<entry_summary>Former IT employee conducted cyberattack on Iowa school district using retained credentials, deleting accounts/systems; led to 21-month prison sentence and $59K restitution.<entry_summary>
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Ipaddress |
<specific IPs>
|
IPs traced to Potter's former employer | T1027 |
| Code | Title |
|---|---|
| T1078.001 | Abuse System Credentials (Google admin account) |
| T1064.001 | Data Manipulation (deleted accounts) |
| T1490.001 | Proxy for Credential Discovery (VPN tracing) |
| T1195 | Input Capture (protected credentials on USB) |
| Type | Value |
|---|---|
| Country | USA |
| Region | Iowa |
| Sector | Education |
A former IT employee at an
Court documents go on to say that in January 2025, Potter accessed the district's Schoology learning management system through a Google administrator account and deleted an IT employee’s account, disrupting teacher access to the platform and impacting classes for approximately two hours. A week later, prosecutors say Potter accessed another administrator account and deleted nine Gmail accounts belonging to current and former district employees, including the district’s IT director and superintendent. Court filings state that Potter later switched to using a VPN service after receiving Google security alerts warning of unauthorized account access. Federal investigators eventually traced some of the activity to IP addresses associated with Potter’s other employers, including Casey’s Store Support Center and The Printer Inc. (TPI). After Potter left TPI in January 2025, prosecutors say he asked a former coworker to retrieve and wipe a USB drive from his desk. Instead, the coworker turned it over to investigators, who allegedly found spreadsheets containing usernames and passwords for Saydel School District accounts and services. Potter pleaded guilty in January 2026 to computer fraud charges under the Computer Fraud and Abuse Act without entering into a plea agreement. On June 11, Potter was sentenced to 21 months in prison followed by three years of supervised release. As part of his supervised release conditions, Potter will be subject to restrictions and monitoring related to employment, finances, and computer systems, including searches of electronic devices upon reasonable suspicion. Potter is also required to pay $59,668.81 in restitution to the Saydel Community School District and its insurer, Travelers Casualty and Surety Company, for remediation costs related to the attacks. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper