Chicago Public Schools
Incident posture
Linked entities
- Victim
- Chicago Public Schools
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Chicago Public Schools announced that a vendor's file transfer server was compromised, exposing personal information of current and former students who attended the district over the past eight years. The compromised data included names, dates of birth, gender, and student identification numbers, and for those enrolled in Medicaid, Medicaid identification numbers and program eligibility dates. Officials confirmed that social security numbers, financial information, and health records were not accessed. With more than 320,000 students enrolled, the breach affects a large portion of the student population.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Friday, Chicago Public Schools officials announced that a vendor's server had been hacked, exposing personal information for current and former students dating back to the 2017‑18 school year. The vendor, Cleo, provides file transfer software used by the district and its system was compromised late last year. According to the announcement, the hackers accessed students’ names, dates of birth, gender, and Chicago Public Schools student identification numbers. For students who were enrolled in Medicaid, the breach also exposed their Medicaid identification numbers and the dates of their program eligibility. Chicago Public Schools emphasized that no social security numbers, financial information, or health data were accessed in the incident. The breach potentially affects all current and former students who attended the district since the 2017‑18 academic year, a period covering more than eight years. With the district’s current enrollment exceeding 320,000 students, the total number of individuals whose data may have been exposed is large.
Chicago Public Schools officials stated that the breach was discovered after the vendor’s system was compromised and that they notified affected individuals promptly. The district advised all current and past students to review their credit reports as a precautionary measure. Officials reiterated that the exposed data did not include social security numbers, financial details, or health records, which they said limits the potential for certain types of fraud. They noted that the incident remains serious despite the absence of the most sensitive identifiers. The announcement did not specify any evidence of misuse of the exposed information at the time of disclosure. Chicago Public Schools said it continues to work with the vendor and law enforcement to investigate the breach and to strengthen security measures surrounding third‑party services.
Sources
Sources available to members: 1 source.