralized student troves come under the same target profile — a pattern confirmed when the later Illuminate Education breach exposed the data of more than a million students through a single supplier rather than any one district.
- Insurers, state education agencies, and procurement offices respond by pricing cyber coverage and vendor contracts around student-data liability, raising costs for under-resourced districts least able to pay them.
Third-order effects
- If the pattern holds toward the scale documented in the later Wired investigation of 300+ attacks since 2020, student-data protection shifts from local IT hygiene to a regulatory question — mandatory minimization of what schools and vendors stockpile, and disclosure duties aimed at minors who cannot monitor their own exposure.
- K-12 becomes a standing segment of the ransomware economy, forcing federal involvement in what has been handled as a patchwork of district-level incidents.
The trend: Schoolchildren's data is becoming collateral in an expanding ransomware-leak economy, pushing student privacy from a district IT issue toward a regulated, vendor-level liability.