Data breach
LA Unified School District
- Records
- 1,989,123
- Breach date
- 1 June 2024Estimated
- Added
- 12 January 2026
What was exposed
4 types of data · 3 more reported
- Dates of birth1
- Email addresses1
- Names1
- Phone numbers1
- Home addressesReported, not counted
- Education historyReported, not counted
- Medical recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The Los Angeles Unified School District has confirmed that student and employee data was stolen through its account on Snowflake, a cloud storage platform, and that the stolen records were offered for sale on dark web marketplaces in June 2024. The listing indexes nearly two million records, about 1,989,123 rows, with an estimated attack date of June 1, 2024. No single group has publicly claimed responsibility for the full dataset.
The district, the second largest school district in the United States, first learned of the problem on June 6, 2024, when a threat actor using the name "The Satanic Cloud" posted a listing on a dark web marketplace offering what was claimed to be more than 24 million LAUSD records for $1,000. A second actor, known as "Sp1d3r," began selling a separate dataset on June 18 for $150,000, telling BleepingComputer the data came from the district's Snowflake account. After reviewing samples, the district confirmed that the Snowflake-linked data had been stolen from its account and said the theft appeared consistent with a wave of intrusions affecting numerous Snowflake customers who had not enabled multi-factor authentication. District officials said their own systems showed no evidence of compromise and that the data had been held by one or more external vendors.
Breach Timeline
June 6, 2024: LAUSD became aware of a dark web listing by the actor "The Satanic Cloud" purporting to sell district data for $1,000, and began investigating with law enforcement, as reported by BleepingComputer.
June 18, 2024: The threat actor "Sp1d3r" began selling a separate LAUSD dataset for $150,000, claiming it was stolen from the district's Snowflake account.
June 21, 2024: LAUSD confirmed to BleepingComputer that the data sold by Sp1d3r was stolen from its Snowflake account, and said it was working with the FBI, CISA, and its vendors.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, phone numbers, and dates of birth. Our investigation team could not determine how many of each type appear in the indexed records.
Reporting provides a more detailed picture of what appeared in samples reviewed during the incident. BleepingComputer reported that the Snowflake-linked dataset contained student names, addresses, family names, demographics, financial information, grades, performance scores, disability information, discipline details, and parent information. A sample from the earlier "Satanic" listing, according to the same reporting, included Social Security numbers, addresses, parent addresses, email addresses, contact information, and dates of birth. Researchers who examined the samples said the data appeared legitimate but possibly dated.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers, dates of birth, and home addresses are the building blocks of identity theft, and children's stolen identities are especially attractive to criminals because misuse can go undetected for years. The exposure of grades, disability information, and discipline records adds a second risk: sensitive personal details of this kind can be used in targeted phishing messages or harassment. Email addresses and phone numbers in the leak can support convincing scams that impersonate the district, its vendors, or credit agencies to extract passwords or payment details. Because one actor reportedly released part of the data for free, the information may circulate among many criminals rather than a single buyer.
What Is LA Unified School District Doing in Response?
The district stated that it became aware of the sale attempts on June 6, 2024, and began investigating the claims while engaging with law enforcement. In its June 21 statement to BleepingComputer, LAUSD said it determined the data was held by external vendors on Snowflake, reported that its investigation had found no compromise of the district's own systems or networks, and said it was collaborating with the FBI, CISA, and its vendors. Officials did not disclose the name of the vendor or a full accounting of the record types involved.
What Should You Do If You Were Affected?
If you are or were an LAUSD student, parent, or employee, treat your personal information as exposed. Review credit reports for yourself and your children for unfamiliar accounts, and consider placing a credit freeze, which is free in the United States. If a Social Security number may have been involved, watch for tax-related notices and consider an IRS Identity Protection PIN. Be cautious with unsolicited emails, texts, and calls that reference the district, your child's school, or account problems, and never share passwords or verification codes in response to such messages.
In the news
- BleepingComputer: Los Angeles Unified School District investigates data theft claimsbleepingcomputer.com (opens in a new tab)
- BleepingComputer: Los Angeles Unified confirms student data stolen in Snowflake account hackbleepingcomputer.com (opens in a new tab)
- The 74: Kept in the Dark: Inside a Trio of Los Angeles School Cyberattacksthe74million.org (opens in a new tab)
