Cyber Incident Victim: Caddo Parish School System
Date:
Jan 2019
Location:
United States of America
Summary
The Caddo Parish School System lost nearly $1 million in taxpayer funds due to a phishing scheme targeting payments intended for Charter Schools USA, which operates Magnolia School of Excellence. Fraudsters based in Nigeria compromised the charter school's account and altered banking information on file with the district, resulting in $988,000 being diverted to an unauthorized account. The incident is under investigation by the FBI and local law enforcement.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Caddo Parish School System suffered a financial fraud incident involving approximately $988,000 in taxpayer funds during summer 2018, with public disclosure occurring in January 2019. Attackers executed a phishing scheme targeting payment processes between the school district and Charter Schools USA, which operates Magnolia School of Excellence. Fraudsters compromised Charter Schools USA's account credentials, enabling them to alter banking information stored within Caddo Schools' payment systems. This manipulation redirected a scheduled monthly payment intended for the charter school operator to an account controlled by criminals associated with a Nigerian bank. The district processed the fraudulent transaction under the false belief it was fulfilling legitimate financial obligations, transferring nearly one million dollars before detecting the deception.

Law enforcement agencies including the FBI and local authorities initiated investigations upon discovery of the misdirected funds. The incident exclusively impacted financial operations rather than student data systems or instructional networks. Public funds designated for charter school operations constituted the primary loss, creating budgetary implications for both the district and the charter operator. No technical details regarding intrusion methods beyond the phishing vector were disclosed, nor were system remediation measures described publicly. The investigation remained active at the time of reporting, with no recovery status disclosed for the stolen funds.
