Your child’s school data was breached. What to do.
School records carry the two things that make a child worth stealing: a Social Security number and a date of birth, neither of which can be reset. Here is what actually protects them, starting with a free step most parents have never been told about.
If a Social Security number was in the exposed records, freeze your child’s credit file at Equifax, Experian and TransUnion — it is free for minors, it blocks new accounts, and it can stay frozen for years. Then check that no credit file already exists in their name, reset the school-portal password everywhere it was reused, opt out of FERPA directory information at the school office, and take the household off people-search sites. Your own details were almost certainly in the same file.
1. Work out what was exposed, and by whom
Read the notice for the list of data categories. A leaked school email address is a nuisance; a date of birth paired with a Social Security number is the combination that makes child identity theft possible, and those two cannot be changed. Note whether the breach was at the district itself or at a software vendor it uses — it does not change your steps, but it tells you how many other families are in the same position and whether more notices are coming.
2. Freeze your child’s credit — this is the one that matters
If a Social Security number was involved, this is the highest-value thing you can do, and it is free. Federal law lets a parent or guardian have a credit file created for a minor and immediately frozen at Equifax, Experian and TransUnion. Frozen, the number cannot be used to open a new account, which is exactly what makes children attractive targets. You will need ID and proof of guardianship, and you have to do all three bureaus separately. Then leave it frozen — a child has no reason to apply for credit for a decade.
3. Check whether the data is already being used
For a child, the correct result from each credit bureau is “no file found”. Anything else means someone has been using the number. The everyday warning signs come by post: pre-approved card offers addressed to a young child, debt collection letters, an IRS notice about a return already filed against that Social Security number, or a benefits claim rejected as a duplicate. If any of that turns up, report it at IdentityTheft.gov, which generates the recovery plan and the affidavit the bureaus and lenders will ask for.
4. Reset the portal password and break the reuse chain
School portals, meal accounts, learning platforms and homework apps tend to share one password per child, often a simple one set years ago by whoever registered the account. Change it on the affected system and everywhere the same password was used, and turn on two-factor authentication where the platform supports it. If you want to know whether a particular password is already circulating in leaked data, our password check tests it against known breach databases without the password ever leaving your device in readable form.
5. Cut what the school hands out by default
Separate from any breach, FERPA lets schools release “directory information” — commonly name, address, phone number, date of birth, photographs and activities — to third parties unless you opt out in writing. The annual notice explaining this usually arrives in the enrollment pack in August and gets signed unread. Ask the office for the directory information form and restrict it. While you are there, ask which outside platforms hold your child’s records and whether the district has a data-retention policy for students who have left; both questions are ones schools are obliged to answer and rarely get asked.
6. Expect the scams that follow a school breach
Breach news is a gift to scammers because it gives them a real event to reference. The recurring ones: an urgent message about an unpaid school lunch or activity balance with a payment link, a fake “identity protection enrollment” page collecting the exact data that leaked, and calls to grandparents that use a child’s real name and school. Verify anything money-related through the school’s own published number, never a number or link inside the message, and warn the grandparents specifically — they are the ones targeted with the family details.
7. Take the family off people-search sites
The leaked school file is out of reach. What is still reachable is the public layer: data brokers and people-search sites that publish your address, phone, relatives and household members, and that list children by name and age often enough to matter. That is the material that turns a breach notice into a convincing phone call. Our guide to removing your child’s information covers the family-tree and people-search sites specifically, and the data-broker opt-out guide has the free, site-by-site route for the household.
Check what is public about your household
PersProtect finds where your family’s address, phone and relatives are listed across 499 broker and people-search sites, removes them, and keeps re-checking as listings come back. Start with a free scan.
Check my exposure — free →Education breaches in our database
Schools, districts, colleges and the software vendors behind them, as recorded in known breach databases. Each page lists the exposed data categories and lets you check whether your address is in it.
School breaches, answered for parents
Why would anyone want a seven-year-old’s data?
Because it is clean and nobody is watching it. A child has a Social Security number with no credit history attached, so it can be paired with a fake date of birth to open accounts that look new rather than fraudulent. Nothing bounces, nobody gets a statement, and the damage is usually found years later when the child applies for a first card, a student loan or a phone contract. That delay is the whole appeal.
Can I freeze my child’s credit if they have no credit file?
Yes. Federal law requires the bureaus to create a file for a minor and then freeze it, free of charge, at a parent or guardian’s request. You will need proof of your identity and of your relationship to the child — usually a birth certificate and a copy of your ID. Do it at Equifax, Experian and TransUnion separately, because a freeze at one does nothing at the other two. It stays until you lift it, so it can simply sit there until the child is old enough to need credit.
The school says the breach was at a vendor, not at them. Does that change anything?
Not for you. Districts run on outside software — student information systems, transport and meal payment platforms, tutoring and testing tools — and a break-in at one of those reaches every district using it. The vendor is where the intrusion happened; the school is who holds the relationship with you and is responsible for notifying you. The data exposed is the same either way, and so are the steps.
What is directory information, and should I opt out of it?
Under FERPA, a school may publish a category called directory information without asking you first — typically name, address, phone number, date and place of birth, photographs, activities and awards. Schools must tell you annually and give you a window to opt out in writing. Opting out is worth it if you are concerned about exposure, but read the notice: opting out of everything can also pull your child from yearbooks, sports programs and graduation lists, so most parents restrict rather than block outright.
How do I check whether my child’s identity is already being used?
Request a credit report for the child from each bureau — for a minor, the correct answer is that no file exists. If one comes back with accounts on it, that is misuse, and you follow the identity-theft report process at IdentityTheft.gov. Warning signs before that: pre-approved credit offers arriving in a young child’s name, collection calls, a letter from the IRS about a duplicate return, or a benefits application rejected because the number is already in use.
Should my child change their school portal password?
Yes, and check where else it was used. Kids reuse a single password across the school portal, a game account, an email and a chat app more than adults do, so one leaked login tends to unlock several things. Change the portal password, change anywhere the same one was used, and turn on two-factor authentication anywhere the account matters.
Is my own data exposed when the school is breached?
Usually. Enrollment records carry the parent or guardian as the contact: name, home address, phone number, email, sometimes employment and financial details from meal-assistance or payment forms. Treat a school breach as a household breach rather than a child-only one, and check your own email against known breach databases as well.
The school file is gone. Your family’s public profile is not.
See which sites are publishing your address, phone and relatives right now — free, in about a minute.
Run a free exposure scan →