ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Pennsylvania State Education Association breach impacted over 500,000 educators

The Pennsylvania State Education Association said the data security incident it suffered last year compromised the sensitive personal and financial information of more than half a million members.

 

Headquartered in Harrisburg, Pennsylvania, the Pennsylvania State Education Association (PSEA) is a labor union representing teachers, educational support professionals, counsellors, curriculum specialists, librarians, health care workers, school nurses and more across the state of Pennsylvania.

 

In a data security incident notice filed with the Office of Maine attorney General, PSEA said that on July 6, 2024, it  experienced a data security incident that affected its internal network. The labour union immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

“Through a thorough investigation and extensive review of impacted data which was completed on February 18, 2025, we determined that the data acquired by the unauthorised actor contained some personal information belonging to individuals whose information was contained within certain files within our network,” reads the notice.

 

The compromised data included names, dates of birth, driver’s license or state IDs, Social Security Numbers, account numbers, account PINs, security codes, passwords and routing numbers, payment card numbers, payment card PINs, expiration dates, passport numbers, taxpayer IDs, usernames and passwords, health insurance Information and medical information.

 

PSEA’s filing with the Maine state regulator also revealed that at least 517,487 educators from across the state were impacted by the incident.

 

PSEA has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general. It has also offered one year of complimentary identity protection and credit monitoring services through IDX to all affected individuals. 

 

In September, the Rhysida ransomware group claimed responsibility for the cyber attack on PSEA and listed it as a victim on its data leak site. The group claimed to be in possession of sensitive personal information of PSEA members and gave PSEA a deadline of 6 days to pay a ransom of 20 bitcoins. It is unclear whether a ransom was paid.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543