CSIDB logo
Threat actor

Laura Rose Carroll

Attribution profile

Type
Insider - Disgruntled
Location
United States of America
Known incidents
1 incident
First seen
2019-08-01
Last seen
2019-08-01
Updated
2026-07-31 19:58
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Laura Rose Carroll, also known by her full name, is an individual based in Pensacola, Florida, United States, who worked as an assistant principal at Bellview Elementary School. She and her teenage daughter, a student at Tate High School, were arrested in March 2021 after an investigation by the Florida Department of Law Enforcement uncovered unauthorized access to the Escambia County School District’s FOCUS student information system. The pair used Carroll’s legitimate district‑level credentials to log into the system, enabling them to manipulate the Tate High School homecoming court voting process and to view personal records of hundreds of students. Carroll’s daughter reportedly used her mother’s account to cast multiple votes, with investigators tracing 246 fraudulent votes to IP addresses linked to their residence and Carroll’s cell phone. The investigation also revealed that beginning in August 2019, Carroll’s account accessed the records of 372 high school students, 339 of whom attended Tate High School, over an extended period. Both individuals faced felony charges including offenses against users of computers, unlawful use of a two‑way communications device, criminal use of personally identifiable information, and conspiracy to commit these offenses.

The activity was confined to the education sector, specifically targeting a single school district in northwestern Florida, and appeared aimed at influencing a school‑based election and obtaining student personal data rather than pursuing financial gain, espionage, or broader disruption. The observed tactics relied on the misuse of authorized access credentials, leveraging a legitimate employee account to gain entry to the FOCUS platform, and employing personal devices such as a cell phone and home computers to carry out the unauthorized actions. No malware, custom tooling, or external infrastructure was referenced in the reporting, and the actions were attributed solely to the individuals involved without any indication of state sponsorship, criminal consortium affiliation, or broader organizational ties. The incident represents a discrete case of insider threat where privileged access was abused for personal advantage, resulting in legal consequences for both the mother and her daughter.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB