← Seesaw Learning

2022 Seesaw — credential-stuffing wave abused parent accounts to send malicious messages

2022 Unknown records affected Share on X

Data compromised

Messaging integrity and contact graph exposure; full victim row count not standardized in press

Technical writeup

Seesaw, a widely used K–5 learning and family-messaging platform, responded to September 2022 reports that attackers leveraged username/password pairs recycled from unrelated breaches (credential stuffing) to hijack a limited set of guardian accounts and push inappropriate image links inside classroom messaging threads. Seesaw temporarily disabled messaging, forced resets on impacted logins, and emphasized salted password storage plus available MFA—framing the abuse as account takeover rather than a core database compromise.

Root cause

Credential stuffing against reused passwords on Seesaw accounts

References