Las Lomitas Elementary School District Data Breach Exposes Student and Staff Information

Education data breach illustration
Breach Discovery: May 2026Breach Notification: May 2026

What Happened in the Las Lomitas Elementary School District Data Breach?

Las Lomitas Elementary School District recently disclosed a data breach connected to its use of Canvas, a learning management system operated by a company called Instructure. The district learned about the incident when Instructure directly notified officials that a criminal threat actor had gained unauthorized access to information stored on the Canvas platform. This means the district itself did not discover the intrusion internally; instead, its technology vendor flagged the problem first.

According to the notification, Instructure informed the district that the access occurred through its Canvas system rather than through the district’s own internal servers. Las Lomitas had piloted Canvas as a learning management tool for its middle school during the spring of 2024, but never fully adopted the platform afterward. As a result, the exposed information relates specifically to the 2023-2024 school year, even though the breach was only reported now.

Once notified, the district’s IT department began reviewing exactly what personal information had been stored within Canvas at the time of the intrusion. This internal review allowed the district to confirm which categories of data were present in the system and therefore potentially accessible to the attacker. Instructure has stated that it found no indication that passwords, dates of birth, government identification numbers, or financial information were involved in the breach.

Who was affected?

The breach affects a defined group connected to Las Lomitas Elementary School District’s La Entrada Middle School. Specifically, it involves students who were enrolled in sixth, seventh, or eighth grade during the 2023-2024 school year. In addition, the caregivers of those students and certain district staff members were also affected.

The district has not publicly disclosed an exact number of individuals impacted by this incident. However, because the exposure is tied to a single middle school pilot program over one school year, the affected population is likely a defined and limited group rather than the district’s entire student body. Because minors were enrolled in the affected grades, some of the exposed information does involve children, which raises additional privacy concerns for families.

What Information Was Potentially Exposed?

The district’s internal review confirmed several categories of personal information were stored in Canvas and therefore potentially accessible during the breach. This information covered both students and the adults connected to them, including caregivers and staff members.

  • First and last names
  • Email addresses
  • Class enrollment records
  • Grade-level information for the 2023-2024 school year
  • Caregiver names associated with affected students
  • Staff names and related account information

Although Instructure reported no evidence that passwords, birth dates, government identifiers, or financial details were compromised, the exposed data still carries risk. For example, names and email addresses combined with school enrollment details can be used to craft convincing phishing emails. Attackers often impersonate school officials or platforms like Canvas to trick parents or staff into clicking malicious links or revealing further information.

Because children are among those affected, caregivers should also stay alert to signs of targeted scams referencing their child’s school or class. Fraudsters sometimes use even limited information, such as a child’s name and grade level, to appear credible when contacting families. This is particularly true when the message references a real school event or platform the family already recognizes.

What is the company doing?

Once Instructure alerted the district to the unauthorized access, Las Lomitas moved to review its Canvas data and determine which individuals were affected. The district then began directly contacting staff and caregivers whose information was involved in the breach. This notification effort appears to be ongoing, with the district reaching out individually rather than through a single public statement alone.

Looking ahead, the district has indicated that Instructure will provide additional information soon, including details about potential protective measures such as identity protection services. The district has committed to forwarding that information to affected individuals as soon as it becomes available. In the meantime, the district has directed anyone with questions to its IT Director for further guidance and clarification.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Even though this breach does not appear to involve Social Security numbers or financial account details, affected caregivers and staff should still consider checking their credit reports periodically. Identity thieves sometimes combine seemingly minor personal details with information gathered elsewhere to attempt fraud. Reviewing your credit report helps you catch unfamiliar accounts or inquiries early.

You can request free credit reports from each of the three major credit bureaus once a year. Consequently, spacing out these requests throughout the year allows for more frequent monitoring at no cost. If you notice anything suspicious, report it to the credit bureau immediately and consider contacting a data breach attorney for guidance.

Watch for Phishing Attempts

Because names and email addresses were exposed, affected individuals should be especially cautious about unexpected emails claiming to come from the school district or Canvas. Scammers often use breached contact information to send messages that look legitimate but contain malicious links or requests for sensitive data.

Before clicking any links or replying to unfamiliar messages, verify the sender’s identity through a separate, trusted channel. For instance, call the school district directly using a phone number from its official website rather than one provided in a suspicious email. This simple step can prevent a phishing attempt from succeeding.

Protect Your Child’s Personal Information

Because students in sixth through eighth grade were affected, caregivers should stay alert for any unusual activity connected to their child’s name. Although children rarely have credit histories, thieves sometimes use a minor’s information to open fraudulent accounts undetected for years.

To check for this, caregivers can request a manual credit freeze or file with credit bureaus specifically for their child, since minors generally do not have an existing credit file to monitor. If a credit file already exists in your child’s name, that itself may be a warning sign worth investigating further.

Stay Informed About Identity Protection Offers

The district has indicated that Instructure will soon share more details, potentially including identity protection services for those affected. Once this information becomes available, affected caregivers and staff should review it closely and consider enrolling if eligible.

In the meantime, keep an eye on official communications from the district’s IT department. Because scammers may try to impersonate this outreach, always confirm any enrollment links or offers directly with the school before providing personal details.



More Information

Official data breach notification from California Attorney General

Related Data Breaches