HomeSecurityEzekiel Potter: 21 months in prison for cyberattacks on a school

Ezekiel Potter: 21 months in prison for cyberattacks on school

Former IT employee Ezekiel Potter was sentenced to 21 months in prison for a series of cyberattacks against his former employer, the Saydel Community School District in Iowa. The case is a classic example of an insider threat, in which a former employee with privileged access retaliates against his former employer, causing serious disruptions tothe operations of the educational institution.

See also: CISA warns of cyberattacks on fuel systems

Ezekiel Potter

According to court documents, 34-year-old Potter worked as a senior IT support specialist at the Saydel Community School District in Des Moines from May 2022 to April 2023. After leaving, he maintained access to the school's network systems and for the next 21 months conducted systematic attacks aimed at paralyzing the operation of the educational institution.

Prosecutors described Potter as a “scourge of the Saydel Community School District” for more than a year and a half. His attacks included deleting the school’s Facebook page, removing employees’ access to educational platforms, and repeated attempts to reset employees’ usernames and passwords on various platforms and accounts.

The cyberattacks began almost immediately after Potter left the school network, with the first attack targeting the school's Facebook account. Potter then focused on Apple School Manager account , deleting user accounts, passwords, phone numbers, billing information and device management server data.

This attack had a devastating impact on the school’s operations, preventing employees from accessing the Apple School Manager platform and disabling management of MacBooks and iPads on the school network for about a week. Staff were forced to work with Apple to restore access.

In January 2025, Potter escalated his attacks by gaining access to the Schoology learning management system through a Google administrator account. He deleted an IT employee's account, disrupting teachers' access to the platform and affecting classes for about two hours.

A week later, Potter, gaining access to another administrator account, deleted nine Gmail accounts belonging to current and former employees of the school network, including the IT director and the school principal. Realizing that he was receiving Google security alerts about unauthorized access to the accounts, Potter began using VPN services to hide his identity.

See also: 'GreyVibe' uses AI to enhance cyberattacks

Ezekiel Potter: 21 months in prison for cyberattacks on school

Federal investigators were eventually able to trace some of the activity to IP addresses linked to Potter's other employers, including Casey's Store Support Center and The Printer Inc. (TPI). After Potter left TPI in January 2025, he asked a former colleague to retrieve and erase a USB drive from his office.

Instead of complying, the colleague turned the USB drive over to investigators, who discovered spreadsheets containing usernames and passwords for Saydel School District accounts and services. This discovery was key to Potter's eventual arrest and conviction.

Legal consequences and financial costs

Potter pleaded guilty in January 2026 to computer fraud charges under the Computer Fraud and Abuse Act, without signing a plea agreement. On June 11, he was sentenced to 21 months in prison followed by three years of supervised release.

As part of the terms of his supervised release, Potter will be subject to restrictions and monitoring regarding employment, finances and computer systems, including searches of electronic devices upon reasonable suspicion. He was also ordered to pay $59,668.81 in restitution to the Saydel Community School District and his insurance company, Travelers Casualty and Surety Company, for restitution costs related to the attacks.

See also: Netherlands: Seizure of 800 servers and 2 arrests for Russian cyberattacks

OpenAI IPO application submission public listing

The case highlights the importance of immediately disabling all accounts and access privileges when IT employees leave an organization, as well as the need for robust monitoring and logging of administrative activities. The case serves as a warning to all organizations about the risks posed by insider threats and the need for rigorous offboarding procedures.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS