[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2jsia464ng6l0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"6a700f716f2e77b596438acd","BellflowerUnifiedSchoolDistrict2025","Bellflower USD 2025 Data Breach","bellflower-unified-school-district-2025","busd.k12.ca.us","2025-07-22T00:00:00.000Z","2026-08-03T03:48:01.046Z","2026-08-03T03:50:15.685Z","Bellflower Unified School District","https:\u002F\u002Fwww.busd.k12.ca.us\u002Fdepartments\u002Fbusiness-services\u002Ftechnology\u002Fcommunity-notifications",[15,17,18],"https:\u002F\u002Fwww.in.gov\u002Fattorneygeneral\u002Fconsumer-protection-division\u002Fid-theft-prevention\u002Ffiles\u002FDB-Year-to-Date-Report-7_2026.pdf","https:\u002F\u002Fwww.comparitech.com\u002Fnews\u002Fbellflower-unified-schools-warns-students-of-data-breach-that-leaked-ssns\u002F",22802,"known",null,"people","Medium",[25,26],"Names","Social security numbers","\u003Cp>\u003Cstrong>The 2025 Bellflower Unified School District data breach\u003C\u002Fstrong> involved unauthorized activity affecting the district's on-premises servers. The Indiana Attorney General record lists July 22, 2025 as the breach date and reports that 22,802 people were affected nationwide.\u003C\u002Fp>\u003Cp>The district said its IT team detected anomalous network activity in early August 2025 and that some network services were temporarily inoperable. A later review determined that an affected server contained historical student, parent, and employee information.\u003C\u002Fp>\u003Ch2>When did the incident occur?\u003C\u002Fh2>\u003Cp>The official Indiana record gives July 22, 2025 as the breach occurrence date. Bellflower's public timeline says its IT team detected the anomalous activity in early August and immediately began securing the network.\u003C\u002Fp>\u003Cp>Those dates describe different stages: the occurrence date in a regulator's record need not be the same as the period when the service disruption was detected. On April 15, 2026, the investigation determined that certain personal information may have been accessed by an unauthorized third party; notices were sent on June 12, 2026.\u003C\u002Fp>\u003Ch2>Which systems were affected?\u003C\u002Fh2>\u003Cp>Bellflower said the event affected only on-premises servers and did not affect cloud-based databases. Aeries, the system holding current student data, was also not affected.\u003C\u002Fp>\u003Cp>The affected server contained some historical student, parent, and employee records. The scope should therefore not be interpreted as covering every current student record or all district systems.\u003C\u002Fp>\u003Ch2>What information may have been exposed?\u003C\u002Fh2>\u003Cp>The public sample notice confirms first and last names as an affected field. Independent reporting on the same event also states that Social Security numbers were included for some notice recipients.\u003C\u002Fp>\u003Cp>The fields can vary by person. Public documents do not substantiate passwords, payment card data, or a broader list applying to every record, so those categories are not included in the confirmed scope.\u003C\u002Fp>\u003Ch2>Why do these data types matter?\u003C\u002Fh2>\u003Cp>A name combined with a Social Security number can increase the risk of identity theft, fraudulent credit applications, and convincing targeted scams. The fact that a record is historical does not make an identity number harmless.\u003C\u002Fp>\u003Cp>Affected people should be cautious with unexpected messages claiming to come from the district, an identity-protection service, or a government agency. A message containing accurate personal details is not necessarily authentic.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should rely on the data fields identified in their own letters, regularly review credit reports and new credit inquiries, and investigate accounts or applications they do not recognize through verified contact channels.\u003C\u002Fp>\u003Cp>Anyone whose Social Security number was involved can consider a fraud alert or credit freeze based on their circumstances. Bellflower also offered complimentary credit monitoring and identity-theft protection to people receiving notices.\u003C\u002Fp>\u003Cp>Use only enrollment details in the letter sent directly to you or on the district's official website. Never provide a full Social Security number, password, or verification code during an unsolicited call.\u003C\u002Fp>\u003Ch2>Confirmed scope\u003C\u002Fh2>\u003Cp>The confirmed scope consists of the July 22, 2025 breach record, the network disruption detected in early August, the nationwide total of 22,802 people, and recipient-variable names and Social Security numbers. The publicly reported Rhysida claim was not acknowledged by the district and is not treated here as a confirmed actor attribution.\u003C\u002Fp>","","Bellflower USD 2025 Data Breach (22.8 Thousand People Affected)","The Bellflower Unified School District data breach affected 22,802 people. Review the timeline, confirmed data types, and practical safety steps.","\u002Fuploads\u002Flogo\u002Fbellflower-unified-school-district-official.png",false,{"name":14,"sector":34,"country":35,"website":10,"websiteArchiveUrl":28,"websiteStatus":36,"websiteCheckedAt":12},"Education","United States","active"]