The Los Angeles Unified School District (LAUSD) is investigating claims of a hacker stealing data. The hacker says he has stolen records for thousands of students and teachers and is threatening to leak them.

LAUSD is the second largest public school district in the United States, with thousands of students, teachers, and other staff.
The hacker says he is selling the allegedly stolen data (11 GB) for $1,000. The CSV files, which were put up for sale on hacking forums, contain over 26 million records with student information, more than 24,000 teacher records, and about 500 containing staff information.
To prove the credibility of his claims, the attacker also shared two data samples containing approximately 1,000 records for students, with Social Security Numbers (SSNs), addresses, parent addresses, email, contact information, and dates of birth.
See also: North Korean workers infiltrate freelance IT networks to steal data
Researchers who analyzed these samples told BleepingComputer that the data appears legitimate, but could be old, as no recent dates are included. However, this observation only applies to the samples. The remaining files, if indeed legitimate, may contain more recent data.
“We are looking into this matter and will contact you if we have more information to share,” Britt Vaughan of the Los Angeles Unified School District told BleepingComputer.
Vice Society: Previous ransomware attack on LAUSD
LAUSD was also hit by a ransomware attack in September 2022. The Vice Society claimed responsibility for the breach, saying it also stole 500GB of files before encrypting the systems.
Following the attack, the Los Angeles Unified School District asked all employees (including teachers, support staff, and administrators) and students to reset their @LAUSD.net account credentials
Nearly a month after the attack, Vice Society published the stolen data, as the school district announced itwould not pay the ransom demanded by the gang.
See also: ToddyCat hackers use sophisticated tools to steal data
At this time, it is unclear whether the data now being sold is connected to the data that was stolen from Vice Society.

Educational sector: Cyberattack protection strategies
One of the most effective strategies is to educate staff and students about cyberattacks. This can include learning the basics of cybersecurity, understanding the most common attack techniques, and learning best practices for protecting personal and institutional data. For example, it is essential to use strong and unique logins and enable MFA on accounts wherever and whenever possible.
Additionally, the use of advanced security solutions, such as intrusion protection systems (IPS), intrusion detection systems (IDS), and antivirus, can provide significant protection against cyberattacks. These tools can detect and repel attacks before they cause significant damage.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: TikTok fixes zero-day used to compromise high-profile accounts
Network segmentation can also help protect educational institutions by preventing a potential attack from spreading to all systems.
Implementing a least privilege policy, which limits access to systems and applications to only those who truly need that access, can reduce the risk of cyberattacks.
Updating all software and applications is also essential, as it fixes potential security vulnerabilities that hackers can exploit.
Finally, regularly backing up important data and implementing disaster recovery plans can ensure that, even if a cyberattack occurs, data can be recovered.
Source: www.bleepingcomputer.com
