
Permanent Record: How School Data Breaches Put Your Child's Identity on the Market
About this episode
Public schools have become one of the softest, highest-value targets in the ransomware economy. They hold enormous amounts of sensitive data on children, run on tight budgets with little security staff, and depend on third-party vendors that keep getting breached. This episode maps the current threat landscape: the PowerSchool breach that exposed roughly 62 million students and 9.5 million teachers, the Canvas breach that became the largest education breach on record, the always-on monitoring software watching half the students in the country, and the collapse of the federal support that many districts relied on. Then it covers what districts have to do and, more importantly, what parents and students can actually control. The single highest-leverage action for a parent: freeze your child's credit.
Defenses and Resources
For districts (CISA guidance):
- Protecting Our Future: Cybersecurity for K-12 (CISA)
- Cybersecurity for K-12 Education (CISA)
- K-12 Ransomware Resources (CISA StopRansomware)
- K-12 Cyber Incident Map (K12 SIX)
For parents and students:
- How to protect your child from identity theft, including freezing a child's credit (FTC)
- FERPA and your rights over education records (U.S. Dept. of Education)
- Children's privacy and COPPA (FTC)
Priority Actions
1. Freeze your child's credit at all three bureaus (Equifax, Experian, TransUnion). Free, and it blocks new accounts opened with a stolen SSN.
2. Treat any breach notice as real. Take the free monitoring, but know the freeze is what actually prevents fraud.
3. Ask your district what SIS, LMS, and monitoring software it uses, what data each holds, and for how long.
4. Use the opt-outs you already have (FERPA directory information; COPPA protections for younger kids).
5. Decline optional apps and accounts. You cannot leak what was never collected.
6. Talk to your kid: a school device is not private, and what they type on it is recorded.
If your child is in school, freeze their credit this week. It is free, it takes about an hour across the three bureaus, and it closes the exact door a data breach opens. Do that first.
Then send one email to your district and ask three questions: what student information system do you use, what monitoring software runs on my child's device, and how long is my child's data retained. You are entitled to ask, and asking tells them parents are paying attention.
Head to OPSECPodcast.com for the full episode and every link.
Your privacy and your security is your responsibility.
Get every episode summarized
Each time The OPSEC Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The OPSEC Podcast

Know Your Enemy: The Border Phone Wipe and the Adversary We Actually Fight
The OPSEC Podcast

Follow the Money: The Complete Surveillance Picture Built by Your Payment Histor...
The OPSEC Podcast

Podcast Update: What's New, What's Not, and What's Next
The OPSEC Podcast

The Smart Home Is a Listening Post: Amazon, Google, and the Surveillance You Pai...
The OPSEC Podcast