Skip To Main Content

Logo Image

Logo Title

Community Notifications

Community Notification: Cyber Security Incident Updates

Notice of Incident Beginning August 2025

In early August, our District IT discovered anomalous activity within our network environment. In response to the event, District IT immediately began remediating, recovering, and rebuilding a secure network. Those efforts were completed successfully, safely, and securely. Additionally, we retained an independent third-party forensic team to analyze the occurrence and shed more light on the potential scope of impact. While the event rendered many of the District’s network services inoperable for a brief period, the District has since rectified all issues and remains fully operational.

At this point, we have a high degree of confidence that the network environment is safe and secure, as it is being continuously monitored, out of an abundance of caution. We also instituted several additional changes to security policies. There has not been evidence of any further anomalous activity.

The District’s assessment of the event is ongoing and nearing its conclusion. While the District continues to review its file directories, sensitive staff and student data is stored in separate externally hosted systems that were not impacted by the event. Nonetheless, we will continue to adhere to all local, state, and federal guidance where required and provide further guidance as needed.

We will continue to provide relevant updates as the assessment draws to a conclusion.

Cyber Security Incident Update June 12, 2026

The District’s assessment of the previously reported data security incident has concluded. The District determined that certain historical information stored in the impacted directory included sensitive information that could have been compromised. For reference, current student data is stored in Aeries, which was not impacted by the incident; however, there was evidence of impact on certain historical student, parent, and employee data stored on an impacted server.

Protecting the privacy and security of the information in our care is a responsibility we take very seriously; we apologize for any inconvenience this situation has caused you. We continue to maintain a high degree of confidence that the network environment is safe and secure because it is continuously monitored, out of an abundance of caution. There continues to be no further evidence of any further anomalous activity.

On June 12, 2026, notification letters will be mailed to individuals who may have been impacted by this incident by U.S. Mail, where the District has valid contact information. The District is also providing impacted individuals access to complimentary credit monitoring and identity theft protection services. More information on these services can be found in the letters received by the impacted individuals. We have also established a dedicated mailbox, CyberIncident@busd.k12.ca.us, should letter recipients have any inquiries. Letter recipients may also contact the dedicated call center telephone number listed in the notices. The District will continue to collaborate with law enforcement and adhere to all local, state, and federal guidance.

Overview