Slate Valley Unified School District Data Breach Exposes Social Security Numbers and Student Records

Published: 4 October 2026
Education data breach illustration
Breach Discovery: September 2026Breach Notification: October 2026

A ransomware group called Kairos attacked Slate Valley Unified School District in Fair Haven, Vermont, starting in September 2026, stealing data that reportedly includes employee Social Security numbers, salary details, and sensitive student and special education records. The district refused to pay the ransom, and the group has threatened to leak the stolen files. Affected employees and families should monitor credit reports and consider a credit freeze immediately.

CompanySlate Valley Unified School District
IndustryEducation
Data Types ExposedSocial Security Numbers, Student Names and Dates of Birth, Parent Names and Addresses, Special Education and IEP Records, Employee Salary and Job Information, Spouse and Dependent Information, Employee Benefits Information
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Slate Valley Unified School District Data Breach?

Slate Valley Unified School District, based in Fair Haven, Vermont, has been dealing with a cybersecurity incident since September 2026. The district first disclosed that it was responding to unauthorized network activity, and it has since issued several updates as its investigation has continued. As a result, families and staff in the district have spent weeks waiting for clear answers about what happened.

A group calling itself Kairos has claimed responsibility for the attack. According to statements the group made to a breach-reporting outlet, Kairos says it stole roughly 762 GB of data from the district’s systems. The group claims this includes 647 GB of SQL databases containing personal and medical information tied to both students and employees. Kairos also said it grew frustrated after the district’s school board voted not to pay its ransom demand.

On September 29, the district provided an update confirming that its board had formally declined to authorize any ransom or extortion payment. Instead, the board directed the superintendent to continue working with legal counsel, cybersecurity professionals, the district’s insurance carrier, and law enforcement on response and recovery efforts. Because the investigation is still active, the district has said it cannot yet confirm whether student data was accessed, although it noted that compromise seems unlikely for current students.

Superintendent Brooke Olsen-Farrell has acknowledged that the length of the investigation has created real frustration for the community. She has stated publicly that determining whether information was actually accessed or copied remains a key part of the ongoing forensic work. The district has not confirmed the full scope of what Kairos may have obtained, and this article relies on claims made by the attacker group along with limited district statements, since the organization itself has not verified every detail Kairos has publicized.

Who was affected?

The population potentially affected by this incident includes both current students and school district employees. Kairos has told a breach-reporting site that it possesses a spreadsheet listing 243 student entries, along with a separate 2026 spreadsheet covering 329 employees. In addition, the employee file reportedly includes information on 466 spouses and dependents connected to those employees.

The district has not publicly disclosed an official total count of affected individuals. Therefore, the true number of people impacted by this breach has not been publicly disclosed in full. Given that the exposed data reportedly spans multiple towns, including Benson, Fair Haven, Hubbardton, Bomoseen, and Castleton, the geographic footprint of this incident appears to be fairly broad within the district’s service area.

Because the affected population includes students, some of whom may be minors receiving special education services, this breach carries added sensitivity. Some of the student records reportedly relate to Individualized Education Programs and other confidential placement decisions protected under federal education privacy law. This means the incident may affect some of the most vulnerable members of the school community.

What Information Was Potentially Exposed?

Based on claims made by the Kairos group and data reviewed by a third-party outlet, several categories of sensitive information may have been exposed in this incident. The exposed records reportedly span both student and employee populations, with differing types of data for each group.

  • Student first and last names
  • Student dates of birth
  • Parent names and home addresses
  • Home phone numbers
  • Special education and IEP-related records
  • Medicaid insurance references tied to special education billing
  • Employee full names and dates of birth
  • Employee Social Security numbers
  • Employee salary, job class, and hire date information
  • Employee postal and email addresses and phone numbers
  • Spouse and dependent names, birth dates, and Social Security numbers
  • Employee benefits information

For employees and their families, the exposure of full Social Security numbers combined with dates of birth is especially concerning. This combination gives criminals nearly everything needed to open fraudulent credit accounts, file false tax returns, or commit broader identity theft. Because spouse and dependent Social Security numbers were reportedly included too, the risk extends well beyond the employees themselves to their immediate family members.

