{"id":1186,"date":"2026-08-20T11:19:52","date_gmt":"2026-08-20T05:49:52","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1186"},"modified":"2026-08-20T11:21:51","modified_gmt":"2026-08-20T05:51:51","slug":"school-district-cyberattack-retained-credentials-admin-access-abuse","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/","title":{"rendered":"Ex-school district employee jailed for hacks on former employer"},"content":{"rendered":"<p>A former Iowa school district IT employee has been sentenced to prison. Prosecutors said he retained access credentials and used them to carry out a prolonged school district cyberattack against his former employer over nearly two years.<\/p>\n<p>According to court records, the school district cyberattack disrupted critical educational and administrative services. The affected systems included identity accounts, learning platforms, and device-management platforms.<\/p>\n<p>The case highlights a persistent enterprise security challenge. Former employees who retain privileged access can create significant operational and financial consequences long after they leave an organization.<\/p>\n<p>For IT and security leaders, the school district cyberattack serves as a reminder that effective offboarding extends beyond disabling a user account. Credential revocation, privileged-access reviews, and continuous monitoring remain critical security controls.<\/p>\n<h2>How the Attack Unfolded<\/h2>\n<p>The reported activity was an example of identity and privileged-access abuse rather than a malware-driven attack. Prosecutors said the former employee retained access credentials after leaving the organization and used them to access multiple administrative systems over an extended period.<\/p>\n<p>The affected services reportedly included:<\/p>\n<ul>\n<li>Facebook administration<\/li>\n<li>Apple School Manager<\/li>\n<li>GoDaddy<\/li>\n<li>Google administrator accounts<\/li>\n<li>Gmail accounts<\/li>\n<li>Schoology<\/li>\n<\/ul>\n<p>The school district cyberattack targeted administrative functions across these platforms, allowing the former employee to delete accounts, modify access, and disrupt day-to-day operations. Rather than exploiting software vulnerabilities, the activity relied on access that should have been revoked during the offboarding process.<\/p>\n<p>The reported Apple School Manager disruption is particularly notable because the platform serves as a central administrative layer for Apple devices in education environments. Prosecutors said the former employee deleted user accounts, passwords, phone numbers, billing information, and device-management server data. As a result, staff lost access to the platform, and device-management operations remained disrupted for approximately one week.<\/p>\n<p>The case illustrates how a compromised or improperly managed administrative account can create organization-wide consequences. When privileged identities maintain access to cloud services, learning platforms, and device-management infrastructure, a single account can become a gateway to widespread operational disruption.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-uem-for-education.webp?format=webp\" class=\"resource-box__image\" alt=\"hexnode-uem-for-education\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-uem-for-education.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-uem-for-education-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-uem-for-education-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-uem-for-education-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"hexnode-uem-for-education\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode UEM for Education\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Get started with Hexnode\u2019s device management solution for the education industry\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/datasheets\/hexnode-uem-for-education\/'>\n                            Get the Datasheet\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How Hexnode Can Strengthen Offboarding and Access Control<\/h2>\n<p>Incidents like this highlight the importance of combining endpoint management, access governance, and security monitoring to reduce the risk of insider or post-employment misuse.<\/p>\n<p>With <a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a>, IT teams can maintain visibility into managed devices, enforce security policies, execute remote actions such as device lock and wipe, and monitor device compliance across supported endpoints, including macOS and iPadOS devices. These capabilities help organizations maintain control over corporate assets when employees leave or administrative responsibilities change.<\/p>\n<p>From a security operations perspective, <a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> provides centralized visibility for threat detection, investigation, and response. By correlating security signals across managed endpoints and consolidating alerts into a single platform, security teams can identify suspicious activity more efficiently and accelerate incident response workflows.<\/p>\n<p>In scenarios involving former employees or privileged-user abuse, organizations should focus on:<\/p>\n<ul>\n<li>Immediate revocation of administrative access during offboarding<\/li>\n<li>Regular reviews of privileged accounts and role assignments<\/li>\n<li>Continuous monitoring for unusual administrative activity<\/li>\n<li>Rapid investigation of unauthorized account modifications or deletions<\/li>\n<li>Maintaining visibility across both endpoint and security telemetry<\/li>\n<\/ul>\n<p>While no single control can eliminate insider risk, combining strong offboarding processes with endpoint management and security monitoring can significantly reduce the likelihood and impact of credential-based abuse.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-Ultimate-Guide-to-XDR-Extended-Detection-and-Response-2.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>The Ultimate Guide to XDR (Extended Detection and Response)<\/h4><p>XDR unifies security data to detect threats faster and automate response from a single platform.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/xdr-extended-detection-and-response\/\" aria-label=\"The Ultimate Guide to XDR (Extended Detection and Response)\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Conclusion<\/h2>\n<p>The Saydel case underscores a security reality that extends far beyond the education sector. Identity offboarding, privileged-access governance, and administrative oversight are foundational security controls.<\/p>\n<p>The incident shows how retained credentials and unmanaged administrative access can create long-term operational risk. That risk can persist even after an employee leaves the organization. When privileged accounts remain active or go unmonitored, a single identity can disrupt critical services, delete data, and impair management capabilities across multiple platforms.<\/p>\n<p>For IT and security leaders, the takeaway is clear. Access revocation must be immediate, verifiable, and consistently enforced across all systems. Regular privileged-access reviews can help identify unnecessary permissions. Credential rotation, audit logging, and continuous monitoring can further reduce the risk of unauthorized access.<\/p>\n<p>Organizations should assume that administrative credentials may persist beyond employment. To reduce that risk, offboarding processes should be automated, audited, and continuously monitored. The longer privileged access remains unchecked, the greater the potential operational and security impact.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f <\/h5><p>Stay ahead of emerging cyber threats with expert insights on endpoint security, identity protection, and IT operations.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A former Iowa school district IT employee has been sentenced to prison. Prosecutors said he&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1187,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,17],"class_list":["post-1186","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-macos","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ex-school district employee jailed for hacks on former employer<\/title>\n<meta name=\"description\" content=\"Former IT employee sentenced after a school district cyberattack involving retained credentials and admin account abuse.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ex-school district employee jailed for hacks on former employer\" \/>\n<meta property=\"og:description\" content=\"Former IT employee sentenced after a school district cyberattack involving retained credentials and admin account abuse.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-20T05:49:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-20T05:51:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/school-district-cyberattack.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Ex-school district employee jailed for hacks on former employer\",\"datePublished\":\"2026-08-20T05:49:52+00:00\",\"dateModified\":\"2026-08-20T05:51:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/\"},\"wordCount\":697,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/school-district-cyberattack.webp?format=webp\",\"articleSection\":[\"Identity Abuse\",\"macOS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/\",\"name\":\"Ex-school district employee jailed for hacks on former employer\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/school-district-cyberattack.webp?format=webp\",\"datePublished\":\"2026-08-20T05:49:52+00:00\",\"dateModified\":\"2026-08-20T05:51:51+00:00\",\"description\":\"Former IT employee sentenced after a school district cyberattack involving retained credentials and admin account abuse.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/school-district-cyberattack.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/school-district-cyberattack.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"school-district-cyberattack\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/school-district-cyberattack-retained-credentials-admin-access-abuse\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ex-school district employee jailed for hacks on former employer\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ex-school district employee jailed for hacks on former employer","description":"Former IT employee sentenced after a school district cyberattack involving retained credentials and admin account abuse.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/","og_locale":"en_US","og_type":"article","og_title":"Ex-school district employee jailed for hacks on former employer","og_description":"Former IT employee sentenced after a school district cyberattack involving retained credentials and admin account abuse.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-20T05:49:52+00:00","article_modified_time":"2026-08-20T05:51:51+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/school-district-cyberattack.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Ex-school district employee jailed for hacks on former employer","datePublished":"2026-08-20T05:49:52+00:00","dateModified":"2026-08-20T05:51:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/"},"wordCount":697,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/school-district-cyberattack.webp?format=webp","articleSection":["Identity Abuse","macOS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/","url":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/","name":"Ex-school district employee jailed for hacks on former employer","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/school-district-cyberattack.webp?format=webp","datePublished":"2026-08-20T05:49:52+00:00","dateModified":"2026-08-20T05:51:51+00:00","description":"Former IT employee sentenced after a school district cyberattack involving retained credentials and admin account abuse.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/school-district-cyberattack.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/school-district-cyberattack.webp?format=webp","width":1024,"height":535,"caption":"school-district-cyberattack"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/school-district-cyberattack-retained-credentials-admin-access-abuse\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Ex-school district employee jailed for hacks on former employer"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1186"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1186\/revisions"}],"predecessor-version":[{"id":1193,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1186\/revisions\/1193"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1187"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}