
The Association of California School Administrators (ACSA) experienced a data breach that compromised the sensitive personal information of more than 50,000 members.
ACSA claims to be the largest umbrella organisation for school leaders in the United States, serving more than 17,000 California educators.
In a data breach notice filed with the Office of the Maine Attorney General, ACSA said that on September 24, it identified encryption malware in its internal network that affected portions of its network. The association immediately launched an investigation with assistance from external cyber security experts, to determine the scope of the incident.
“The investigation determined that between September 23rd and 24th, 2023, an unauthorised actor gained access to certain ACSA systems and accessed or may have taken certain information contained therein,” reads the notice.
According to the Association, the compromised data included names, addresses, dates of birth, driver’s licence numbers, Social Security numbers, passport details, financial account information, payment card information, medical information, health insurance information, employer identification numbers, employer assigned identification numbers, tax IDs, student ID numbers, other education-related information (including student directory information, student grade point average, student report cards/transcripts/grades, and student test scores), occupational health related information, and online account credentials.
The association’s filing with the Maine state regulator states that at least 54,682 individuals were impacted by the incident.
While ACSA found no evidence of the compromised information being misused, it has advised all affected individuals to regularly monitor their credit reports, bank accounts and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered one year of complimentary identity protection and credit monitoring services through IDX to all affected individuals.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543