Rockland BOCES, the Board of Cooperative Educational Services serving Rockland County, New York, has notified people that an unauthorized individual gained access to an employee email account. The notice says the account may have held personal information, including test data.
Schools and the agencies that support them keep records on students, families, and staff. Organizations that hold that information are responsible for protecting it, and a compromised email account can put a lot of it within reach.
Rockland BOCES’s Data Breach Investigation
Rockland BOCES sent notification letters through Cyberscout, a TransUnion company that handles breach response, after learning that an unauthorized person had gotten into an employee’s email account. A sample of the letter appears on the Massachusetts state government’s public list of data breach notification letters. It is the main public record of the incident, and it is a template with placeholder names and codes, not a copy sent to a specific person.
According to the letter, Rockland BOCES discovered the incident on August 12, 2026. It then started its incident response procedures, hired legal counsel, secured the affected account, and began an investigation. The review concluded that information stored in the email account may have included the recipient’s personal information, described in the letter as test data. The organization says it has no evidence that anyone’s information was compromised or misused.
The letter does not explain how the unauthorized person got into the account, how long they had access, or whether any messages or attachments were opened or copied. It also does not say what kind of test data is involved, such as assessment results, scores, or identifying details tied to the person who took a test. Those gaps matter, because test records for students can sit alongside names, dates of birth, and school or district identifiers.
Email account intrusions are among the most common ways personal information is exposed. A single mailbox often holds years of attachments, forwarded spreadsheets, and messages sent to coworkers, and people often do not realize how much sensitive material has built up there. When an organization investigates, it usually has to review the contents of the account to work out whose information was in it, which is why notices tend to arrive weeks after the incident.
Rockland BOCES says it has added safeguards and provided extra security awareness training to its personnel. It is offering single bureau credit monitoring, a credit report, and a credit score for twelve months, along with fraud assistance. Recipients have 90 days from the date of the letter to enroll using a code printed on their individual notice.
The Massachusetts listing shows one Massachusetts resident among those notified. The total number of people who received notices has not been published, and residents of other states are often reported separately. Attorneys are looking into the incident to understand whether the organization had reasonable protections in place and what options people affected may have.
When Did This Breach Occur?
Rockland BOCES says it found the incident on August 12, 2026. The letter does not state the date the unauthorized access started or ended, and it does not give the date the notices were mailed. The notification was posted publicly in September 2026.
State laws generally require notice without unreasonable delay once an investigation shows personal information may have been involved. The gap between discovery and notice here is about one month.
What Information Was Breached?
The letter says the email account may have held the recipient’s personal information, such as test data. Rockland BOCES has not published a full list of data types, and it does not say whether Social Security numbers, financial details, or health information were involved.
Because the details are limited, anyone who got a notice should treat it seriously and read it closely. Test data can be sensitive on its own, particularly for minors, and may be paired with other identifying information in the same account.
What You Can Do
If you received a notice from Rockland BOCES, consider these steps:
- Enroll in the free credit monitoring through Cyberscout before the 90-day deadline, using the code on your letter.
- Review your credit reports and bank statements and report anything you do not recognize.
- Consider placing a fraud alert or a free security freeze with Equifax, Experian, and TransUnion.
- If a child received the notice, ask the credit bureaus about a freeze for a minor.
- Be careful with emails or calls that mention the school or your records, since scammers use breach news to look convincing.
File a Data Breach Lawsuit Against Rockland BOCES
People whose personal information may have been exposed in a data breach can have legal options, including joining a class action against the organization responsible. A class action lets many affected people pursue claims together, without each person paying to bring a case alone.
Attorneys are investigating whether Rockland BOCES failed to protect the information entrusted to it. If you got a notice letter, you may be eligible to take part.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.