HackingEducationEducationStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryDownstream VictimsIDENTITY_BASICCREDENTIALSAUTHENTICATIONLowContained
Rocklin Unified School District
bd_8b52c8ace2109b1b · schema v1 · pii pii-v1
Full breach record for Rocklin Unified School District →Rocklin Unified School District notified families on May 12, 2020 of unauthorized access to Aeries Student Information System (SIS) on November 4, 2019. The breach, affecting RUSD and hundreds of other districts using Aeries, potentially exposed parent/student login information, physical addresses, email addresses, and encrypted passwords. Law enforcement was notified and arrests were made. Passwords were reset for all accounts.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190573
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 2, 2020
- Raw hash
- 66f8e61456885ffa5fba051a6dad276eaa4eb9f31abf0ba75e91be6a2aa68a2b
Reporting entity
- Name
- Rocklin Unified School Districtnorm: rocklin unified school district
- Domain
- rocklinusd.org
Victim entity
- Name
- Rocklin Unified School Districtnorm: rocklin unified school district
- Domain
- rocklinusd.org
- Industry
- Educationllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 12, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALSAUTHENTICATION
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing ApplicationT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Local and federal law enforcement officials were notified of the incidentCharges were filed and the people responsible were arrested
- Third party
- via Aeries
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.