2022 Seesaw — credential-stuffing wave abused parent accounts to send malicious messages
Data compromised
Messaging integrity and contact graph exposure; full victim row count not standardized in press
Technical writeup
Seesaw, a widely used K–5 learning and family-messaging platform, responded to September 2022 reports that attackers leveraged username/password pairs recycled from unrelated breaches (credential stuffing) to hijack a limited set of guardian accounts and push inappropriate image links inside classroom messaging threads. Seesaw temporarily disabled messaging, forced resets on impacted logins, and emphasized salted password storage plus available MFA—framing the abuse as account takeover rather than a core database compromise.
Root cause
Credential stuffing against reused passwords on Seesaw accounts