Former Saydel IT worker sabotaged school systems
Summary
A former Saydel Community School District IT employee used retained credentials from at least May 14, 2023, through January 2025 to access district systems and disrupt accounts, classroom platforms and managed devices. Ezekiel Dean Potter pleaded guilty to computer fraud and was sentenced June 11, 2026, to 21 months in prison and $59,668.81 in restitution.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing. -
Incident end:
?
Confirmed or defensibly assessed end of material operational disruption or incident activity.
Primary victim organization
Impacted locations
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Insider threat
Malicious or negligent actions by an authorized insider resulting in cyber impact.
-
Credential compromise
Theft, exposure, or abuse of user or administrator credentials.
-
Unauthorized access
Unauthorized access to systems, accounts, networks, or data.
Data impacts
-
Data deletion or destruction
Data was intentionally deleted, wiped, destroyed, or made permanently unrecoverable.
-
Data alteration or manipulation
Data was intentionally changed, falsified, manipulated, or otherwise modified without authorization.
-
Data exposure
Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.
Operational impacts
-
Educational operations disrupted
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
-
Application unavailable
A specific application or software platform became unavailable or unusable.
-
Authentication disruption
Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
Extortion indicators
-
No known extortion indicator
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that Saydel Community School District experienced a sustained insider-linked cyber-sabotage campaign after a former IT employee retained privileged credentials. A federal charging record placed the admitted conduct from at least May 14, 2023, through at least January 16, 2025. The U.S. Attorney’s Office for the Southern District of Iowa later said Ezekiel Dean Potter downloaded more than 300 district usernames and passwords before his April 2023 termination and used them to access or attempt to access district accounts and applications. Potter pleaded guilty to computer fraud and was sentenced June 11, 2026, to 21 months in prison, three years of supervised release and $59,668.81 in restitution.
DysruptionHub’s published report said the activity included deleting the district’s Facebook page, disabling Apple device management, attempting to interfere with website hosting, temporarily disabling Schoology and deleting employee email accounts. The conduct was intentional, repeated and operationally disruptive rather than a single isolated access event.
Operational significance
Federal prosecutors said the attacks caused districtwide technology outages and required substantial remediation by district staff. The campaign culminated in January 2025 attacks on district applications that suspended classes for multiple hours. Schoology was temporarily unavailable during a school day, preventing teachers from using the learning platform for instruction.
The offender also interfered with Apple School Manager, which impaired management of district MacBooks and iPads, and deleted or revoked access to employee accounts and other district resources. These actions affected classroom technology, staff authentication and administrative control over managed devices. January 16, 2025, is the latest specific date in the charged conduct; no later operational impact was found.
Disclosure posture
The strongest public evidence comes from the federal prosecution, public court records and reporting based on sentencing materials. The Justice Department’s account is directly authoritative and documents both the malicious computer activity and material disruption, supporting an OC-OD classification. This does not mean Saydel published the operational account: the district did not appear to issue a detailed public statement identifying the full campaign, its duration or its effects. The case became fully documented through prosecution and sentencing rather than contemporaneous district disclosure.
Current status
The malicious activity ended by January 2025, and the identified offender was prosecuted and sentenced in June 2026. The known incident is therefore resolved, although public records do not establish whether the district completed every credential, identity and device-management remediation measure prompted by the campaign.
Confidence and uncertainty
Confidence is high in the cyber characterization, disruption and offender identification because the conclusions are supported by a guilty plea, sentencing evidence and a federal prosecution. This is not ransomware or extortion. The primary mechanism was unauthorized use of retained credentials by a former trusted employee, followed by account deletion, access revocation and sabotage of district services.
The record also establishes a data-security impact: Potter possessed hundreds of district credentials and other sensitive district information on a USB drive. Public reporting does not establish that student or employee personal information beyond credentials was disclosed to third parties or publicly released.
Analytic gaps
The public record does not provide a complete event-by-event timeline, identify every compromised account, or establish how long each outage lasted. It also does not explain whether multi-factor authentication was enabled, how former-employee access was revoked, which recovery controls failed, or whether the district conducted a broader notification or independent security review.
Organizations involved
Saydel Community School District

Locations
Organization type
Critical infrastructure
Impacted locations
Marquisville, Iowa
Saydel Community School District’s administrative office is in the Marquisville area, an unincorporated locality in Polk County that uses a Des Moines mailing address. Marquisville is not an incorporated municipality and does not have an official municipal boundary.
Saydel Community School District, Iowa
Sources
DysruptionHub reported that former Saydel IT worker Ezekiel Dean Potter disrupted classroom technology, staff accounts and district-managed devices for about 21 months after leaving the district. The conduct included deleting accounts, disabling device management and temporarily taking Schoology offline.
The Justice Department said Potter downloaded more than 300 district usernames and passwords before termination and used them over the next year and a half to disrupt district accounts and applications. The attacks caused districtwide technology outages and culminated in January 2025 attacks that suspended classes for multiple hours.
The district’s official website identifies Saydel Community School District and its three schools in Polk County, Iowa. The site provides the district office address and confirms the organization’s public K-12 identity.
The U.S. Attorney’s Office said a federal grand jury charged Potter on October 15, 2025. The indictment alleged unauthorized access, password resets, account deletion and revoked access from at least May 14, 2023, through at least January 16, 2025, causing widespread operational disruption and tens of thousands of dollars in losses. Potter later pleaded guilty to the charged count.
See something that needs correction?
Signed-in members can report an error, update, or missing source.