discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Ex-school district employee jailed for hacks on former employer

A former Iowa school district IT worker got 21 months in prison for a 21-month hacking spree against his old employer.

By Lawrence Abrams·Jun 13·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Ex-school district employee jailed for hacks on former employer
Image: bleepingcomputer.com

Prosecutors said Ezekiel Dean Potter kept access after leaving Saydel Community School District and repeatedly hit its accounts and services. The attacks deleted accounts, disrupted classes, and led to nearly $60,000 in restitution and remediation costs.

Why it matters

This is a clear insider-threat case: access left behind after employment ended became a long-running way back into school systems. It shows how former staff with old credentials can cause real operational damage, not just data theft.

A former school tech worker kept keys to the school’s computer doors after leaving. He used them to sneak back in, break things, and lock people out, like someone keeping a house key and coming back to mess with the lights.

Analysis

What happened

According to court documents, Ezekiel Dean Potter worked as a senior IT support specialist for Saydel Community School District in Iowa from May 2022 through April 2023. After his job ended, prosecutors said he kept credentials and used them over the next 21 months to break into district systems.

Impact on the district

The government said Potter deleted the district’s Facebook page, interfered with access to education platforms, and repeatedly tried to reset usernames and passwords for district accounts. Court filings say he also hit the Apple School Manager account, removing user and billing data and blocking management of school MacBooks and iPads for about a week. In January 2025, prosecutors said he accessed Schoology through a Google administrator account, deleted an IT employee’s account, and disrupted classes for about two hours. A week later, he allegedly deleted nine Gmail accounts tied to current and former employees, including the IT director and superintendent.

Investigation and sentence

The district also saw unauthorized access attempts against GoDaddy and other services. Investigators said Potter later used a VPN after Google security alerts warned about suspicious logins. They also traced some activity to IP addresses linked to later employers, and a USB drive tied to him reportedly contained spreadsheets with Saydel usernames and passwords.

Potter pleaded guilty in January 2026 to computer fraud charges under the Computer Fraud and Abuse Act. On June 11, he was sentenced to 21 months in prison, followed by three years of supervised release. He must also pay $59,668.81 in restitution to the district and its insurer.

Bottom line

The case is a reminder that offboarding matters. If old credentials survive a departure, a former employee can keep causing damage long after leaving the building.

Key points

  • Potter was sentenced to 21 months in prison for hacking the Saydel Community School District after leaving his IT job.
  • Prosecutors said he kept access credentials and attacked the district’s systems for about 21 months.
  • The alleged attacks deleted accounts, disrupted classes, and interfered with device management and online services.
  • He must pay $59,668.81 in restitution and will serve three years of supervised release.
  • The case highlights the risk of former employees retaining access to sensitive school systems.
The Upside

The sentence and supervised release may help limit further harm from the same person. The district now has a public example of how important it is to remove old access and track accounts carefully when staff leave.

The Downside

The case shows how much damage a former insider can do if credentials are not fully cut off. It also suggests that schools may face repeated disruptions if account cleanup and access controls are weak.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityunited-statessocietypolicy

Author

Lawrence Abrams

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 13, 2026

Source

bleepingcomputer.com

Share

Topics

securityunited-statessocietypolicy

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…