Carruth Compliance Consulting Breach
December 2024. K-12 vendor risk extends to the back office. A breach at a retirement-plan administrator exposed school-employee data across many districts at once.
What happened
Attackers infiltrated Carruth Compliance Consulting, the third-party administrator for 403(b) and 457(b) retirement plans used by many public school districts, between December 19 and 26, 2024. Disclosures rolled out through 2025. Seattle Public Schools confirmed the breach affected everyone it employed from 2008 to 2024.
Confirmed exposed
- Names and Social Security numbers
- Financial account details
- In some cases W-2s, driver license numbers, tax filings, and medical billing data
Confirmed not exposed
- This incident involves school-employee data held by a benefits administrator, distinct from any student information system
Why it belongs in this library
Vendor risk is not only the student information system. Benefits and payroll administrators hold staff PII just as sensitive as student records, and one administrator breach hits many districts at once. This is a separate event from the PowerSchool incident, and it shows the back office is part of the attack surface.
Sources
This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].