Saydel Community School District

A former Saydel Community School District IT employee used retained credentials from at least May 14, 2023, through January 2025 to access district systems and disrupt accounts, classroom platforms and managed devices. Ezekiel Dean Potter pleaded guilty to computer fraud and was sentenced June 11, 2026, to 21 months in prison and $59,668.81 in restitution.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malicious or negligent actions by an authorized insider resulting in cyber impact.
Theft, exposure, or abuse of user or administrator credentials.
Unauthorized access to systems, accounts, networks, or data.
Data was intentionally deleted, wiped, destroyed, or made permanently unrecoverable.
Data was intentionally changed, falsified, manipulated, or otherwise modified without authorization.
Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
A specific application or software platform became unavailable or unusable.
Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that Saydel Community School District experienced a sustained insider-linked cyber-sabotage campaign after a former IT employee retained privileged credentials. A federal charging record placed the admitted conduct from at least May 14, 2023, through at least January 16, 2025. The U.S. Attorney’s Office for the Southern District of Iowa later said Ezekiel Dean Potter downloaded more than 300 district usernames and passwords before his April 2023 termination and used them to access or attempt to access district accounts and applications. Potter pleaded guilty to computer fraud and was sentenced June 11, 2026, to 21 months in prison, three years of supervised release and $59,668.81 in restitution.
DysruptionHub’s published report said the activity included deleting the district’s Facebook page, disabling Apple device management, attempting to interfere with website hosting, temporarily disabling Schoology and deleting employee email accounts. The conduct was intentional, repeated and operationally disruptive rather than a single isolated access event.
Federal prosecutors said the attacks caused districtwide technology outages and required substantial remediation by district staff. The campaign culminated in January 2025 attacks on district applications that suspended classes for multiple hours. Schoology was temporarily unavailable during a school day, preventing teachers from using the learning platform for instruction.
The offender also interfered with Apple School Manager, which impaired management of district MacBooks and iPads, and deleted or revoked access to employee accounts and other district resources. These actions affected classroom technology, staff authentication and administrative control over managed devices. January 16, 2025, is the latest specific date in the charged conduct; no later operational impact was found.
The strongest public evidence comes from the federal prosecution, public court records and reporting based on sentencing materials. The Justice Department’s account is directly authoritative and documents both the malicious computer activity and material disruption, supporting an OC-OD classification. This does not mean Saydel published the operational account: the district did not appear to issue a detailed public statement identifying the full campaign, its duration or its effects. The case became fully documented through prosecution and sentencing rather than contemporaneous district disclosure.
The malicious activity ended by January 2025, and the identified offender was prosecuted and sentenced in June 2026. The known incident is therefore resolved, although public records do not establish whether the district completed every credential, identity and device-management remediation measure prompted by the campaign.
Confidence is high in the cyber characterization, disruption and offender identification because the conclusions are supported by a guilty plea, sentencing evidence and a federal prosecution. This is not ransomware or extortion. The primary mechanism was unauthorized use of retained credentials by a former trusted employee, followed by account deletion, access revocation and sabotage of district services.
The record also establishes a data-security impact: Potter possessed hundreds of district credentials and other sensitive district information on a USB drive. Public reporting does not establish that student or employee personal information beyond credentials was disclosed to third parties or publicly released.
The public record does not provide a complete event-by-event timeline, identify every compromised account, or establish how long each outage lasted. It also does not explain whether multi-factor authentication was enabled, how former-employee access was revoked, which recovery controls failed, or whether the district conducted a broader notification or independent security review.

Saydel Community School District’s administrative office is in the Marquisville area, an unincorporated locality in Polk County that uses a Des Moines mailing address. Marquisville is not an incorporated municipality and does not have an official municipal boundary.
DysruptionHub reported that former Saydel IT worker Ezekiel Dean Potter disrupted classroom technology, staff accounts and district-managed devices for about 21 months after leaving the district. The conduct included deleting accounts, disabling device management and temporarily taking Schoology offline.
The U.S. Attorney’s Office said a federal grand jury charged Potter on October 15, 2025. The indictment alleged unauthorized access, password resets, account deletion and revoked access from at least May 14, 2023, through at least January 16, 2025, causing widespread operational disruption and tens of thousands of dollars in losses. Potter later pleaded guilty to the charged count.
The Justice Department said Potter downloaded more than 300 district usernames and passwords before termination and used them over the next year and a half to disrupt district accounts and applications. The attacks caused districtwide technology outages and culminated in January 2025 attacks that suspended classes for multiple hours.
Signed-in members can report an error, update, or missing source.