Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-03 · updated: 2026-10-03 · tags: [incident, education] · confidence: medium · severity: high · affected_sectors: [education] · au_impact: false

Edtech provider Frontline Education, which supplies administration and workforce-management software to US school districts, is notifying districts of a data breach after attackers exploited a vulnerability in a third-party application to gain unauthorised access to its systems and steal employee information. A notification to one impacted district says the company's security team identified the third-party vulnerability on 14 August 2026, allowing unauthorised access to part of the environment; Frontline says it investigated with an independent cybersecurity firm, remediated the flaw, engaged law enforcement and reinforced system security. It has not disclosed which third-party application was involved or when the first unauthorised access occurred. For the notification reported by BleepingComputer on 2 October, all employees at the affected district were impacted, with exposed data including Social Security numbers, email addresses and physical addresses. School IT administrators on the K12SysAdmin subreddit reported that districts began receiving similar notifications on 1 October, and multiple administrators independently confirmed the notifications are legitimate.

Attribute Detail
Sector Education
Date 2026-10-03
Source BleepingComputer
Reliability Tier 2