Menu
Browse

Cyber Incident Victim: Morgan Hill Unified School District

Date:

Sep 2022

Location:

United States of America

Summary

Morgan Hill Unified School District experienced unauthorized access to an employee's email account over a one-month period, compromising communications and attachments within the account. The district confirmed the intrusion but could not identify which specific emails or data were accessed, leaving the scope of impacted information unclear; the breach notification did not specify whether student records, employee details, or both were involved. Affected individuals were offered one year of credit monitoring, though the total number of notified persons remained undisclosed. The district, serving thousands of students and hundreds of staff, provided no public disclosure beyond the mandated notifications.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Morgan Hill Unified School District in California experienced a data breach involving unauthorized access to an employee’s email account between September 11 and October 11, 2022. The district’s investigation confirmed unauthorized connections to the account during this period but could not identify which specific emails or attachments were viewed or accessed by the threat actor. The breach spanned 31 days, though the district did not disclose when the intrusion was initially detected or the methods used to identify the compromise. No technical details about the attacker’s entry vector—such as phishing, credential theft, or system vulnerabilities—were revealed in the district’s notification to affected parties or in public disclosures.

Cyber Incident Image

On January 27, 2023, the district submitted a breach notification to the California Attorney General’s Office, though it did not publish an advisory on its website. The notification did not specify whether compromised data involved student records, employee information, or both, nor did it describe the nature of the exposed data (e.g., names, addresses, financial details). Affected individuals were offered a one-year subscription to a credit monitoring service as a remedial measure. The district did not disclose the total number of impacted individuals, though it served over 8,000 students and employed more than 320 full-time teachers during the 2021–2022 academic year. No ransomware deployment, data destruction, or financial demands were mentioned in available reports. The investigation’s inability to determine the scope of accessed data left residual uncertainties about potential misuse risks.

Sources
Sources available to members
1 source