Odyssey Charter School, Inc. Data Breach Exposes Student and Family Personal Information

Published: 16 September 2026
Education data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Odyssey Charter School, Inc., a Florida-based tuition-free charter school network, suffered a ransomware attack claimed by the group Wallstreet, with notification occurring in September 2026. The breach may affect current and former students, families, and staff, potentially exposing personal and academic information. Affected individuals should monitor credit reports and consider a credit freeze immediately.

CompanyOdyssey Charter School, Inc.
IndustryEducation
Data Types ExposedStudent Names and Dates of Birth, Parent or Guardian Contact Information, Enrollment and Academic Records, Social Security Numbers, Health or Immunization Records, Employee Payroll and Benefits Information
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Odyssey Charter School Data Breach?

Odyssey Charter School, Inc. has confirmed that it experienced a ransomware attack affecting its network systems. The Odyssey Charter School data breach came to light after a group calling itself Wallstreet claimed responsibility for the intrusion. This organization runs tuition-free public charter schools across Florida, serving students from preschool through 12th grade.

Details about the exact method the attackers used to get into the network have not been publicly disclosed. However, ransomware incidents like this one typically involve attackers gaining access through phishing emails, stolen credentials, or unpatched software. Once inside a network, these groups often copy sensitive files before deploying encryption, a tactic designed to pressure victims into paying a ransom.

The breach notification associated with this incident came in September 2026. As a result, families connected to the school district have only recently learned that their information may be at risk. Because the exact discovery date has not been publicly disclosed, it remains unclear how long the attackers had access before the school identified the intrusion.

Following the discovery, the school likely brought in cybersecurity specialists to assess the scope of the compromise. This kind of forensic review is standard practice after a ransomware claim surfaces. In addition, investigators typically work to determine exactly which files and systems the attackers reached before any public notification goes out.

Who was affected?

The population affected by this incident likely includes current and former students, along with their parents or guardians. Because Odyssey Charter School serves children from preschool through high school, this breach may involve the personal data of minors. That detail raises the stakes considerably, since childhood identity theft can go undetected for years.

School employees may also be part of the affected group. Staff records often include payroll details, benefits information, and other sensitive data stored on the same networks that serve students and families. The exact number of individuals affected by this incident has not been publicly disclosed.

Given that Odyssey Charter School operates only within Florida, the geographic scope of this breach is likely concentrated in that state. However, families who have moved away or staff who previously worked at the school could also be impacted. Anyone with a past or current connection to the school should take this incident seriously.

What Information Was Potentially Exposed?

The specific categories of data taken in this attack have not been fully itemized in public statements. Nevertheless, school systems commonly store a wide range of sensitive information about students, families, and staff. Based on what schools typically maintain, the following types of data may have been involved.

  • Student names and dates of birth
  • Parent or guardian contact information
  • Enrollment and academic records
  • Social Security numbers (for staff and possibly families)
  • Health or immunization records
  • Employee payroll and benefits information

If Social Security numbers or health records were part of this breach, the risk to affected families grows significantly. Identity thieves can use stolen Social Security numbers to open credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. For children, this type of fraud can remain hidden until they apply for their first credit card or loan years later.

Health information carries its own set of dangers. Criminals can use medical details to commit insurance fraud or to craft convincing phishing messages that reference real treatment history. Meanwhile, contact information and academic records can fuel targeted scams aimed at parents, especially those posing as school officials requesting payment or personal details.

What is the company doing?

Odyssey Charter School has acknowledged the ransomware attack and is working to address the incident. In response, the school likely engaged cybersecurity professionals to contain the threat and secure its network against further unauthorized access. This kind of immediate containment step is a standard first response to a confirmed ransomware event.

Beyond containment, the school is expected to continue investigating the full scope of what data was accessed. Notification letters to affected families and staff typically follow once that assessment is complete. Because breach notification occurred in September 2026, official communication may still be reaching some affected individuals.

Schools facing incidents like this one often review their cybersecurity policies afterward. This can include updating password requirements, adding multi-factor authentication, and retraining staff on how to spot phishing attempts. These steps aim to reduce the chance of a similar attack happening again.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone connected to Odyssey Charter School should check their credit reports regularly in the coming months. You can request a free copy from each of the three major credit bureaus through AnnualCreditReport.com. Reviewing these reports helps you spot unfamiliar accounts or inquiries before they cause serious damage.

For parents, this step matters even more if a child’s Social Security number may have been exposed. Consider requesting a credit report check for your child as well, since most children have no credit history and any activity is a red flag. Because fraud involving a minor’s identity can go unnoticed for years, early checks are especially valuable here.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers were part of this breach, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further, blocking access to your credit file entirely until you lift it.

Both options are free to set up and can be requested directly through each credit bureau. This step is particularly important for staff members whose Social Security numbers may have been part of the compromised data. Freezing a child’s credit file is also possible and worth considering if you suspect their information was involved.

Watch for Phishing and Scam Attempts

Following any school data breach, families should stay alert for suspicious emails, texts, or phone calls. Scammers often use stolen information to make their messages appear legitimate, sometimes referencing real names or enrollment details. Because of this, never click links or share personal information in response to unexpected messages.

Instead, verify any communication directly with the school through a known phone number or official website. If a message claims to be from Odyssey Charter School but asks for payment or sensitive details, treat it with caution. Reporting suspicious messages to the school can also help administrators track ongoing scam attempts tied to this breach.

Protect Health Information If Exposed

If health or immunization records were part of the exposed data, review any medical bills or insurance statements closely. Look for services or claims you do not recognize, since these can signal medical identity theft. This type of fraud can be harder to detect than financial fraud, so careful review matters.

Contact your health insurance provider immediately if you notice anything unusual. In addition, request a copy of your insurance claims history to check for unfamiliar entries. Acting quickly can prevent fraudulent claims from affecting your future coverage or medical records.

Consult a Data Breach Attorney

Given the potential involvement of student and family data, affected individuals may want to speak with a data breach attorney. An attorney can help you understand whether you qualify for compensation through a class action or individual claim. Many offer free case evaluations, so there is little downside to asking questions.

Because deadlines for filing claims can vary by state and case, it helps to act sooner rather than later. A qualified attorney can also guide you on documenting any losses related to this breach. This is especially useful if you discover fraudulent activity tied to your information down the road.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →