The breach came to light after a school district shared a notification letter with BleepingComputer. In the letter, Frontline Education stated that its security team identified a vulnerability in a third-party software product on August 14, which allowed unauthorized access to part of its environment. The company said it promptly investigated with the help of an independent cybersecurity firm, remediated the vulnerability, engaged with law enforcement and took steps to reinforce system security.
Frontline has not disclosed which third-party application was involved or when the unauthorized access first occurred. According to the notification seen by BleepingComputer, all employees at the affected district had their data exposed. One administrator reported that 1,210 employees associated with their district were impacted.
School IT administrators on the K12SysAdmin subreddit confirmed they began receiving notifications on October 1 from an email address at notifications.cyberscout.com. Some initially questioned the legitimacy, but several later reported that they had independently verified the notifications with Frontline representatives.
Frontline said it will handle notifications to affected individuals on behalf of impacted school districts unless a district opts out by October 16. Districts can opt out via a dedicated website or phone number. If a district opts out, Frontline will not provide notification services or reimburse the district for the costs of issuing its own notices.
Impacted adults are being offered two years of free credit monitoring and identity theft protection through TransUnion. Minors will receive cyber monitoring services. The company will also handle notifications to state attorneys general and cover costs associated with individual notifications and the identity protection services.
The total number of school districts or individuals affected remains unclear.