Chicago Public Schools says Cleo vendor breach exposed 700,000 students

Organization
Chicago Public Schools
Exploit
Supply Chain Attack
Industry
Education

Chicago Public Schools notified families in early March 2025 that personal information on roughly 700,000 current and former students had been exposed through a cyberattack on Cleo, a file transfer software vendor the district used to share data with other agencies. The district said the underlying compromise happened in late 2024.

The exposed records covered students enrolled from the 2017-18 school year onward and included names, dates of birth, gender and CPS student identification numbers. Chalkbeat Chicago reported that about 344,000 students enrolled in Medicaid also had their Medicaid identification numbers and eligibility dates exposed. CPS said Social Security numbers, financial information and health records were not involved, and that no staff data was affected.

The theft formed part of the Clop extortion group's campaign against a flaw in Cleo's file transfer products, which affected more than 60 organisations. CPS said the stolen files were initially encrypted but that the attackers decrypted them and posted the contents on a dark web site.

The district reported the incident to the FBI and the Illinois attorney general's office, and said it also worked with the Department of Homeland Security and the Illinois Department of Innovation and Technology. CPS said it was never contacted about paying a ransom and had seen no evidence that student data had been misused. It directed families to a dedicated notification page and said it expected vendors to match its own standard of care.

Sources