For students, the risk looks different but is still significant. Although Social Security numbers do not appear to be part of the student spreadsheet, the combination of names, birth dates, and home addresses can still support identity theft, since children’s identities are often not monitored for years. In addition, the exposure of special education records raises serious privacy concerns. These files can reveal sensitive medical, behavioral, or developmental information that families reasonably expect schools to keep confidential.

What is the company doing?

According to its public incident notice, Slate Valley Unified School District has been actively working through a formal response process since the incident began. The district says it engaged cybersecurity professionals, legal counsel, its insurance carrier, and law enforcement to help manage the investigation. In addition, the school board took the formal step of voting against paying the ransom demand, instead authorizing continued recovery and remediation work.

The superintendent has committed to sharing accurate updates as they become available, while cautioning that premature disclosures could interfere with the investigation or ongoing recovery efforts. The district has acknowledged publicly that it cannot yet confirm whether student data was compromised, though it has said compromise appears unlikely for current students specifically. Because the forensic review is still underway, further updates are expected as more information is confirmed.

It is important to note that much of what is currently known about the scope of stolen data comes from the attacker group itself, not from the district. Kairos has published claims about the volume and contents of the stolen files on its dark web leak site. The district has not independently confirmed every detail included in those claims, and affected individuals should watch for official notification letters for confirmed, verified information about their own records.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

If you are a current or former Slate Valley Unified School District employee, you should begin monitoring your credit reports right away. You can request free reports from all three major credit bureaus and review them for unfamiliar accounts or inquiries. Doing this regularly makes it much easier to catch fraud early, before it causes lasting damage.

Because Social Security numbers were reportedly included in the stolen employee data, this step is especially important. Identity thieves often wait months or even years before using stolen information, so one-time checks are not enough. Consider setting a recurring reminder to check your reports every few months going forward.

Place a Fraud Alert or Credit Freeze

Given that full Social Security numbers for employees, spouses, and dependents were reportedly exposed, a credit freeze is one of the strongest protective steps available. A freeze blocks new creditors from accessing your credit file, which makes it much harder for criminals to open accounts in your name. You can place a freeze for free with each of the three major bureaus.

Alternatively, a fraud alert requires creditors to take extra verification steps before approving new credit. This option is less restrictive than a freeze but still adds a meaningful layer of protection. Families with dependents whose Social Security numbers may have been exposed should also look into how to place protective freezes for minors.

Watch for Phishing and Scam Attempts

Affected individuals should be on alert for phishing emails, texts, or calls that reference this incident. Scammers often use real breach news to create convincing fake messages that ask victims to click links or confirm personal information. As a result, you should never respond to unsolicited messages asking for sensitive details, even if they appear to reference the school district.

Instead, verify any communication directly through the district’s official channels. If you receive a notification letter about this breach, read it carefully, but confirm its authenticity before clicking any links. When in doubt, contact the district’s office directly using a phone number you look up independently.

Protect Sensitive Student and Special Education Records

Families whose children may be connected to special education records should pay close attention to any district communications about this incident. Because IEP-related files and placement records can contain sensitive medical and behavioral information, their exposure carries unique privacy risks. Parents should ask the district directly whether their child’s specific records were involved, since broad statements may not reflect every family’s situation.

In addition, parents should watch for any signs of misuse tied to their child’s identity, such as unexpected mail addressed to a minor or unfamiliar accounts. While this kind of misuse can take years to surface, early awareness helps limit the damage. If you have concerns about your rights under federal student privacy law, consulting a data breach attorney for a free case evaluation can help clarify your options.

Consider Legal Options for Affected Employees and Families

Employees whose Social Security numbers, salaries, and benefits details were reportedly exposed may have legal options worth exploring. Many individuals affected by large data breaches choose to consult an attorney who focuses on data breach litigation. This can help clarify whether compensation or other remedies may be available.

Because this incident involves both current students and employees, the legal landscape may be complex. As a result, speaking with a knowledgeable attorney can help you understand deadlines and potential claims specific to your situation. Many offer free initial consultations, so there is little downside to asking questions early.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Check other recent data breach notifications →