Kept in the Dark: Inside a Trio of Los Angeles School Cyberattacks
A 74 investigative series: Meet the hired guns who make sure school cyberattacks stay hidden.
Get stories like this delivered straight to your inbox. Sign up for The 74 Newsletter
Kept in the Dark is an in-depth investigation into more than 300 K-12 school cyberattacks over the last five years, revealing the forces that leave students, families and district staff unaware that their sensitive data was exposed. Use the search feature below to learn how cybercrimes 鈥 and subsequent data breaches 鈥 have played out in your own community. Here鈥檚 what we uncovered about America鈥檚 second-largest school district.
The Los Angeles Unified School District was ensnared by three high-profile cyberattacks in the last few years, each of which exposed reams of sensitive information online.
Three subsequent class-action lawsuits from parents accused the nation鈥檚 second-largest district of taking inadequate steps to protect their children鈥檚 personal records 鈥 and failing to tell them that sensitive information had been leaked. The district has since taken multiple actions to shield details about the incidents from public view.
The trio of events encompass a September 2022 ransomware attack that exposed students鈥 highly sensitive psychological evaluations among other records; a January 2022 cyberattack on education technology company Illuminate Education, which compromised sensitive information in Los Angeles and districts nationwide; and a massive June 2024 cyberattack on the cloud computing company Snowflake, a third-party vendor used by the district to store certain records.
Threat actors with the Vice Society cybergang took credit for the September 2022 ransomware attack on L.A. schools, posting the records to its dark web leak site after education officials did not pay its extortion demand. In the aftermath of the attack, Superintendent Alberto Carvalho sought to downplay its effect on students. An told the local press that students鈥 psychological evaluations were included in the leak, a revelation Carvalho refuted as 鈥渁bsolutely incorrect.鈥

鈥淲e have seen no evidence that psychiatric evaluation information or health records, based on what we鈥檝e seen thus far, has been made available publicly,鈥 said Carvalho, who acknowledged the hackers had 鈥渢ouched鈥 the district鈥檚 massive student information system but said the 鈥渧ast majority鈥 of exposed student records involved their names, academic records and home addresses.
An investigation by The 74 into the leak uncovered that the breach had, in fact, exposed student psychological evaluations, which contain a startling degree of personally identifiable information about students receiving special education services, including their detailed medical histories, academic performance and disciplinary records. Just hours after our story published, the district acknowledged in a statement that 鈥渁pproximately 2,000鈥 student psychological evaluations 鈥 including those of 60 current students 鈥 had been uploaded to the dark web.
In a statement to The 74, a district spokesperson said its cybersecurity response protocol 鈥渇ollows a clear, structured process that prioritizes swift internal assessment and adherence to all applicable state and federal data privacy regulations.鈥 The process, the district said, is 鈥渄esigned with transparency, compliance and community trust in mind.鈥

Due to the sensitive nature of the information, students may have to 鈥渄eal with this breach for the rest of their lives,鈥 attorney Ryan Clarkson told The 74. Clarkson represents students and parents in a class-action lawsuit alleging LAUSD failed to act on known cybersecurity vulnerabilities and provided families insufficient notice that students鈥 personal records had been compromised.
鈥淚t鈥檚 hard to bury it, it鈥檚 hard to get away from it, it鈥檚 kind of part of who we are,鈥 Clarkson said in an interview. 鈥淵our psychology as a child is always going to be your psychology as a child.鈥
While the parents of special education students had been left in the dark about the breach, so too were members of the district鈥檚 special education committee. Carvalho acknowledged at a September 2022 that L.A. Unified was a 鈥渄istrict under siege鈥 and sought to 鈥渄ispel rumors鈥 about the incident, including one that multiple attacks had occurred. He didn鈥檛 make any statements regarding the impact on sensitive special education records.
Carl Petersen, who served on the committee at the time, told The 74 that Carvalho left the committee members without information about the attack鈥檚 ramifications on children with disabilities.
鈥淎t that point it was, 鈥極h, this was a very minor thing. We caught them in the system immediately and we shut it down,鈥 said Petersen, who described Carvalho鈥檚 comments as part of a larger district effort to obfuscate.
In January 2023 鈥 four months after the attack 鈥 L.A. school officials acknowledged in that sensitive records had been exposed but only listed Social Security numbers included in payroll records and third-party contractor files swept up in the breach. It wasn鈥檛 until March 2023 that they disclosed to state regulators the leak had also compromised .
The letter submitted to the California AG鈥檚 office doesn鈥檛 make clear the types of student records that were affected but urges individuals to 鈥渒eep a copy of this notice for your records in case of future issues with your child鈥檚 medical records.鈥
The 74 submitted a public records request for information related to the ransomware attack, including complaints submitted to a hotline LAUSD created in its wake, insurance claims, Carvalho鈥檚 communications with the FBI and the types of student records that were subject to disclosure. The district denied the requests, stating it could not locate any 鈥渘on-privileged responsive records,鈥 meaning that they didn鈥檛 have to provide any of the records that were responsive because they were legally protected from disclosure.
A week after it was discovered, the school board to grant Carvalho emergency spending powers to recover from the 2022 Labor Day weekend attack, allowing the schools chief a year to 鈥渆nter into any and all contracts鈥 to address the incident 鈥渨ithout advertising or inviting bids and for any dollar amount necessary.鈥
鈥楽hared with the world鈥
In August 2023, nearly a year after the attack, Carvalho made a high-profile appearance at the White House, where then-First Lady Jill Biden warned about the growing threat of cyberattacks on students and a need to do more to protect their sensitive data.

