DisclosureLens
HackingEducationEducationVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedDownstream VictimsN-DayIdentity (basic)AuthenticationEducationLowResolved

Santa Barbara Unified School District

bd_0885f01d410c5843 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

May 20, 2020

To disclose

Affected

Not disclosed

Confidence

81%
Full breach record for Santa Barbara Unified School District

Santa Barbara Unified School District notified families on May 20, 2020 of unauthorized access to the Aeries Student Information System, a third-party vendor used by hundreds of California districts. The breach, discovered in late November 2019, may have exposed student IDs, parent and student emails, physical addresses, and hashed passwords. Aeries patched the vulnerability in December 2019 and perpetrators were taken into custody.

Incident timeline

Nov 1, 2019

Begins

May 20, 2020

Filed

Part of Aeries supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.