Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Breach topic
No spam. Unsubscribe anytime.
Granite School District says unauthorized access exposed student and employee records
Summary
District IT staff told the community council that an unauthorized actor copied files from district systems in Sept. 2024 that may include student records (dating back to 1975) and employee payroll and personnel data; the district has forced password resets, implemented multi-factor authentication and offered monitoring and notification resources.
Get email alerts on the Data Breach topic
No spam. Unsubscribe anytime.
Granite School District officials told the District Community Council on Jan. 28 that an unauthorized actor accessed district systems in September 2024 and copied files that may include both student and employee records. Chief Information Officer Rick Anthony said the district’s investigation found the access occurred between Sept. 11 and Sept. 25, 2024, and that data-mining is ongoing to determine the full scope.
"Our investigation determined that between September 11 and 25, 2024 an unauthorized actor gained access to certain systems and copied files stored in those systems," Anthony told the council. He said student information located in cumulative folders "has been found as far back as 1975." On employee data, presenters said payroll bank account and routing numbers from July 2021 forward and other personnel records may have been included.
District staff described immediate technical and notification steps: confirming the threat actor no longer had access, reviewing copied files for sensitive information, notifying individuals by mail, email and website, notifying state authorities and law enforcement, instituting privileged account management, forcing password resets for all employees and implementing multi-factor authentication. Anthony said the district has "tried to be as transparent as possible and sent out emails as quickly as we had the information."
The district provided guidance for affected individuals, including enrollment in monitoring services, watching account statements and free credit reports, and placing an initial or extended fraud alert or credit freeze. The district offered a verification contact: the cyber insurance provider at 1-877-719-9674 and customerservice@graniteschools.org. Anthony told the council, "At this point we do not have any confirmed cases of information from this breach being used fraudulently."
Officials said they will consult their insurance provider and legal counsel about options for helping families (for example, whether the district can help with placing freezes for minors) and will continue updating communication protocols and employee training to reduce phishing risk. The district recommended that school technology coaches and the Help Desk review suspicious messages before staff or families click links.
