DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

CA: Dixon High School student arrested in electronic grade-changing scandal

Posted on May 15, 2015 by Dissent

Richard Bammer reports:

An 18-year-old Dixon High School student was arrested Thursday on suspicion of altering a computer data system, a felony, in connection with more than 200 grade changes for more than 30 students at the school.

Senior Juan Ambriz was taken into custody at the 555 College Way campus by Dixon police after Dixon Unified School District officials uncovered the scandal and said they gathered enough information to conclude he had breached the electronic gradebook system and made the changes.

Read more on The Reporter.

The district issued the following press release:

On Tuesday, May 13 the administration staff at Dixon High School became aware that unauthorized changes were made to the grades of a student through the electronic gradebook system. A teacher on campus noticed the changes and reported them as the difference was significant.

Upon questioning, the student explained how the grades had come to be changed. A second student was interviewed and confirmed the same information. Both students described how another student had gained access to teachers’ online electronic gradebooks and had the capability to change the grades on any assignment in them.

District technology staff members were able to generate reports from the student information system documenting the number of grade changes made, the specific changes made by student and assignment, as well the details of date and time. They were also able to obtain the IP address of the computer utilized to make the grade changes and verify that it was not a district computer.

Administration staff questioned the student suspected of being responsible for the grade changes and presented the documentation generated by the technology staff. The student was cooperative with staff under questioning and made a full and detailed admission of how he accessed the electronic gradebooks.

The investigation by administration staff is on-going and will take an extended period of time to complete. At this time more than 200 separate grade changes for over 30 students have been identified. Consequences for students shall not be determined until the conclusion of the investigation.

District staff contacted the Dixon Police Department and it is conducting its own investigation into the situation. The computer used by the student was obtained by district staff and is in the possession of the investigative staff at the Police Department. The student was taken into custody by Dixon Police for additional questioning on Wednesday afternoon.

Superintendent Brian Dolan has made this statement regarding this situation:
“I am joined by the staff at Dixon High in expressing my profound disappointment with regard to this situation. The fact that one student was both able to and did change grades is distressing. The additional fact that more than 30 other students appear to have enlisted his assistance in these dishonest and unethical acts is of grave concern to all of us.”

So does it concern anyone else that had a teacher not noticed a change, the district’s system didn’t detect any unusual or questionable activity – given that the changes were being made from an IP outside of the district? Yes, teachers can work from home, but what controls did this district have in place? And if the student could access the electronic gradebook, what else could potentially be accessed of a sensitive nature?


Related:

  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees (2)
Category: Education SectorInsiderU.S.

Post navigation

← HealthCare.gov Contractor Optum Declares Its Job Done
University of Pittsburgh Medical Center patients victimized by rogue employee of Medical Management LLC →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.