School and college data breaches: what to do next.
School and college files hold the two things that cannot be reset — a Social Security number and a date of birth. Which is why a child’s stolen details stay useful for a decade, while a student’s tend to get used within months. The steps are different for each, so this guide is in two parts.
If a Social Security number was in the exposed records, a credit freeze is the step that actually blocks harm — a parent has one created and frozen for a minor at Equifax, Experian and TransUnion, and an adult student does the same for their own file. From there the paths split: for a child, check that no credit file already exists, opt out of FERPA directory information and take the household off people-search sites; for a college student, read the award history at studentaid.gov, get an IRS Identity Protection PIN and confirm the registrar still holds your real address. Either way, reset the portal password everywhere it was reused.
If your child’s school or district was breached
For a minor the danger is patience: the details sit unused until the child applies for their first card or loan, which is why the fix is a freeze rather than a watch.
1. Work out what was exposed, and by whom
Read the notice for the list of data categories. A leaked school email address is a nuisance; a date of birth paired with a Social Security number is the combination that makes child identity theft possible, and those two cannot be changed. Note whether the breach was at the district itself or at a software vendor it uses — it does not change your steps, but it tells you how many other families are in the same position and whether more notices are coming.
2. Freeze your child’s credit — this is the one that matters
If a Social Security number was involved, this is the highest-value thing you can do, and it is free. Federal law lets a parent or guardian have a credit file created for a minor and immediately frozen at Equifax, Experian and TransUnion. Frozen, the number cannot be used to open a new account, which is exactly what makes children attractive targets. You will need ID and proof of guardianship, and you have to do all three bureaus separately. Then leave it frozen — a child has no reason to apply for credit for a decade.
3. Check whether the data is already being used
For a child, the correct result from each credit bureau is “no file found”. Anything else means someone has been using the number. The everyday warning signs come by post: pre-approved card offers addressed to a young child, debt collection letters, an IRS notice about a return already filed against that Social Security number, or a benefits claim rejected as a duplicate. If any of that turns up, report it at IdentityTheft.gov, which generates the recovery plan and the affidavit the bureaus and lenders will ask for.
4. Reset the portal password and break the reuse chain
School portals, meal accounts, learning platforms and homework apps tend to share one password per child, often a simple one set years ago by whoever registered the account. Change it on the affected system and everywhere the same password was used, and turn on two-factor authentication where the platform supports it. If you want to know whether a particular password is already circulating in leaked data, our password check tests it against known breach databases without the password ever leaving your device in readable form.
5. Cut what the school hands out by default
Separate from any breach, FERPA lets schools release “directory information” — commonly name, address, phone number, date of birth, photographs and activities — to third parties unless you opt out in writing. The annual notice explaining this usually arrives in the enrollment pack in August and gets signed unread. Ask the office for the directory information form and restrict it. While you are there, ask which outside platforms hold your child’s records and whether the district has a data-retention policy for students who have left; both questions are ones schools are obliged to answer and rarely get asked.
6. Expect the scams that follow a school breach
Breach news is a gift to scammers because it gives them a real event to reference. The recurring ones: an urgent message about an unpaid school lunch or activity balance with a payment link, a fake “identity protection enrollment” page collecting the exact data that leaked, and calls to grandparents that use a child’s real name and school. Verify anything money-related through the school’s own published number, never a number or link inside the message, and warn the grandparents specifically — they are the ones targeted with the family details.
7. Take the family off people-search sites
The leaked school file is out of reach. What is still reachable is the public layer: data brokers and people-search sites that publish your address, phone, relatives and household members, and that list children by name and age often enough to matter. That is the material that turns a breach notice into a convincing phone call. Our guide to removing your child’s information covers the family-tree and people-search sites specifically, and the data-broker opt-out guide has the free, site-by-site route for the household.
If your college or university was breached
A college file is a thicker file: government ID numbers, financial-aid history and academic records, all tied to an adult who can be charged, billed and enrolled today rather than in ten years.
1. If a government ID number leaked, freeze your own credit
College files hold more than school files do. Enrollment, financial aid and international-student paperwork put a Social Security or other government ID number next to your date of birth and address, and that pairing is what lets someone open an account as you. As an adult you freeze your own file at Equifax, Experian and TransUnion — free, online, all three separately, and reversible in minutes with a PIN when you actually need credit. A freeze blocks new accounts outright; monitoring only tells you afterwards.
2. Lock down financial aid before someone applies as you
Stolen student identities get used to claim aid, and colleges are a known target for it. Sign in at studentaid.gov, change your FSA ID password, turn on two-factor authentication, and read the award history for applications or disbursements you did not make. If something is there, report it to the school’s financial aid office and to the Federal Student Aid feedback centre — the school can stop a disbursement in progress, which nobody else can. Getting an IRS Identity Protection PIN is worth doing in the same sitting, because a stolen Social Security number tends to be tried on a tax return next.
3. Check your academic record for changes, not just leaks
Academic records were in several of the 2026 college breaches, and the risk is not only that someone reads your transcript. Ask the registrar for a copy of your record and confirm the basics still match: your enrollment status, your contact address, and where transcripts have been sent. A changed mailing address on file is the quiet step that redirects everything else, and it is the kind of edit nobody notices until a document goes missing. While you are there, ask whether the breach reached the third-party platform the school uses for transcripts and verification, because that is usually where the copy lives.
