Cyber Incident Victim: Morgan Hill Unified School District
Date:
Sep 2022
Location:
United States of America
Summary
Morgan Hill Unified School District experienced unauthorized access to an employee's email account over a one-month period, compromising communications and attachments within the account. The district confirmed the intrusion but could not identify which specific emails or data were accessed, leaving the scope of impacted information unclear; the breach notification did not specify whether student records, employee details, or both were involved. Affected individuals were offered one year of credit monitoring, though the total number of notified persons remained undisclosed. The district, serving thousands of students and hundreds of staff, provided no public disclosure beyond the mandated notifications.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Morgan Hill Unified School District in California experienced a data breach involving unauthorized access to an employee’s email account between September 11 and October 11, 2022. The district’s investigation confirmed unauthorized connections to the account during this period but could not identify which specific emails or attachments were viewed or accessed by the threat actor. The breach spanned 31 days, though the district did not disclose when the intrusion was initially detected or the methods used to identify the compromise. No technical details about the attacker’s entry vector—such as phishing, credential theft, or system vulnerabilities—were revealed in the district’s notification to affected parties or in public disclosures.

On January 27, 2023, the district submitted a breach notification to the California Attorney General’s Office, though it did not publish an advisory on its website. The notification did not specify whether compromised data involved student records, employee information, or both, nor did it describe the nature of the exposed data (e.g., names, addresses, financial details). Affected individuals were offered a one-year subscription to a credit monitoring service as a remedial measure. The district did not disclose the total number of impacted individuals, though it served over 8,000 students and employed more than 320 full-time teachers during the 2021–2022 academic year. No ransomware deployment, data destruction, or financial demands were mentioned in available reports. The investigation’s inability to determine the scope of accessed data left residual uncertainties about potential misuse risks.
