2026 Frontline Education — third-party app vuln; school employee SSNs/emails/addresses
Data compromised
Social Security numbers, email addresses, and physical addresses of school district employees (district notices via BC); nationwide census unpublished
Technical writeup
Verified company notices to school districts — Frontline Education identified on August 14, 2026 a vulnerability in a third-party software product that allowed unauthorized access; remediated with independent forensics and law enforcement engagement. District letters (BleepingComputer Oct 2, 2026; r/k12sysadmin) describe employee SSNs, emails, and addresses; one district cited 1,210 local employees. Frontline offers 2-year TransUnion/Cyberscout monitoring and will notify individuals unless districts opt out by Oct 16 via frontline-transunion.com / 833-516-8792. Nationwide person census unpublished — recordsAffected 0. companyConfirmed true.
Root cause
Vulnerability in a third-party software product used by Frontline allowed unauthorized access to a portion of its environment (company notice to districts)