A former IT worker has been sentenced to 21 months in prison over the Saydel School District cyberattack, a campaign of sustained disruption that stretched across nearly two years, deleted accounts, knocked out device management for a week, and left the Iowa district facing a remediation bill of nearly $60,000.
Ezekiel Dean Potter, 34, had worked as a senior IT support specialist for the Saydel Community School District in Des Moines from May 2022 through April 2023. Prosecutors say he retained access credentials after leaving and began targeting his former employer’s systems almost immediately. Court documents describe what followed as a prolonged, deliberate campaign rather than a single incident.
What the Saydel School District cyberattack actually involved
The trouble started when Saydel’s Facebook page was deleted shortly after Potter’s departure. From there, the attacks escalated. Potter targeted the district’s Apple School Manager account, deleting user accounts, passwords, phone numbers, billing information, and device management server data. The result: school employees lost access to the platform, and management of district MacBooks and iPads was disabled for roughly a week while staff worked with Apple to recover access.
The district’s GoDaddy account and other online services also saw unauthorised access attempts. Then, in January 2025, Potter accessed the district’s Schoology learning management system through a Google administrator account and deleted an IT employee’s account, disrupting teacher access and impacting classes for approximately two hours. A week later, he accessed another administrator account and deleted nine Gmail accounts belonging to current and former staff, including the district’s IT director and superintendent.
The US government’s sentencing memorandum was unsparing. ‘For over a year and a half, Defendant was a plague on the Saydel Community School District,’ it read. ‘He deleted SCSD’s Facebook page, stripped its employees of access to educational platforms and accounts, and tried again and again to reset its employees’ usernames and passwords for various other platforms and accounts.’
How investigators caught up with Potter
Potter’s operational security improved as the investigation closed in. After receiving Google security alerts warning of unauthorised account access, he switched to using a VPN service. Federal investigators nonetheless traced some activity to IP addresses linked to his other employers, including Casey’s Store Support Center and The Printer Inc. (TPI).
His undoing came after he left TPI in January 2025. Potter asked a former coworker to retrieve and wipe a USB drive from his desk. The coworker handed it to investigators instead. Prosecutors say the drive contained spreadsheets with usernames and passwords for Saydel School District accounts and services.
Potter pleaded guilty in January 2026 to computer fraud charges under the Computer Fraud and Abuse Act, without entering into a plea agreement. On 11 June he was sentenced to 21 months in prison followed by three years of supervised release.
Restitution and the conditions attached to release
The financial cost of the Saydel School District cyberattack has been quantified precisely: Potter is required to pay $59,668.81 in restitution to the district and its insurer, Travelers Casualty and Surety Company, to cover remediation costs.
The supervised release conditions are tailored to someone with Potter’s background. He will face restrictions and monitoring relating to employment, finances, and computer systems, and his electronic devices may be searched on reasonable suspicion. For a former IT professional whose access to systems was the weapon, those conditions amount to a closely watched three years once his prison term ends.