4. Expect tuition and refund scams on the .edu address
A leaked student email plus a real term date is enough to build a convincing message: an unpaid tuition balance with a payment link, a refund waiting on a form, a housing deposit that has to clear today, or a campus-job offer that starts with a cheque you are asked to deposit and partly forward. Verify anything about money through the bursar’s published number or the student portal you typed in yourself. And change the portal password everywhere you reused it — a student email is often the recovery address for a bank, so it is worth more than it looks.
Check what is public about your household
PersProtect finds where your family’s address, phone and relatives are listed across 499 broker and people-search sites, removes them, and keeps re-checking as listings come back. Start with a free scan.
Check my exposure — free →Education breaches in our database
Schools, districts, colleges and the software vendors behind them, as recorded in known breach databases. Each page lists the exposed data categories and lets you check whether your address is in it.
School and college breaches, answered
Why would anyone want a seven-year-old’s data?
Because it is clean and nobody is watching it. A child has a Social Security number with no credit history attached, so it can be paired with a fake date of birth to open accounts that look new rather than fraudulent. Nothing bounces, nobody gets a statement, and the damage is usually found years later when the child applies for a first card, a student loan or a phone contract. That delay is the whole appeal.
Can I freeze my child’s credit if they have no credit file?
Yes. Federal law requires the bureaus to create a file for a minor and then freeze it, free of charge, at a parent or guardian’s request. You will need proof of your identity and of your relationship to the child — usually a birth certificate and a copy of your ID. Do it at Equifax, Experian and TransUnion separately, because a freeze at one does nothing at the other two. It stays until you lift it, so it can simply sit there until the child is old enough to need credit.
The school says the breach was at a vendor, not at them. Does that change anything?
Not for you. Districts run on outside software — student information systems, transport and meal payment platforms, tutoring and testing tools — and a break-in at one of those reaches every district using it. The vendor is where the intrusion happened; the school is who holds the relationship with you and is responsible for notifying you. The data exposed is the same either way, and so are the steps.
What is directory information, and should I opt out of it?
Under FERPA, a school may publish a category called directory information without asking you first — typically name, address, phone number, date and place of birth, photographs, activities and awards. Schools must tell you annually and give you a window to opt out in writing. Opting out is worth it if you are concerned about exposure, but read the notice: opting out of everything can also pull your child from yearbooks, sports programs and graduation lists, so most parents restrict rather than block outright.
How do I check whether my child’s identity is already being used?
Request a credit report for the child from each bureau — for a minor, the correct answer is that no file exists. If one comes back with accounts on it, that is misuse, and you follow the identity-theft report process at IdentityTheft.gov. Warning signs before that: pre-approved credit offers arriving in a young child’s name, collection calls, a letter from the IRS about a duplicate return, or a benefits application rejected because the number is already in use.
Should my child change their school portal password?
Yes, and check where else it was used. Kids reuse a single password across the school portal, a game account, an email and a chat app more than adults do, so one leaked login tends to unlock several things. Change the portal password, change anywhere the same one was used, and turn on two-factor authentication anywhere the account matters.
I am the student, not a parent. Is the advice different?
Yes, in the parts that matter. A minor gets a credit file created and frozen by a parent, and the harm shows up years later. An adult student freezes their own file, and the harm tends to arrive within months, through financial aid claimed in their name, a tax return filed against their Social Security number, or an account opened with the ID number that sat in their enrollment record. The college-specific steps are the ones nobody thinks of: check your award history at studentaid.gov, get an IRS Identity Protection PIN, and confirm the registrar still has your real mailing address on file.
Someone applied for financial aid in my name. What do I do?
Start with the school, not the federal system. Call the financial aid office, tell them the application is not yours, and ask them to flag the account — a school can stop a disbursement that is still in progress, which is the only step that is time-sensitive. Then report it to Federal Student Aid, file an identity theft report at IdentityTheft.gov to get the affidavit lenders and bureaus will ask for, and freeze your credit at all three bureaus so the same details cannot be used elsewhere. Keep the case numbers; aid fraud takes several rounds of paperwork to unwind.
The college says only academic records leaked. Does that matter?
It is better than an ID number, but it is not nothing. Academic records usually travel with the enrollment data around them — dates of birth, addresses, student ID numbers, sometimes citizenship or visa status — and that is a ready-made script for someone pretending to be the registrar, a scholarship body or an immigration adviser. Read the notice for the exact list rather than the summary line, because the categories are what decide whether you need a credit freeze or just a sharper eye on your inbox.
Is my own data exposed when the school is breached?
Usually. Enrollment records carry the parent or guardian as the contact: name, home address, phone number, email, sometimes employment and financial details from meal-assistance or payment forms. Treat a school breach as a household breach rather than a child-only one, and check your own email against known breach databases as well.
The school file is gone. Your family’s public profile is not.
See which sites are publishing your address, phone and relatives right now — free, in about a minute.
Run a free exposure scan →