Ķvlog

Privacy & Security

Tech Glitch Could Have Exposed Thousands of School Districts’ Confidential Files

By Lauraine Langreo — June 18, 2025 3 min read
Eye of the hacker in a keyhole . Spyware, hacking, cybercrime concept. Vector illustration.
  • Save to favorites
  • Print
Email Copy URL

Thousands of school districts’ confidential files and other sensitive documents could have been publicly accessible for months because of a technical glitch in BoardDocs, a software used to manage school board meetings.

People who were not authorized to access districts’ confidential documents within the BoardDocs application were still able to access them if they searched within the app, said Nithya Das, the general manager of governance and chief legal officer for Diligent Corp., BoardDocs’ parent company.

The glitch was not because of a third-party malicious actor but rather because of a “misconfiguration,” or an issue with the way the application was “coded and architected,” she said in an interview with Education Week.

Das did not disclose how many districts were affected but said only about 1% of documents stored on BoardDocs, or roughly 64,000 files, were involved. BoardDocs is used by about 5,000 public-sector entities in the United States and Canada, mostly public schools.

The glitch adds BoardDocs to the list of K-12 ed-tech companies whose vulnerabilities have put at risk the sensitive information that districts store about students and staff. Most recently, a cyberattack on PowerSchool exposed the personal information of millions of students, parents, and staff and has led to dozens of lawsuits against the ed-tech company.

“School systems rely on their vendors to hold and manage a lot of very sensitive information,” said Doug Levin, a school cybersecurity expert and the national director of the K12 Security Information Exchange. “This [BoardDocs incident] is underscoring that we need our vendors and suppliers to be partners with us with respect to cybersecurity.”

That means K-12 vendors should be doing what they can to prevent an incident. But perhaps more importantly, Levin said, if a cybersecurity incident happens, districts “need to be notified promptly and very clearly.”

BoardDocs launches investigation to determine what happened

BoardDocs is designed to allow districts to publish public documents like meeting agendas, policies, and other documents in a library to comply with open meeting laws and promote civic engagement.

BoardDocs became aware of a “misconfiguration” in the app after a customer told the company of an issue where documents with visibility set to “private,” which were then saved in the public-content section of the app, were accessible through the in-app search, Das said. The company did not disclose the name of the client.

reported on May 30 that the Lower Merion school district was affected by a BoardDocs breach. In that instance, legal counsel representing plaintiffs in a case against the district accessed a confidential document that had been stored in a password-protected section of the application, according to the district.

See Also

Illustration of setting computer security settings. Vector illustration of computer privacy management.
iStock/Getty

BoardDocs “immediately” corrected the issue for the customer, then launched an investigation “to better understand the scope of the issue” and “remediated that issue for the other clients who were impacted,” Das said. The company has also undertaken a third-party audit of the entire software to ensure all the “configurations are accurate.”

The issue shows up in a “fairly limited use case,” Das said. “It’s not how most of our clients interact with the product. But it’s our responsibility to make sure that the configuration works as it should.”

BoardDocs has been in the process of notifying its direct clients and partners via email if they were affected or not, Das said.

But Levin criticized the company for not providing information on its website about the issue.

K12 Security Information Exchange members had to ask BoardDocs for information after learning about it from the Inquirer article, “meaning the company did not proactively inform its user base that it had this issue,” he said. also reported that multiple districts were unaware of the issue.

BoardDocs said, in a statement to Education Week, that it didn’t make a public announcement because it was “a software issue, not a data breach involving malicious third parties and did not impact the entire client population.”

Still, Levin said it “speaks to the cybersecurity culture of the company and may beg a number of questions that BoardDocs customers should be asking of the company the next time they renew their agreements.”

District leaders should think about asking questions about a vendor’s code-review process, Levin said. They should also consider adding language in their contracts with vendors about providing prompt notification of incidents that might have affected the district.

“A school system can’t manage risks if they’re not even aware that there’s potentially an issue here,” he said.

A version of this article appeared in the October 01, 2025 edition of Education Week as Tech glitch could have exposed thousands of school districts’ confidential files

Events

This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
Special Education Webinar
Hidden Costs of Special Ed Vacancies: Solutions for Your District
When provider vacancies hit, students feel it first. Hear what district leaders are doing to keep IEP-related services on track.
Content provided by 
This content is provided by our sponsor. It is not written by and does not necessarily reflect the views of Education Week's editorial staff.
Sponsor
School & District Management Webinar
Turn Athletic Facilities Into School-Wide Communication Hubs
Districts are turning idle scoreboards into revenue streams, student learning opportunities, and community platforms. See how yours can too.
Content provided by 
Mathematics K-12 Essentials Forum Middle and High School Math: How to Get Struggling Learners on Track
Join this free virtual event to uncover the nature of students’ weaknesses in secondary-level math and find a path forward.

EdWeek Top School Jobs

Teacher Jobs
Search over ten thousand teaching jobs nationwide — elementary, middle, high school and more.
Principal Jobs
Find hundreds of jobs for principals, assistant principals, and other school leadership roles.
Administrator Jobs
Over a thousand district-level jobs: superintendents, directors, more.
Support Staff Jobs
Search thousands of jobs, from paraprofessionals to counselors and more.

Read Next

Privacy & Security A Cyberattack on Canvas Could Cause Lasting Aftershocks for Schools
Data from millions of students might have been compromised.
Concept image of security breach, system hacked alert with red broken padlock icon showing vulnerable access.
Nicolas Herrbach/iStock/Getty
Privacy & Security A Potential Breach of an Anonymous Tip App Could Have Exposed Sensitive Student Data
The breach may have exposed personal information of students attending more than 30,000 schools.
A person types on a laptop, in Miami. Reuters reports that the hacker, using the name Internet Yiff Machine, said in a statement that they hacked and shared the data to expose that the confidential tips people submit through Navigate360’s P3 Global Intel platform are neither secure nor anonymous. The breach may have exposed the personal information of students attending more than 30,000 schools in the United States.
Cybersecurity experts recommend that schools should take steps now to protect student data as they wait for confirmation of a potential hack of Navigate360’s P3 Global Intel platform, which features a safety tip line.
Wilfredo Lee/AP
Privacy & Security How School Leaders Can Combat Rising Cyber Threats
Continuous training and student engagement can be key in protecting schools.
4 min read
Image with icons for "i" information, email, eye for "watch", and locks.
Collage via Canva
Privacy & Security From Our Research Center Is AI Ready to Protect Schools From Cyberattacks?
Some experts and district tech leaders are unsure what role the tech should play in cybersecurity.
6 min read
Illustration of woman defending school from monster with tentacles.
DigitalVision Vectors