Raptor Technologies Cloud Exposure
January 2024. No hacker required. Three unprotected cloud buckets from a school-safety vendor exposed lockdown plans, camera locations, and at-risk student files. Vendor cloud hygiene is a life-safety issue, not just a privacy one.
What happened
Security researcher Jeremiah Fowler found three cloud storage buckets belonging to school-safety software vendor Raptor Technologies that had no password protection. The buckets exposed roughly 4 million records. Raptor's software is used by more than 5,300 US districts and 60,000+ schools worldwide.
Confirmed exposed
- School incident-response and lockdown plans, evacuation meeting points
- Classroom layouts, camera locations, and documented security vulnerabilities
- Background-check details and at-risk student documents, including medical and mental-health information
Confirmed not exposed
- This was a misconfiguration discovered by a researcher, not a confirmed criminal exfiltration
Why it belongs in this library
The data most schools most need to keep secret, the plans for the worst day, sat in the open because of a storage setting. Vendor cloud hygiene is a physical-safety question, and "we were never hacked" is not the same as "your data was never exposed."
Sources
This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].