鈥淚f we want to safeguard our children鈥檚 futures, we must protect their personal data,鈥 she said at the first-ever K-12 cybersecurity summit. 鈥淓very student deserves the opportunity to see a school counselor when they鈥檙e struggling and not worry that these conversations will be shared with the world.鈥
Carvalho said quick reaction time by the Los Angeles district and federal law enforcement officials set into motion a response plan that mitigated the attack, limited the number of files breached and avoided class cancellations. His remarks in the East Room didn鈥檛 touch on the leak of students鈥 mental health records but said the number of stolen files 鈥渃ould have been much worse鈥 had officials not acted quickly to prevent the cybercriminals from encrypting additional district systems. One action they had no intention of doing, he said, was paying the undisclosed ransom demand because 鈥渨e don鈥檛 negotiate with terrorists.鈥
Los Angeles parent Ariel Harman-Holmes, whose three children are in special education, said she鈥檚 worried that fallout from the data breach could divert money from the services her children with disabilities need.
鈥淚 would rather have those funds go back into the schools and special education rather than spending a ton on litigation or settlements about privacy issues,鈥 said Harman-Holmes, while acknowledging it 鈥渨ould be very disturbing鈥 if her own child鈥檚 psychological evaluations were leaked online.
As L.A. Unified鈥檚 response to the attack was being lauded by federal officials at the White House summit, its lawyers were in court with parents who alleged the district鈥檚 mitigation efforts weren鈥檛 just inadequate 鈥 they violated the law. Three separate lawsuits filed in Los Angeles County Superior Court charge the district had insufficient safeguards in place to secure students鈥 sensitive records and failed to provide enough notice to victims once that information was stolen.
An inspector general鈥檚 office audit highlighted cybersecurity vulnerabilities yet, the complaints allege, LAUSD failed to take the necessary steps to prevent the attack. Parents also charge the district failed to comply with state data breach notice requirements after it learned that students鈥 psychological records and other files were published online.
The most recent complaint was filed in September 2024 against the district and the company InfoSys, which built and manages the My Integrated Student Information System 鈥 the district鈥檚 primary student data portal. The district 鈥渉as stated under oath in discovery responses鈥 that InfoSys managed the student information system that was compromised, according to court records filed by the plaintiffs.
Insufficient cybersecurity protocols allowed the intrusion to go unnoticed for more than two months, the lawsuit alleges, and, once it was discovered, L.A. school leaders failed to provide 鈥減rompt and accurate notice of the data breach.鈥
The breached portal 鈥渋s currently the largest student data system in the United States,鈥 the 162-page complaint notes, yet district officials 鈥減rioritized a race to incorporate technology in classrooms, with no regard for the risks of harboring troves of student data in online databases subject to cyberattacks.鈥
One district, three breaches
Months before the Vice Society ransomware attack began, Los Angeles student records were exposed in a cyberattack on ed tech vendor Illuminate Education, which affected districts nationwide. LAUSD submitted a breach notice to the California attorney general鈥檚 office in May 2022, some unfolded. The report doesn’t disclose the types of information that were exposed or the number of students who had been affected.
Then, in June 2024, a threat actor who goes by the name 鈥渢he Satanic Cloud鈥 posted a listing on a notorious dark web marketplace, seeking $1,000 in exchange for what they claimed was a trove of more than 24 million L.A. school district records. A second threat actor, known as 鈥淪p1d3r鈥 similarly posted a listing for records reportedly stolen from the district with a $150,000 price tag.
The district said school data maintained by a third-party vendor was caught up in a cyberattack on the cloud computing company Snowflake, but officials didn鈥檛 disclose the name of the vendor or the types of records that may have been compromised.
The district denied a public records request by The 74 seeking information related to the incident, saying that certain files were protected by attorney-client privilege.
The incident doesn鈥檛 appear in a California attorney general鈥檚 office database of data breaches.
This story was supported by a grant from the Fund for Investigative Journalism.
Did you use this article in your work?
We鈥檇 love to hear how The 74鈥檚 reporting is helping educators, researchers, and policymakers.