← All incidents
Resolved, last updated 2024
K-12 safety vendorMisconfigurationSchool safety dataPhysical security

Raptor Technologies Cloud Exposure

January 2024. No hacker required. Three unprotected cloud buckets from a school-safety vendor exposed lockdown plans, camera locations, and at-risk student files. Vendor cloud hygiene is a life-safety issue, not just a privacy one.

What happened

Security researcher Jeremiah Fowler found three cloud storage buckets belonging to school-safety software vendor Raptor Technologies that had no password protection. The buckets exposed roughly 4 million records. Raptor's software is used by more than 5,300 US districts and 60,000+ schools worldwide.

Confirmed exposed

  • School incident-response and lockdown plans, evacuation meeting points
  • Classroom layouts, camera locations, and documented security vulnerabilities
  • Background-check details and at-risk student documents, including medical and mental-health information

Confirmed not exposed

  • This was a misconfiguration discovered by a researcher, not a confirmed criminal exfiltration

Why it belongs in this library

The data most schools most need to keep secret, the plans for the worst day, sat in the open because of a storage setting. Vendor cloud hygiene is a physical-safety question, and "we were never hacked" is not the same as "your data was never exposed."

Sources

  1. K-12 Dive — Sensitive school safety details among 4M records exposed in Raptor Technologies data leak (2024-01)
  2. vpnMentor — Raptor School Safety Software Breach Exposed 4 Million Records (2024)

This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].

Raptor Technologies Cloud Exposure: January 2024 | Ask Before You App