Frontline Education Data Breach Exposes Employee Social Security Numbers
Frontline Education is notifying school districts of a data breach after an attacker exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers.
Frontline Education is an edtech company that provides administrative and workforce management software and services for school districts.
Third-party software vulnerability led to unauthorized access
A reader shared Frontline’s data breach notification with BleepingComputer. The notice states that the attacker entered the company’s environment through a vulnerability in a third-party application.
“On August 14, 2026, our security team identified a vulnerability in a third-party software product we use that could allow unauthorized access to a portion of our environment,” the notice reads.
“We quickly investigated this issue with the help of an independent cybersecurity firm, remediated the vulnerability, worked with law enforcement, and took steps to further strengthen the security of our systems.”
Frontline did not identify the third-party application involved or disclose when the unauthorized access first began.
Employee Social Security numbers and addresses compromised
According to a notification seen by BleepingComputer, all employees within at least one affected district were impacted. The compromised information included Social Security numbers, email addresses, and physical addresses.
BleepingComputer contacted Frontline Education about the breach, but the company did not respond to an email.
School district IT administrators also reported receiving similar notices in the K12SysAdmin subreddit.
One administrator initially said that a supervisor and business manager received a notification from [email protected] on October 1. At the time, Frontline Support had not verified whether the message was legitimate.
Other administrators later said they independently verified that the breach notices were authentic.
“I can confirm that this is legitimate. I have had verbal communication with Frontline personnel regarding this matter,” one administrator reported.
One administrator also shared a copy of a Frontline notice stating that 1,210 employees associated with the district were affected. The notice said their Social Security numbers, email addresses, and physical addresses had been compromised.
Frontline offers credit monitoring and identity protection
Frontline says it will process notifications to affected individuals on behalf of school districts unless a district opts out by October 16.
Districts that wish to opt out can do so through www.frontline-transunion.com or by calling 833-516-8792. If a district opts out, Frontline says it will not provide notification services or reimburse the district for the cost of issuing its own notifications.
Affected adults will receive two years of free credit monitoring and identity theft protection through TransUnion. Minors will receive cyber monitoring services.
Frontline also says it will process the required notifications to state attorneys general and cover the costs associated with individual notifications and privacy services.
Number of affected districts remains unknown
The total number of affected school districts and individuals has not been disclosed.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



