HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICPIILowContained
Pittsfield Public Schools
bd_b98d1fdd793fd52f · schema v1 · pii pii-v1
Full breach record for Pittsfield Public Schools →Pittsfield Public Schools notified the Massachusetts AG of a cybersecurity incident involving the Canvas learning management system (Instructure). The breach potentially exposed student names, email addresses, student ID numbers, and messages. No passwords, SSNs, or financial data were accessed. Instructure revoked compromised credentials, rotated keys, and restricted account creation. Services are back online.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-746-pittsfield-public-schools/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- 8f9dc71352bd2d6e98c579423dd1523001fecbd7ba89e5b01e4ba2f849ea6915
Reporting entity
- Name
- Pittsfield Public Schoolsnorm: pittsfield public schools
- Domain
- pittsfield.net
Victim entity
- Name
- Pittsfield Public Schoolsnorm: pittsfield public schools
- Domain
- pittsfield.net
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 10, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Instructure (Canvas)
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.