← All incidents
Resolved, last updated 2025
K-12 benefits administratorThird-party administratorStaff PIIRetirement plans

Carruth Compliance Consulting Breach

December 2024. K-12 vendor risk extends to the back office. A breach at a retirement-plan administrator exposed school-employee data across many districts at once.

What happened

Attackers infiltrated Carruth Compliance Consulting, the third-party administrator for 403(b) and 457(b) retirement plans used by many public school districts, between December 19 and 26, 2024. Disclosures rolled out through 2025. Seattle Public Schools confirmed the breach affected everyone it employed from 2008 to 2024.

Confirmed exposed

  • Names and Social Security numbers
  • Financial account details
  • In some cases W-2s, driver license numbers, tax filings, and medical billing data

Confirmed not exposed

  • This incident involves school-employee data held by a benefits administrator, distinct from any student information system

Why it belongs in this library

Vendor risk is not only the student information system. Benefits and payroll administrators hold staff PII just as sensitive as student records, and one administrator breach hits many districts at once. This is a separate event from the PowerSchool incident, and it shows the back office is part of the attack surface.

Sources

  1. SC Media — Extensive US public school employee data compromise from Carruth Compliance Consulting breach (2025)
  2. OPB — Multiple Oregon school districts hit by Carruth data breach (2025-01-17)

This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].

Carruth Compliance Consulting Breach: December 2024 | Ask Before You App