Public records project
Worcester Cybersecurity Records Project
Reconstructing the July 30, 2026 phishing incident and Worcester Public Schools’ handling of it — from the records the district itself produced.
On the morning of July 30, 2026, a phishing message reached a Worcester family. The records request filed about it was then caught by the City’s own phishing filter. An appeal, a 184,407-result search, a zero-result Vault screen for a key employee, and a second search that produced 118 pages followed. This project assembles that record from the produced documents themselves.
Last updated: October 1, 2026
What the records establish
- The campaign was real, and the preserved recipient copy was not ordinary display-name spoofing: Gmail recorded SPF, DKIM and DMARC passes and the recomputed signed body hash matched the body containing the Netlify link.
- Worcester’s technical response was fast — an investigation opened within minutes of the earliest produced campaign row, and a bulk deletion completed by 8:43:37 a.m.
- That first recorded deletion pass was not reported as 100 percent successful: 581 attempts, 570 successes, 11 failures.
- Jean Pray was in fact communicating about the incident. The second search produced her alerting Paul Johnson about the secure email and describing broad BCC distribution.
- Paul Johnson wrote that he reset Tammy Murray’s password and emailed “Bob Walt.”
- The initial Jean Pray zero-result search did not exhaust the responsive records. Worcester itself said the September 18 inquiry led to the second search.
- The public-records process materially changed the factual picture: the later evidence produced internal communications that directly addressed questions posed in the original July 30 request.
What the records do not establish
- That 584 people received the message. 584 is a spreadsheet row count.
- That 581 unique people or mailboxes were targeted.
- That nobody clicked the link, or that anyone submitted credentials or other information.
- That the 11 failed deletion attempts remained visible in inboxes.
- That the nine later-timestamped spreadsheet rows were delivered after cleanup.
- That Dr. Murray personally sent the message, or that any particular access mechanism was used.
- That Dr. Murray’s Drive, contacts, student records, Vault or other Workspace resources were accessed.
- Why the original Jean Pray search was constructed with the particular string shown in the Vault screenshot.
- Any intentional withholding by Worcester or any particular employee.
- That the 118 pages are 118 pages of cybersecurity evidence. A page-by-page review puts the incident-specific material on pages 66, 68, 69, 71, 72, 76, 87 and 104; the balance is ordinary administrative content.
Timeline
- July 30, 2026 — incident. A message subject “Worcester Public Schools,” sent under Dr. Tammy Murray’s district address, offered a “secure message” hosted at murraytammy.netlify.app. Gmail recorded SPF, DKIM and DMARC passes for worcesterschools.net, and an independently recomputed DKIM body hash matched the signed body. This establishes an authenticated Worcester-authorized sending path; it does not identify who used it.
- July 30, 8:35–8:43 a.m. — technical response. Worcester’s Google Workspace audit shows an investigation created at 8:39:46 a.m., content accessed at 8:41:05 with the justification “phishing investigation,” and a bulk deletion completing at 8:43:37 a.m. — 581 attempted, 570 succeeded, 11 failed.
- July 30, 10:37 a.m. — records request filed with an immediate preservation notice to the City’s records access officer, copied to the Superintendent, the district’s counsel and others.
- July 30 — written notice. Separate security notices went to the Superintendent and School Committee members at about 1:51, 2:05, 2:09 and 2:20 p.m. Eastern, and a Rule 31 public petition was filed at 6:59 p.m.
- August 13, 2026 — School Committee. The petition appeared on the official agenda as c&p 6-13, recommending “Refer to Administration.” No approved-minute record of the final motion or vote has been located.
- August 25, 2026 — appeal. With no written response, exemption claim, fee estimate or production located, an appeal was filed with the Massachusetts Supervisor of Records. A separate Netlify-specific appeal was filed the same night and remains a distinct track.
- August 26, 2026 — Worcester explains the nonresponse. Records Access Officer Michael Manning wrote that the July 30 request had triggered the City’s own phishing rule and been diverted into a quarantined folder he could not access, and that he had not been notified of the diversion. He opened it as W094042-082626.
- September 1 and 3, 2026 — SPR26/3372. The Supervisor acknowledged the appeal, then ordered Worcester to respond within ten business days, expressly preserving the right to appeal the substantive response.
- September 10, 2026 — first substantive response. Searching the request’s terms individually returned approximately 184,407 responsive communications. Worcester proposed combined-term searches and no more than six of them; the requester agreed to narrow. Worcester reported no responsive records for Item 4F (notification, public warning, regulatory reporting).
- September 11, 2026 — partial production. Items 4A and 4B produced call-detail material, technical records and search screenshots, redacted under Exemptions (a), (b) and (c). A Google Vault screen for Jean Pray reported Count 0 under a nine-term query.
- September 18, 2026 — the search is questioned. The narrowed 4D search produced 550 “hits” and a waived fee. The same day, the requester asked whether the Vault terms had been run conjunctively, whether the zero-result finding rested on that query alone, and whether broader searches had been run.
- September 29, 2026 — second search, 118 pages. Worcester stated that the September 18 inquiry led to a second search “which returned a result of 118 pages of email correspondences,” and produced them.
- October 12, 2026 — next production. Approximately 594 pages were reported as under review, with about one-fifth reviewed as of September 30.
Key records from the 118-page production
Eight incident-specific pages, plus the official August 13 agenda item. The remaining 110 pages of the production are routine administrative material. The full production is a redacted public-records document containing third-party material, so only these crops are published.









Open questions for the next production
- What was the final technical determination about the sending mechanism?
- Did Worcester conclude that a mailbox, session, OAuth token, delegation, API access or relay had been compromised or misused?
- How many unique recipients or mailboxes received the message, and can they be categorised without disclosing personally identifiable information?
- What explains the difference between 584 campaign rows and 581 deletion attempts?
- What caused the 11 deletion failures, and were all 11 remediated?
- Were campaign-wide click or form-submission metrics available?
- What is the complete native thread behind page 69 and the other clipped records?
- What did Paul Johnson communicate to Bob Walt, and what followed?
- What systems, custodians and query logic supported the September 10 no-records statement for Item 4F?
- Was there a written incident report, root-cause analysis or after-action review?
- What was the final School Committee disposition of c&p 6-13 on August 13?
- Was any direct notice ultimately sent to known or potentially affected recipients, and if so when and through what channel?
Add to this record
If you hold a responsive record from this incident — a call log, a ticket, an internal email, or a copy of something Worcester produced — send it to us. Corrections to anything published here are welcome.
