Washington and D.C. Public Schools: DCPS data breach potentially exposed students' names, addresses, birthdays

Washington and D.C. Public Schools: DCPS data breach potentially exposed students' names, addresses, birthdays

DC Public Schools Reports Potential Student Data Breach

Washington, D.C. Public Schools (DCPS) disclosed a data breach that may have exposed sensitive student information, including names, addresses, and identification numbers. The incident involved an unauthorized third party accessing a web-based application used for DCPS Summer Learning registration.

In a letter sent to families on Wednesday, DCPS confirmed that the breach was discovered during routine monitoring. Upon detection, the district immediately launched an investigation with support from the D.C. Office of the Chief Technology Officer (OCTO), removed student data from the affected application, and notified law enforcement.

The potentially compromised data includes:

  • Student names and identification numbers
  • Dates of birth
  • School and grade levels
  • Parent/guardian names
  • Home addresses
  • Phone numbers

While officials have not identified any misuse of the exposed information, they are implementing additional safeguards to prevent future incidents. DCPS is also reviewing its systems and processes to address vulnerabilities. Families were advised to monitor for suspicious communications requesting personal details. The district expressed regret over the incident and reaffirmed its commitment to strengthening data security measures.

Source: https://www.nbcwashington.com/news/local/dcps-data-breach-potentially-exposed-students-names-addresses-birthdays/4136249/

DC Office of the State Superintendent of Education (OSSE) cybersecurity rating report: https://www.rankiteo.com/company/osse

"id": "OSS1785422972",
"linkid": "osse",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Students and their families',
                        'industry': 'Education',
                        'location': 'Washington, D.C.',
                        'name': 'Washington, D.C. Public Schools (DCPS)',
                        'type': 'Educational Institution'}],
 'attack_vector': 'Unauthorized access to a web-based application',
 'customer_advisories': 'Families advised to monitor for suspicious '
                        'communications requesting personal details',
 'data_breach': {'personally_identifiable_information': 'Student names, '
                                                        'identification '
                                                        'numbers, dates of '
                                                        'birth, school and '
                                                        'grade levels, '
                                                        'parent/guardian '
                                                        'names, home '
                                                        'addresses, phone '
                                                        'numbers',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Personally Identifiable '
                                             'Information (PII)'},
 'description': 'Washington, D.C. Public Schools (DCPS) disclosed a data '
                'breach that may have exposed sensitive student information, '
                'including names, addresses, and identification numbers. The '
                'incident involved an unauthorized third party accessing a '
                'web-based application used for DCPS Summer Learning '
                'registration.',
 'impact': {'data_compromised': 'Student names, identification numbers, dates '
                                'of birth, school and grade levels, '
                                'parent/guardian names, home addresses, phone '
                                'numbers',
            'identity_theft_risk': 'High',
            'systems_affected': 'Web-based application for DCPS Summer '
                                'Learning registration'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Strengthening data security '
                                                  'measures'},
 'references': [{'source': 'DCPS Letter to Families'}],
 'response': {'communication_strategy': 'Letter sent to families',
              'containment_measures': 'Removed student data from the affected '
                                      'application',
              'enhanced_monitoring': 'Additional safeguards to prevent future '
                                     'incidents',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes',
              'remediation_measures': 'Reviewing systems and processes to '
                                      'address vulnerabilities',
              'third_party_assistance': 'D.C. Office of the Chief Technology '
                                        'Officer (OCTO)'},
 'title': 'DC Public Schools Reports Potential Student Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.