
A former IT employee of an Iowa school district received a 21-month prison sentence for carrying out a long-term cyberattack against his previous employer, which disrupted classroom activities, erased accounts, and led to tens of thousands of dollars in losses.
According to court documents, Ezekiel Dean Potter, 34, served as a senior IT support specialist for the Saydel Community School District in Des Moines from May 2022 through April 2023.
Prosecutors allege that following the termination of his employment, Potter kept his access credentials and relentlessly attacked the district’s systems over a 21-month span.
"For over a year and a half, Defendant was a plague on the Saydel Community School District," the U.S. government stated in a sentencing memorandum.
"He deleted SCSD’s Facebook page, stripped its employees of access to educational platforms and accounts, and tried again and again to reset its employees’ usernames and passwords for various other platforms and accounts."
Prosecutors asserted that the attacks caused significant disruption to the school district, hindered its capacity to educate students, and incurred tens of thousands of dollars in recovery expenses.
Court documents indicate the attacks started shortly after Potter left the district, when Saydel's Facebook account was removed.
Prosecutors claim Potter subsequently targeted the district’s Apple School Manager account, erasing user accounts, passwords, phone numbers, billing information, and device management server data.
This action effectively blocked school employees from using the Apple School Manager platform and disabled management of district MacBooks and iPads for roughly one week while staff worked with Apple to restore access.
The district also faced unauthorized access attempts against its GoDaddy account and other online services.
Court documents further state that in January 2025, Potter accessed the district’s Schoology learning management system via a Google administrator account and removed an IT employee’s account, disrupting teacher access to the platform and affecting classes for approximately two hours.
One week later, prosecutors allege Potter accessed another administrator account and deleted nine Gmail accounts belonging to current and former district employees, including the district’s IT director and superintendent.
Court filings indicate that Potter later began using a VPN service after receiving Google security alerts about unauthorized account access.
Federal investigators eventually traced some of the activity to IP addresses linked to Potter’s other employers, including Casey’s Store Support Center and The Printer Inc. (TPI).
After Potter left TPI in January 2025, prosecutors say he asked a former coworker to retrieve and wipe a USB drive from his desk.
Instead, the coworker handed it over to investigators, who reportedly discovered spreadsheets containing usernames and passwords for Saydel School District accounts and services.
Potter pleaded guilty in January 2026 to computer fraud charges under the Computer Fraud and Abuse Act without entering into a plea agreement.
On June 11, Potter was sentenced to 21 months in prison, followed by three years of supervised release.
As part of his supervised release conditions, Potter will face restrictions and monitoring related to employment, finances, and computer systems, including searches of electronic devices upon reasonable suspicion.
Potter is also required to pay $59,668.81 in restitution to the Saydel Community School District and its insurer, Travelers Casualty and Surety Company, for recovery costs associated with the attacks.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
PowerSchool hacker claims they stole data of 62 million students
PowerSchool hack exposes student, teacher data from K-12 districts
UN food agency discloses breach affecting 600,000 Gaza households
Instructure hacker claims data theft from 8,800 schools, universities
Cosmetics giant Rituals discloses data breach affecting customers