# Former Iowa School Employee Sentenced to 21 Months for Year-Long Cyberattack on District Systems


A federal judge has handed down a significant sentence against a former IT employee who conducted a sophisticated, prolonged cyberattack against his previous employer, underscoring the persistent threat posed by disgruntled insiders with retained system access.


Ezekiel Dean Potter, 34, was sentenced on June 11, 2026, to 21 months in prison for computer fraud charges related to a 21-month campaign of disruptions against the Saydel Community School District in Des Moines, Iowa. The attacks—which included deleting accounts, wiping cloud storage, and disabling critical educational platforms—caused tens of thousands of dollars in damage and repeatedly interrupted classroom operations.


## Background: Employment and Access Retention


Potter worked as a senior IT support specialist for Saydel Community School District from May 2022 through April 2023. His role provided him with privileged access to the district's IT infrastructure, cloud services, and administrative accounts—access that proved critical to the subsequent attacks.


After his employment ended in April 2023, Potter retained his credentials and system access, a security failure that enabled the attacks to begin almost immediately. Rather than immediately revoking all access upon termination, the district's access management procedures left multiple pathways open for a former employee with malicious intent.


The attacks that followed would span 21 months and strike at multiple layers of the district's digital infrastructure, from social media presence to educational platforms to email systems.


## The Campaign: Systematic Destruction


Court documents paint a picture of calculated and escalating attacks designed to maximize disruption while evading detection:


Initial Strikes (April 2023)


The attacks began shortly after Potter's departure with the deletion of the Saydel Community School District's Facebook page—a symbolic first target that eliminated the district's public social media presence.


Apple School Manager Compromise (Timeline Unspecified)


Potter targeted the district's Apple School Manager account, one of the most critical infrastructure points for an institution managing multiple MacBooks and iPads. His actions included:


  • Deletion of user accounts
  • Removal of passwords and authentication data
  • Extraction of phone numbers and billing information
  • Destruction of device management server data

  • The attack rendered the Apple School Manager platform inaccessible to school staff for approximately one week while administrators worked with Apple to restore access and rebuild device management capabilities.


    Cloud Service Targeting


    The attack extended to GoDaddy and other online service accounts, demonstrating Potter's familiarity with the full scope of the district's digital footprint.


    Learning Management System Compromise (January 2025)


    In January 2025, nearly two years after his departure, Potter accessed the district's Schoology learning management system through a compromised Google administrator account. He deleted the account of an IT employee, immediately disrupting teacher access to the platform and impacting classroom instruction for approximately two hours.


    Email System Attacks (Late January 2025)


    A week after the Schoology attack, Potter escalated further by accessing another administrator account and deleting nine Gmail accounts belonging to current and former district employees, including the IT director and superintendent. These deletions created cascading authentication failures across email-dependent systems and workflows.


    ## Evasion Tactics and Operational Security


    As the investigation intensified and Potter received Google security alerts warning of unauthorized account access, he shifted to using a VPN service to mask his IP address and location. This operational security measure—switching tactics mid-campaign when detection increased—suggests awareness of law enforcement investigation techniques.


    Federal investigators eventually traced portions of Potter's activity to IP addresses associated with his subsequent employers, Casey's Store Support Center and The Printer Inc. (TPI), indicating he may have launched attacks from work networks at multiple subsequent jobs.


    ## Investigation and Evidence


    The breakthrough in the investigation came not from digital forensics alone, but from human intervention. After Potter left TPI in January 2025, he allegedly asked a former coworker to retrieve and wipe a USB drive from his desk. The coworker, either unwilling to assist or suspicious of the request, instead turned the USB drive over to federal investigators.


    That decision proved decisive. The USB drive contained spreadsheets listing usernames and passwords for Saydel School District accounts and services—documentary evidence of Potter's unauthorized access and clear proof of intent.


    Potter pleaded guilty in January 2026 to Computer Fraud and Abuse Act violations without entering into a plea agreement, likely acknowledging the strength of the evidence against him.


    ## Sentencing and Restitution


    On June 11, 2026, Potter received a sentence of 21 months in federal prison followed by three years of supervised release. The conditions of his supervised release include:


  • Restrictions and monitoring related to employment
  • Financial monitoring and restrictions
  • Mandatory searches of electronic devices upon reasonable suspicion
  • Prohibition from IT-related work during supervised release

  • Potter was ordered to pay $59,668.81 in restitution to the Saydel Community School District and its insurer, Travelers Casualty and Surety Company, to cover remediation costs, system recovery, IT staff time, and downtime expenses.


    ## Implications for K-12 School Districts


    This case represents a textbook example of insider threat risks in educational institutions, where IT staff often have broad system access to support diverse technological needs—from classroom devices to administrative systems to communication platforms.


    Key Risk Factors Exposed:


    | Area | Risk | Observed in Case |

    |------|------|------------------|

    | Access Control | Failure to revoke credentials upon termination | Potter retained access months after departure |

    | Privilege Management | Broad administrative access granted to individual contributors | Potter could delete accounts at multiple privilege levels |

    | Monitoring | Inadequate alerting on account deletions and unauthorized access | Attacks continued undetected for extended periods |

    | Separation Procedures | Insufficient offboarding process | No documented credential revocation protocol |

    | Audit Trails | Weak logging or analysis of administrative activities | Took 21 months to detect systematic account deletions |


    ## Recommendations for Educational Institutions


    Immediate Actions:


    1. Conduct access audits: Review all former employee accounts and verify complete credential revocation for terminations within the past 24 months

    2. Implement conditional access policies: Require multi-factor authentication for all administrative accounts and enforce IP restrictions

    3. Enable comprehensive logging: Configure audit trails for all account modifications, platform access, and administrative actions


    Systemic Changes:


    1. Zero-trust architecture: Assume no insider should have persistent access—require re-authentication for sensitive operations

    2. Privilege access management (PAM): Deploy a separate, hardened PAM system for administrative credentials with immutable audit logs

    3. Separation of duties: Prevent any single individual from having unilateral control over critical systems

    4. Offboarding automation: Use automated workflows to revoke access across all systems simultaneously upon termination

    5. Threat detection: Deploy user and entity behavior analytics (UEBA) to flag patterns like account deletion sprees or access from unusual locations


    ---


    ## HackWire Analysis


    This case reveals a pattern that extends far beyond education: the insider threat problem isn't primarily about external breach sophistication—it's about systemic failures in access governance that allow disgruntled employees to maintain privilege long after employment ends.


    Potter had every advantage that defenders should have controlled: he was a known person with a known departure date, not an anonymous external attacker. Yet 21 months of systematic account deletion across multiple platforms went undetected until a USB drive surfaced. This isn't a sophisticated exploit—it's a failure of operational discipline at the foundation of security.


    What makes this case important *now* is the timing: we're seeing a wave of K-12 ransomware incidents, but this case demonstrates that IT staff departures pose equally severe risks when access management fails. The financial impact ($59K in direct costs) mirrors what many districts are experiencing, but this one was entirely preventable through:


    1. Automated credential revocation: An offboarding workflow that revokes all access on day one

    2. Immutable audit logs: Detecting systematic account deletions should have triggered alerts within hours, not months

    3. Monitoring administrative actions: A simple policy that flags when any account deletes 5+ accounts in a week


    The pattern extends beyond education. Any organization with high employee turnover (fast-growing tech companies, staffing firms, contractors) faces similar risk. The difference is whether you've built the infrastructure to detect and respond.


    For IT directors in school districts especially: this sentence should prompt immediate conversations with your superintendent about whether your termination procedures include automated access revocation and audit monitoring. If they don't, you're operating in Potter's threat model.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)