CSIDB logo
Threat actor

Shandra Gilles

Attribution profile

Type
Insider - Disgruntled
Location
United States of America
Known incidents
1 incident
First seen
2020-06-22
Last seen
2020-06-22
Updated
2026-07-31 22:00
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Shandra Gilles, also known by the alias Shandra Gilles, is a former employee of Coastal Preparatory Academy located in New Hanover County, North Carolina, United States of America. According to a lawsuit filed by the charter school and contemporaneous news reporting, Gilles improperly obtained sensitive personal data from the institution’s computer systems, including Social Security numbers, health records, financial information, and employment details for students, parents, and staff. The individual allegedly locked system administrators out of critical networks by refusing to provide passwords, effectively becoming the sole administrator and paralyzing the school’s ability to manage its data. After being terminated, Gilles continued to possess and access the retained data in violation of a court agreement, prompting the school to seek emergency injunctive relief and to notify affected parties that their information may have been compromised.

The incident demonstrates a targeting focus on the education sector, specifically a K‑12 charter school operating within the United States, with no indication of broader geographic or industrial scope in the available sources. The school’s leadership characterized the breach as an isolated event involving only the former employee and emphasized cooperation with legal authorities, engagement of forensic experts, and implementation of measures to prevent future exposures. While the article does not explicitly state Gilles’s strategic objectives, the described actions—unauthorized data extraction, denial of service through credential withholding, and unlawful retention of information after separation—align with a pattern of data theft and disruption rather than any publicly attributed financial gain, espionage motive, or state sponsorship.

No specific malware families, exploit tools, or initial access vectors are detailed in the reporting; the described tactics involve improper credential use, password refusal to lock out administrators, and continued unlawful possession of data after termination. Consequently, the threat actor’s known TTPs are limited to unauthorized access, credential withholding to deny legitimate users, and illicit data retention. Publicly available information does not associate Gilles with any larger criminal consortium, state‑affiliated group, or prior campaigns beyond this singular incident at Coastal Preparatory Academy. The case remains notable as an example of insider threat where a former employee leveraged legitimate access to exfiltrate sensitive personal information and subsequently obstructed organizational recovery efforts.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB