Bellflower Unified School District: Bellflower Unified Schools warns students of data breach that leaked SSNs

Bellflower Unified School District: Bellflower Unified Schools warns students of data breach that leaked SSNs

Bellflower Unified School District Hit by Rhysida Ransomware Attack in August 2025

In August 2025, Bellflower Unified School District (BUSD) in Los Angeles County suffered a ransomware attack that disrupted network services and compromised sensitive data, including Social Security numbers. The district confirmed the breach in June 2026, notifying affected individuals via letters filed with the California attorney general.

The cybercriminal group Rhysida claimed responsibility for the attack on October 28, 2025, demanding a 10 Bitcoin ransom (approximately $1.15 million). BUSD has not confirmed Rhysida’s involvement, and it remains unclear whether the district paid the ransom or how the attackers breached its systems. The incident affected historical student, parent, and employee data stored on an impacted server, though current student records in the Aeries system were unaffected.

BUSD is offering free credit monitoring through Iris Identity Protection to breach victims, with a 90-day enrollment deadline from the notice date.

Rhysida’s Growing Threat

Rhysida, a ransomware-as-a-service (RaaS) group active since May 2023, operates by encrypting systems and extorting victims for both data deletion and decryption keys. In 2025, the group claimed 92 attacks, with 27 confirmed by targeted organizations. Around the same time as the BUSD incident, Rhysida also struck:

  • Collège Supérieur de Montréal (Canada, October 2025) – Demanded $430,000
  • Yokosuka Gakuin Elementary School (Japan, December 2025) – Demanded $519,000

In 2026, Rhysida has already claimed 10 additional attacks, including confirmed breaches at German tech firm Elabs AG and Canadian manufacturer STELIA Aerospace.

Ransomware’s Impact on Education

The BUSD attack is part of a broader surge in ransomware targeting schools. In 2025, 56 confirmed attacks on U.S. educational institutions compromised over 4 million records. Other recent incidents include:

  • Nelson University – Notified 22,000 individuals of a May 2025 breach linked to the Qilin ransomware group.
  • Evanston Township High School District 202 (Illinois) – Still recovering from a June 2026 attack.

Such attacks disrupt critical operations attendance tracking, grading, payroll, and communications while exposing students and staff to fraud risks. Schools that refuse ransom demands may face prolonged downtime and permanent data loss.

BUSD serves nearly 10,000 students across 13 schools in Los Angeles County. The district has not provided further details on the attack’s origin or response.

Source: https://www.comparitech.com/news/bellflower-unified-schools-warns-students-of-data-breach-that-leaked-ssns/

Bellflower Unified School District cybersecurity rating report: https://www.rankiteo.com/company/bellflower-unified

"id": "BEL1782152779",
"linkid": "bellflower-unified",
"type": "Ransomware",
"date": "8/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Historical student, parent, and '
                                              'employee data',
                        'industry': 'Education',
                        'location': 'Los Angeles County, California, USA',
                        'name': 'Bellflower Unified School District',
                        'size': 'Nearly 10,000 students across 13 schools',
                        'type': 'School District'}],
 'customer_advisories': 'Offering free credit monitoring through Iris Identity '
                        'Protection to breach victims, with a 90-day '
                        'enrollment deadline from the notice date',
 'data_breach': {'data_encryption': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Social Security numbers',
                                              'Historical student data',
                                              'Parent data',
                                              'Employee data']},
 'date_detected': '2025-08',
 'date_publicly_disclosed': '2026-06',
 'description': 'In August 2025, Bellflower Unified School District (BUSD) in '
                'Los Angeles County suffered a ransomware attack that '
                'disrupted network services and compromised sensitive data, '
                'including Social Security numbers. The district confirmed the '
                'breach in June 2026, notifying affected individuals via '
                'letters filed with the California attorney general.',
 'impact': {'data_compromised': 'Sensitive data, including Social Security '
                                'numbers, historical student, parent, and '
                                'employee data',
            'identity_theft_risk': 'High',
            'operational_impact': 'Disrupted attendance tracking, grading, '
                                  'payroll, and communications',
            'systems_affected': 'Network services, impacted server'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain',
 'ransomware': {'data_encryption': True,
                'ransom_demanded': '10 Bitcoin (~$1.15 million)',
                'ransomware_strain': 'Rhysida'},
 'references': [{'source': 'California Attorney General'}],
 'regulatory_compliance': {'regulatory_notifications': 'Filed with the '
                                                       'California attorney '
                                                       'general'},
 'response': {'communication_strategy': 'Notified affected individuals via '
                                        'letters filed with the California '
                                        'attorney general'},
 'threat_actor': 'Rhysida',
 'title': 'Bellflower Unified School District Hit by Rhysida Ransomware Attack',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.