
New York Mayor Eric Adams and city officials have demanded an FBI investigation into the largest single breach of K-12 student data in January, which potentially revealed the personal data of 820,000 current and former students.
Cybercriminals were able to hack into the IT systems of Illuminate Education, a California-based software company that created the popular IO Classroom, Skedula, and PupilPath platforms, used by New York City’s Department of Education to track grades and attendance.
The hack, which caused the largest ever exposure of students’ data in American history, exposed the names, primary languages, dates of birth, ethnicities, and ID numbers of students dating back to the 2016-17 academic year.
The incident came to the spotlight again following an official acknowledgment last week by the software vendor Illuminate Education. Eric Adams blasted the two-month gap between the January software outages and Illuminate Education’s acknowledgment last week.
He alleged that the vendor’s formal notification of the breach after two months shows the company was more concerned with protecting itself than the students. Education officials also accused Illuminate of misrepresenting the safeguards it had in place concerning student data and of failing to encrypt its platforms.
In a written statement, the software vendor said that it recently completed the investigation into the January incident, which found that personal information was exposed by unauthorized access to its systems. The company is currently issuing notifications to the affected customers.
Meanwhile, there is no evidence of any fraudulent or illegal activity related to this incident, which resulted in the grading and attendance systems going offline for several weeks, to the dismay of teachers, parents, and students. According to Illuminate Education, the company does not store financial information or Social Security numbers.
K12 Security Information Exchange, which has tracked thousands of cyber-attacks targeting schools and education platforms since 2016, said that many attacks originate with software vendors.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543