DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Former Public School Information Technology Manager Charged with Damaging School’s Computer Network

Posted on December 4, 2023 by Dissent

From the U.S. Attorney’s Office in Massachusetts on November 29:

BOSTON – An Ayer man was charged today and agreed to plead guilty in connection with a June 2023 cyberattack targeting the computer network of his former employer, an Essex County public high school.

Conor LaHiff, 30, was charged in an Information with one count of unauthorized damage to protected computers. He will appear in federal court in Boston at a later date.

According to court documents, LaHiff was employed as a desktop and network manager at an Essex County public high school until he was terminated in June 2023. After he was fired, LaHiff allegedly used his administrative privileges to deactivate and delete thousands of Apple IDs from the school’s Apple School Manager account – software used to manage student, faculty and staff information technology resources. LaHiff also allegedly deactivated more than 1,400 other Apple accounts and other IT administrative accounts and disabled the school’s private branch phone system, which left the school’s phone service unavailable for approximately 24 hours.

The charge of unauthorized damage to protected computers provides for a sentence of up to 10 years in prison, up to three years of supervised release and a fine of $250,000 or twice the gross gain or loss. Sentences are imposed by a federal district court judge based upon the U.S. Sentencing Guidelines and statutes which govern the determination of a sentence in a criminal case.

Acting United States Attorney Joshua S. Levy and Jodi Cohen, Special Agent in Charge of the Federal Bureau of Investigation, Boston Division made the announcement today.  Assistant U.S. Attorney Mackenzie A. Queenin of the Securities, Financial & Cyber Fraud Unit is prosecuting the case.

The details contained in the charging documents are allegations. The defendant is presumed innocent unless and until proven guilty beyond a reasonable doubt in a court of law.


Related:

  • Two suspected Scattered Spider hackers plead not guilty over Transport for London cyberattack
  • Attleboro investigating ‘cybersecurity incident' impacting city's IT systems
  • Fired techie admits sabotaging ex-employer, causing $862K in damage
  • Report released on PowerSchool cyber attack
  • Princeton University Data Breach Impacts Alumni, Students, Employees
  • From bad to worse: Doctor Alliance hacked again by same threat actor (2)
Category: Education SectorInsiderU.S.

Post navigation

← Sellafield nuclear site hacked by groups linked to Russia and China (1)
On September 2nd, the U.S. branch of Great Star Industrial Co. disbursed a ransom of 1 million dollars to a ransomware group →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • ANNOUNCE: A new resource to help small and mid-sized HIPAA-regulated entities
  • Askul says 740,000 sets of data breached in cyberattack
  • Google and Apple roll out emergency security updates after zero-day attacks
  • Doxers Posing as Cops Are Tricking Big Tech Firms Into Sharing People’s Private Data
  • Virginia Urology Silent on Possible Data Breach as Purported Patient Data Begins to Leak
  • Village of Golf Manor considering paying ransom amid cyberattack (1)
  • Teen who allegedly stole millions of personal data records arrested in Spain
  • Akira ransomware: FBI tallies 250 million in payouts
  • IE: HSE confirms second ransomware attack but ‘no evidence’ patient data was stolen
  • Examining impact of federal relief program after major healthcare cyberattack — Research Brief

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Slovenian officials weaponize data-privacy laws against investigative journalism
  • End-of-Year 2025 State and Federal Developments in Minors’ Privacy
  • Tool allows stealthy tracking of Signal and WhatsApp users through delivery receipts
  • Oh Great, Smart Glasses That Record Everything You Say
  • CBP Agents Held This U.S. Citizen for Hours Until He Agreed To Let Them Search His Electronic Devices

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.