Cyber Incident Victim: Rockdale ISD
Date:
Jan 2025
Location:
United States of America
Summary
A phishing attack targeting a school district compromised all employees' confidential tax information when an employee inadvertently forwarded W-2 forms to an impersonator posing as the superintendent. The breach enabled fraudulent tax filings for multiple staff members, prompting involvement of local police, the FBI, and IRS investigators. District officials confirmed comprehensive exposure of employee data and initiated plans to strengthen cybersecurity protocols through vendor partnerships and enhanced staff training to identify phishing attempts.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 30, 2018, Rockdale Independent School District experienced a data breach compromising confidential tax information for all district employees. The incident originated from a phishing email scheme targeting an employee with access to employee W-2 records. An attacker impersonated Rockdale ISD Superintendent Dr. Denise Monzingo in a fraudulent email communication, successfully deceiving the employee into forwarding the entire district's W-2 tax documents. This unauthorized disclosure exposed sensitive personal and financial data including Social Security numbers, income details, and withholding information for every district employee. The breach remained undetected until subsequent fraudulent tax filings involving multiple employees alerted the district to the compromise on the following Monday, though officials could not specify the exact number of employees directly affected by false filings at the time of disclosure.

Rockdale ISD administrators contacted Rockdale Police Department immediately upon discovering the fraudulent filings, initiating a multi-agency investigation that expanded to include the Federal Bureau of Investigation and Internal Revenue Service. District leadership confirmed the breach impacted all employees systemwide due to the comprehensive nature of the compromised W-2 records. In response, the district announced plans to engage cybersecurity firms to strengthen institutional safeguards against future attacks. Concurrently, Rockdale ISD committed to enhancing employee training programs focused on phishing identification and email verification protocols to reduce susceptibility to similar social engineering tactics. The district did not publicly disclose whether stolen data appeared on dark web markets or whether affected employees received credit monitoring services following the breach.
