Former Saydel Community School District IT employee Ezekiel Dean Potter was sentenced to 21 months in prison after prosecutors said he carried out a prolonged cyber sabotage campaign against the Iowa district following his April 2023 termination. Authorities said Potter kept access to more than 300 district credentials and, from May 2023 through January 2025, used them to delete accounts, take down the district’s Facebook page, interfere with Apple School Manager, target GoDaddy, and compromise Google/Gmail, PowerSchool Schoology, and other school services.
The intrusions locked teachers out of platforms, disrupted classrooms, and caused tens of thousands of dollars in losses, with reported direct costs exceeding $73,000 and restitution set at $59,668.81. Investigators tied the activity to Potter through forensic evidence including IP addresses linked to later employers, activity traced despite VPN use, and a USB drive containing spreadsheets of district usernames and passwords. Potter pleaded guilty in January 2026 to computer fraud charges under the Computer Fraud and Abuse Act and was also ordered to serve supervised release with computer-use monitoring conditions.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Potter was sentenced to 21 months in prison for the prolonged cyberattack campaign against Saydel Community School District. He was also ordered to pay $59,668.81 in restitution and serve supervised release with computer-use monitoring conditions.
In January 2026, Potter pleaded guilty to computer fraud charges under the Computer Fraud and Abuse Act for the attacks on his former employer.
From May 2023 through January 2025, Potter used retained credentials to target systems including Apple School Manager, Schoology, Gmail, GoDaddy, PowerSchool, and the district's Facebook account, causing teacher lockouts and classroom disruption. Investigators later tied some activity to IP addresses from Potter's later employers and recovered a USB drive containing district usernames and passwords.
The charging narrative described the unauthorized activity against Saydel Community School District as continuing through January 2025.
Prosecutors said Potter retained district credentials and began a prolonged unauthorized access and sabotage campaign against Saydel Community School District in May 2023. The activity included deleting accounts and disrupting district-managed services.
The former IT employee's employment with Saydel Community School District ended in April 2023, which preceded the later unauthorized activity against the district.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.