CSIDB logo
Threat actor

Two unidentified students

Attribution profile

Type
Insider - Disgruntled
Location
United States of America
Known incidents
3 incidents
First seen
2017-01-01
Last seen
2020-10-28
Updated
2026-07-31 03:27
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by the aliases “Two unidentified students” and “Student” and operates within the United States of America. Observed activity is confined to the education sector, specifically targeting K‑12 school districts and high schools. The actor’s demonstrated objectives include altering academic records, attempting to obtain fraudulent lunch refunds, and accessing personally identifiable information such as names, Social Security numbers and addresses. No explicit statements link the actor to financial gain beyond the lunch refund attempts, to espionage, or to disruption beyond the observed data exposure and grade changes.

The actor’s tactics consistently involve exploiting vulnerabilities in school‑based information systems to gain initial access. In the Bloomfield Hills High School incident the actor used a portal vulnerability to modify grades, attendance and lunch balances while attempting to conceal activity by altering records for twenty students. In the South Washington County incident the actor exploited a server vulnerability to download a large dataset containing personal information for over fifteen thousand individuals, later opening files for 478 people. The Fort Zumwalt incident similarly involved unauthorized server access through an unspecified method, after which the actor voluntarily reported the breach. No malware families, custom tooling, or command‑and‑control infrastructure are referenced in the available sources. Attribution to any state sponsor, criminal consortium or organized group is not established; the perpetrators are identified solely as students acting individually or in pairs.

Representative operations include the 2018 Bloomfield Hills High School grade‑alteration and lunch‑refund scheme, the 2017 South Washington County personal data exfiltration that prompted identity‑theft monitoring for 478 affected individuals, and the 2020 Fort Zumwalt server intrusion that was self‑reported and led to an investigation. Following each incident, affected districts reported patching the exploited vulnerabilities, resetting passwords for compromised accounts, and, where personal data was accessed, offering credit monitoring and migrating sensitive files to encrypted servers with two‑factor authentication. These outcomes reflect the observed consequences of the actor’s actions without assigning additional intent or capability beyond what is documented.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB