社区黑料

Explore

Cyberattack Hits South Carolina School Choice Program

Hackers gained access to some education vendors鈥� banking information before state officials intervened to lock down the system.

The South Carolina Department of Education was still working this week to restore access to accounts in the state鈥檚 education savings account program following a security breach last month. (South Carolina Department of Education, Facebook)

South Carolina鈥檚 was the target of an email scam late last month in which hackers, impersonating the state education agency or a widely used payment platform, tried to obtain vendors鈥� banking information.

The phishing attempt went to service providers like Bridget Deline, who runs Upward Learning Center, a Montessori-style program and tutoring center in Columbia. 鈥淭his can devastate us enough to where we won’t even be able to function,鈥� she said. 鈥淚鈥檓 literally thousands of dollars out of funding.鈥�

The breach came just days before the U.S. Treasury Department released rules聽for a nationwide school choice program funded by taxpayer donations that will operate in much the same way, with hundreds of nonprofits collecting data and distributing scholarships. It underscores the need for greater security in such programs, with one expert calling it a 鈥渨arning shot.鈥�

鈥淚f the future is more ESA-type programs rolling out across states or nationally, it would be important to see strong controls to make sure dollars are going to the places they鈥檙e supposed to go,鈥� said Doug Levin, national director of K12 Security Information Exchange, a nonprofit focusing on cybersecurity in education.

The South Carolina Department of Education, which runs the Education Scholarship Trust Fund program, notified vendors of the attack on Sept. 25 and instructed them to reset passwords for both their email and the ClassWallet platform. The department and ClassWallet temporarily locked down the system to conduct a 鈥渞isk assessment,鈥� state spokeswoman Christy Cox told 社区黑料. That meant vendors couldn鈥檛 receive funds and parents were not able to see those businesses listed online or upload invoices for tuition, classes or tutoring.

The disruption 鈥渟hut down our entire ClassWallet operations,鈥� one vendor wrote in a Facebook group, noting that he even missed out on orders from families in other states that also use ClassWallet. 

The department restored accounts to 鈥渘ormal operation,鈥� Cox said, once they were 鈥渄etermined to present a low risk.鈥� 

On Tuesday, Deline said she and her students鈥� parents were still waiting to regain access to the system. The incident has also affected her confidence in the program. She has received updates from the department, but said she was questioning whether they were 鈥渓egitimate.鈥�

With $210 million allocated over three years, South Carolina鈥檚 Education Scholarship Trust Fund is one of more than 20 education savings accounts programs in the U.S. that award funds to families for either private school or other education expenses. South Carolina鈥檚 scholarship is set at $7,634 this year. 

The phishing attempt wasn鈥檛 unique. It was the same type of scam often tried in public schools, Levin said.

鈥淚t鈥檚 about trying to trick school business officials to send otherwise authorized payments to the wrong place,鈥� he said. Hackers will sometimes research the names of district business officials. 鈥淭hey might even be able to break into their e-mail and literally jump into the middle of a chain discussion going back and forth.鈥�

In this case, instead of parents sending funds to a vendor鈥檚 account through the ClassWallet platform, 鈥渢hey鈥檙e sending it to the criminal鈥檚 account,鈥� Levin said. 

It鈥檚 unclear how many vendors actually clicked on the deceptive link that prompted them to enter their banking information or how much the hackers were able to withdraw. 

鈥淭he department will not know the full scope of the impact on [providers] until the verification of all affected bank account information has been completed,鈥� Cox said. 鈥淭hat process remains ongoing.鈥�

Officials told vendors they were also working with ClassWallet to 鈥渋mplement additional safeguards against similar attempts in the future.鈥� According to its , eight states use the company to manage their ESA programs.

鈥楶artially successful鈥�

Levin said he was unaware of a similar cyberattack affecting another private school choice program, but encouraged those running these systems to add extra layers of security. 

鈥淚f we’ve seen this in one place and it has been at least partially successful, the odds are very high that other programs where money is being distributed in this sort of a scheme are likely to be targeted,鈥� he said.

There have been data leaks affecting other school choice programs.

Earlier this year, the acknowledged that it posted, by mistake, a list of students enrolled in the state鈥檚 MOScholars voucher program on its website. The data included parent email addresses, scholarship amounts and schools participating in the program.

, the first state to make an ESA program universally available, a parent was able to view the names of students in the program, their disabilities and other information about ClassWallet orders for several days in 2023. An investigation by the state鈥檚 Homeland Security department described the incident as a 鈥減ermission setting error鈥� and linked the mistake to the former program administrator鈥檚 laptop.

That official, Christine Accurso, and another high-ranking employee Linda Rizzo, following the incident.

As it tries to resolve the ClassWallet issue, South Carolina officials are also responding to a last week that affected school districts using Frontline Education, a school administration software platform. In an email to parents, said student information may have been compromised.

The state isn鈥檛 the first to have an education agency targeted by cyber criminals. In 2023, the Minnesota Department of Education was the victim of a affecting a software program called MOVEit. Hackers were able to access files that included demographic information for roughly 95,000 names of students in foster care. The following year, the Alabama State Department of education was hit with a that exposed some students鈥� and teachers鈥� personal information. 

As states prepare to launch the federal tax credit program next year, ensuring donors鈥� and students鈥� information is secure should be a high priority, said Cecilia Retelle Zywicki, who co-founded LearningSpring to help states and scholarship granting organizations put those pieces in place.

鈥淚 think Treasury gave a lot of power to states to do the right thing,鈥� she said. 鈥淏ut you have to balance real access with real safeguards.鈥�

Did you use this article in your work?

We鈥檇 love to hear how 社区黑料鈥檚 reporting is helping educators, researchers, and policymakers.

Republish This Article

We want our stories to be shared as widely as possible 鈥� for free.

Please view 社区黑料's republishing terms.





On 社区黑料 Today