The Springfield Public Schools breach: what is confirmed, and what to do
The cyberattack that closed Springfield’s schools in September also stole student and staff data, the FBI has confirmed. The district does not yet know exactly what was taken. Here is what is known, what is only possible, and what parents and staff can do while they wait for a letter.
On 15 September 2026 the FBI told Springfield Public Schools in Massachusetts that a cybercriminal group had stolen student and staff data in the attack that closed the district from 8 to 11 September. Staff Social Security numbers may be included; the district says it does not normally store student Social Security numbers in those files. Nobody has said how many people are affected, and the data has not been published, so no website can check you against it. Parents should freeze their children’s credit at all three bureaus, which is free. Staff should enrol in the district’s free credit monitoring, freeze their credit and get an IRS Identity Protection PIN.
What is confirmed vs what is only possible
The middle column is what the district has said, including what the FBI told it. The right column is what officials say may be involved, what local reporting adds, and what the attackers claim. Read them separately: most of the alarming detail in coverage of this breach comes from the right column.
| Question | Confirmed | Possible, reported or claimed |
|---|---|---|
| That data was stolen | Yes. The FBI told the district on 15 September 2026 that a cybercriminal organisation had taken student and staff data during the attack. | Nothing disputed. The attack itself closed every school for a week before the theft was confirmed. |
| Whose data | Students and staff. The district has not said how many people or which years of records. | Local reporting says former staff, retirees and possibly former students may be in it too. The district has written to former employees. |
| Social Security numbers | Possibly for staff, not confirmed. The district says it does not normally keep student Social Security numbers in student data files. | Treat staff numbers as exposed until a letter says otherwise. |
| Other student details | Not listed. On 16 September the superintendent said it was still unclear what had been taken. | The superintendent said the data could include student addresses, ages, ethnicity and medical information. None of that is confirmed. |
| Who did it | Not named. Officials are withholding the group’s name while the FBI, state police and local police investigate. | Trackers that monitor ransomware leak sites listed the district under the Interlock group on 15 September. That is the group’s own claim. |
| Credit monitoring | Offered free to district personnel. Current employees are receiving letters explaining how to enrol; the district posts updates in an FAQ on its website. | No monitoring offer for students or families had been announced as of 24 September 2026. |
Sources: statements by Springfield Public Schools and the City of Springfield as reported by New England Public Media, The Boston Globe, NBC Boston and Western Mass News (15–16 September 2026), and WAMC (9 and 16 September 2026); ransomware leak-site trackers for the Interlock listing. Status as of 24 September 2026.
1. What happened, in order
Springfield Public Schools, the third-largest district in Massachusetts, found a cyberattack on its systems in the week of Labor Day. Classes were cancelled from Tuesday 8 September, and the mayor, Domenic Sarno, called it a Level 4, or severe, cyberattack. Schools reopened on Monday 14 September. The next afternoon the FBI told the district that this was also a data theft: a cybercriminal organisation had taken student and staff information. On 16 September the superintendent, Dr. Sonia Dinnall, said it was still unclear exactly what had been taken and asked families and staff to be very careful with their personal information.
2. What may be in the stolen files
Nothing has been confirmed field by field. According to the district, the data could include Social Security numbers for staff, plus student addresses, ages, ethnicity and medical information. For a family that means the file may link a child’s name to a home address and a health record, so a caller who has it can sound very official. Staff face a more familiar risk, because a Social Security number and a name are enough to open credit or file a fake tax return.
3. The honest answer to “are we affected”
There is no lookup for this breach. The files have not appeared in the known breach databases that email checkers search, so a clean result only means nothing has been indexed. The answer will come from the district once the investigation shows whose records were copied. Until then, if you are a current or former student, parent, employee or retiree of the district, assume your record may be in the file.
4. For parents: freeze your child’s credit now
A child’s identity is useful to criminals because nobody checks it. A Social Security number with no credit history can be used to open accounts that stay unnoticed until the child applies for a first loan or phone contract years later. Ask Equifax, Experian and TransUnion to create and freeze a file for your child. It is free, it takes a birth certificate and proof of guardianship, and it stays in place until you lift it. The security expert WAMC interviewed about this breach gave the same advice. Our guide for parents after a school breach covers the rest.
5. For staff and retirees: monitoring, a freeze and an IRS PIN
The district is offering free credit monitoring to its personnel, with letters explaining how to enrol. Monitoring tells you after something happens. A credit freeze at the three bureaus stops it from happening, so do both. Then request an IRS Identity Protection PIN, which blocks anyone else from filing a return with your Social Security number. Tax refund fraud is the most common thing criminals do with a stolen staff record. Retirees and former staff should make sure the district has a current mailing address.
6. The messages that come next
A school breach is usually followed by fake messages that use the school’s name: a letter asking you to confirm a child’s details, a text about a lunch balance or a bus pass, a call offering credit monitoring that first needs your Social Security number. The stolen file makes these more convincing because the sender may know your child’s name, school and address. Check anything that asks for information or money with the school directly. Our guide to telling a real breach letter from a fake shows what the real notice should look like when it arrives.
Your family’s address is already public elsewhere
You cannot search this breach. You can search the people-search sites that list your home address, phone number and household members, and those listings are where a convincing scam call usually starts. PersProtect checks 499 broker and people-search sites for your details, checks your email against known breach databases, and files the removals.
Check my exposure — free →The Springfield Public Schools breach, answered
Was my child’s data stolen in the Springfield Public Schools breach?
Possibly, and nobody can tell you for certain yet. The FBI has confirmed that student data was taken, but the district has not said which students, which years or which fields. The data has not been published anywhere public, so it is not in the breach databases an email check searches, and any website offering to look your child up against it is guessing. If your child attends or attended a Springfield public school, plan as if their record is in the file and wait for the district’s letter to narrow it down.
Were student Social Security numbers exposed?
The district says it is not its practice to keep student Social Security numbers in student data files, which is reassuring but not the same as a guarantee. The student details the superintendent said could be involved are addresses, ages, ethnicity and medical information. A child’s credit freeze costs nothing and protects against the worst outcome either way, so it is worth doing without waiting for certainty.
How do I freeze my child’s credit?
Contact Equifax, Experian and TransUnion separately and ask each to create and freeze a file for a minor. Federal law makes this free for children under 16 when a parent or guardian asks. You will need proof of your identity, the child’s birth certificate and Social Security card, and proof you are their parent or guardian. Most bureaus take the request by post or through an online upload. Once frozen, the file stays that way until you lift it.
I work for the district. What should I do first?
Enrol in the free credit monitoring when your letter arrives, then freeze your credit at all three bureaus, which stops new accounts being opened in your name. Request an Identity Protection PIN from the IRS so nobody can file a tax return with your Social Security number. If you have left the district or retired, check that the address the district has for you is current, because that is where the enrolment letter goes.
Who hacked Springfield Public Schools?
Officials have not said. The FBI told the district that a cybercriminal organisation was responsible, and the district is withholding the name while the investigation continues. Services that track ransomware leak sites listed Springfield Public Schools under the Interlock group on 15 September 2026, which is the group’s own claim rather than a confirmed attribution.
Will the stolen data be published?
It might be. Ransomware groups often post stolen files on their leak sites when a victim does not pay, and the district has not said whether a ransom was demanded. If files are published, they can be copied and passed around quickly. That is one more reason to freeze credit now: a freeze works whether or not the data ever surfaces.
Someone called saying they are from the school district. Is it real?
Hang up and call the school or district office on a number you already have. After a school breach the most common follow-up is a message or call that sounds official, asks you to confirm a child’s details, offers credit monitoring that needs your Social Security number, or asks for a payment. The real enrolment letter explains how to sign up for monitoring. It does not ask you to read out your details over the phone.
The school file is out. You can still shrink what is public.
See which people-search sites publish where your family lives and how to reach you. It is free and takes about a minute.
Run my free exposure scan →