09/04/2026
SECURITY UPDATE
On September 3rd, LFIL identified unauthorized access to a staff email
account. The account was used to send phishing messages titled “Review
and Sign” and “Please check”. These messages were not sent by the
employee.
Based on the records reviewed so far, we have found no evidence that
the unauthorized person accessed or removed sensitive or student data.
The activity confirmed in our logs appears limited to preparing,
sending, and concealing the phishing email campaign. We have
identified no further unauthorized activity since the account was
contained.
We are also receiving reports that other local schools have
experienced similar account compromises. We do not yet know whether
these incidents are connected.
Response timeline
• 4:42 p.m. : The main phishing email blast began.
• 5:25 p.m. : LFIL reset the account credentials and suspended the
account, containing the known unauthorized activity.
• By 5:39 p.m. : Identified copies in LFIL-managed inboxes were marked
as phishing and removed from internal inboxes.
If you received one of these messages, do not click its links,
download files, or install anything. Report it as phishing and delete
it.
If you entered a password, change it immediately from a trusted device
anywhere that password was used. If you opened or ran a downloaded
file, disconnect the device from the network and have it examined by a
qualified technician.
Thank you to everyone who reported the messages quickly. Our
investigation is continuing, and we will share another update if our
findings materially change.