
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers.
Frontline Education is an edtech company that provides administration and workforce management software and services used by school districts.
Last night, a reader shared a data breach notification with BleepingComputer that Frontline sent to an impacted school district, stating that attackers breached its environment through a vulnerability in a third-party application.
"On August 14, 2026, our security team identified a vulnerability in a third-party software product we use that allowed unauthorized access to a portion of the environment," the notification letter reads.
"We promptly investigated the issue with the assistance of an independent cybersecurity firm, remediated the vulnerability, engaged with law enforcement, and took steps to further reinforce the security of our systems."
The company has not disclosed which third-party application was involved or when the unauthorized access first occurred.
For the notification seen by BleepingComputer, our source said all employees at the district were impacted, with exposed information including Social Security numbers, email addresses, and physical addresses.
BleepingComputer contacted Frontline Education yesterday about the breach but did not receive a reply to our email.
However, school IT administrators reported on the K12SysAdmin subreddit that district officials had begun to receive similar notifications.
One administrator initially said their superintendent and business manager received the notification on October 1 from [email protected], but Frontline support had not yet confirmed whether the message was legitimate.
However, other administrators later said they had independently confirmed the breach notifications were legitimate.
"Can confirm this is legitimate. We've had verbal contact with our Frontline rep on it," one administrator reported.
One administrator also shared a copy of a Frontline notification stating that 1,210 employees associated with their district were impacted and that Social Security numbers, email addresses, and addresses were also exposed.
Frontline says it will handle notifications to affected individuals on behalf of impacted school districts unless a district opts out by October 16.
Districts that want to opt out can do so through www.frontline-transunion.com or by calling 833-516-8792. If a district opts out, Frontline says it will not provide notification services or reimburse the district for the costs of issuing its own notices.
Impacted adults are being offered two years of free credit monitoring and identity theft protection through TransUnion, while minors will be offered cyber monitoring services.
The company says it will also handle required notifications to state attorneys general and cover costs associated with individual notifications and the identity protection services.
It is unclear how many school districts or individuals were affected.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat