Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Saydel School District cyberattack lands former IT worker 21 months in prison
    Technology

    Saydel School District cyberattack lands former IT worker 21 months in prison

    Gary BehanBy Gary Behan16/08/2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Saydel School District cyberattack
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    A former IT worker has been sentenced to 21 months in prison over the Saydel School District cyberattack, a campaign of sustained disruption that stretched across nearly two years, deleted accounts, knocked out device management for a week, and left the Iowa district facing a remediation bill of nearly $60,000.

    Ezekiel Dean Potter, 34, had worked as a senior IT support specialist for the Saydel Community School District in Des Moines from May 2022 through April 2023. Prosecutors say he retained access credentials after leaving and began targeting his former employer’s systems almost immediately. Court documents describe what followed as a prolonged, deliberate campaign rather than a single incident.

    What the Saydel School District cyberattack actually involved

    The trouble started when Saydel’s Facebook page was deleted shortly after Potter’s departure. From there, the attacks escalated. Potter targeted the district’s Apple School Manager account, deleting user accounts, passwords, phone numbers, billing information, and device management server data. The result: school employees lost access to the platform, and management of district MacBooks and iPads was disabled for roughly a week while staff worked with Apple to recover access.

    The district’s GoDaddy account and other online services also saw unauthorised access attempts. Then, in January 2025, Potter accessed the district’s Schoology learning management system through a Google administrator account and deleted an IT employee’s account, disrupting teacher access and impacting classes for approximately two hours. A week later, he accessed another administrator account and deleted nine Gmail accounts belonging to current and former staff, including the district’s IT director and superintendent.

    The US government’s sentencing memorandum was unsparing. ‘For over a year and a half, Defendant was a plague on the Saydel Community School District,’ it read. ‘He deleted SCSD’s Facebook page, stripped its employees of access to educational platforms and accounts, and tried again and again to reset its employees’ usernames and passwords for various other platforms and accounts.’

    How investigators caught up with Potter

    Potter’s operational security improved as the investigation closed in. After receiving Google security alerts warning of unauthorised account access, he switched to using a VPN service. Federal investigators nonetheless traced some activity to IP addresses linked to his other employers, including Casey’s Store Support Center and The Printer Inc. (TPI).

    His undoing came after he left TPI in January 2025. Potter asked a former coworker to retrieve and wipe a USB drive from his desk. The coworker handed it to investigators instead. Prosecutors say the drive contained spreadsheets with usernames and passwords for Saydel School District accounts and services.

    Potter pleaded guilty in January 2026 to computer fraud charges under the Computer Fraud and Abuse Act, without entering into a plea agreement. On 11 June he was sentenced to 21 months in prison followed by three years of supervised release.

    Restitution and the conditions attached to release

    The financial cost of the Saydel School District cyberattack has been quantified precisely: Potter is required to pay $59,668.81 in restitution to the district and its insurer, Travelers Casualty and Surety Company, to cover remediation costs.

    The supervised release conditions are tailored to someone with Potter’s background. He will face restrictions and monitoring relating to employment, finances, and computer systems, and his electronic devices may be searched on reasonable suspicion. For a former IT professional whose access to systems was the weapon, those conditions amount to a closely watched three years once his prison term ends.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleVelvet Ant Operation Highland Burrowed Into Air-Gapped Network for a Decade
    Next Article Outsider Enterprise phishing takedown seizes servers, $100k in crypto and a Telegram bot
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    City-Forum Data Theft Campaign Exploits Salesforce and ServiceNow Guest Access

    16/08/2026

    Outsider Enterprise phishing takedown seizes servers, $100k in crypto and a Telegram bot

    16/08/2026

    Velvet Ant Operation Highland Burrowed Into Air-Gapped Network for a Decade

    15/08/2026

    Fable 5 Export Control Ban Pulls Anthropic’s Top Models Offline Worldwide

    15/08/2026

    Maine breach portal fake disclosures prompt shutdown and procedure review

    15/08/2026

    Dark Web Supply-Chain Warnings Buried in Plain Sight Before Breaches Go Public

    14/08/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.