Public records project

Worcester Cybersecurity Records Project

Reconstructing the July 30, 2026 phishing incident and Worcester Public Schools’ handling of it — from the records the district itself produced.

On the morning of July 30, 2026, a phishing message reached a Worcester family. The records request filed about it was then caught by the City’s own phishing filter. An appeal, a 184,407-result search, a zero-result Vault screen for a key employee, and a second search that produced 118 pages followed. This project assembles that record from the produced documents themselves.

July 30, 2026
phishing incident
10:37 AM
records request filed
SPR26/3372
appeal docket
118 pages
second-search production
Oct 12, 2026
next production (~594 pages)

Last updated: October 1, 2026

What the records establish

  • The campaign was real, and the preserved recipient copy was not ordinary display-name spoofing: Gmail recorded SPF, DKIM and DMARC passes and the recomputed signed body hash matched the body containing the Netlify link.
  • Worcester’s technical response was fast — an investigation opened within minutes of the earliest produced campaign row, and a bulk deletion completed by 8:43:37 a.m.
  • That first recorded deletion pass was not reported as 100 percent successful: 581 attempts, 570 successes, 11 failures.
  • Jean Pray was in fact communicating about the incident. The second search produced her alerting Paul Johnson about the secure email and describing broad BCC distribution.
  • Paul Johnson wrote that he reset Tammy Murray’s password and emailed “Bob Walt.”
  • The initial Jean Pray zero-result search did not exhaust the responsive records. Worcester itself said the September 18 inquiry led to the second search.
  • The public-records process materially changed the factual picture: the later evidence produced internal communications that directly addressed questions posed in the original July 30 request.

What the records do not establish

  • That 584 people received the message. 584 is a spreadsheet row count.
  • That 581 unique people or mailboxes were targeted.
  • That nobody clicked the link, or that anyone submitted credentials or other information.
  • That the 11 failed deletion attempts remained visible in inboxes.
  • That the nine later-timestamped spreadsheet rows were delivered after cleanup.
  • That Dr. Murray personally sent the message, or that any particular access mechanism was used.
  • That Dr. Murray’s Drive, contacts, student records, Vault or other Workspace resources were accessed.
  • Why the original Jean Pray search was constructed with the particular string shown in the Vault screenshot.
  • Any intentional withholding by Worcester or any particular employee.
  • That the 118 pages are 118 pages of cybersecurity evidence. A page-by-page review puts the incident-specific material on pages 66, 68, 69, 71, 72, 76, 87 and 104; the balance is ordinary administrative content.

Timeline

  1. July 30, 2026 — incident. A message subject “Worcester Public Schools,” sent under Dr. Tammy Murray’s district address, offered a “secure message” hosted at murraytammy.netlify.app. Gmail recorded SPF, DKIM and DMARC passes for worcesterschools.net, and an independently recomputed DKIM body hash matched the signed body. This establishes an authenticated Worcester-authorized sending path; it does not identify who used it.
  2. July 30, 8:35–8:43 a.m. — technical response. Worcester’s Google Workspace audit shows an investigation created at 8:39:46 a.m., content accessed at 8:41:05 with the justification “phishing investigation,” and a bulk deletion completing at 8:43:37 a.m. — 581 attempted, 570 succeeded, 11 failed.
  3. July 30, 10:37 a.m. — records request filed with an immediate preservation notice to the City’s records access officer, copied to the Superintendent, the district’s counsel and others.
  4. July 30 — written notice. Separate security notices went to the Superintendent and School Committee members at about 1:51, 2:05, 2:09 and 2:20 p.m. Eastern, and a Rule 31 public petition was filed at 6:59 p.m.
  5. August 13, 2026 — School Committee. The petition appeared on the official agenda as c&p 6-13, recommending “Refer to Administration.” No approved-minute record of the final motion or vote has been located.
  6. August 25, 2026 — appeal. With no written response, exemption claim, fee estimate or production located, an appeal was filed with the Massachusetts Supervisor of Records. A separate Netlify-specific appeal was filed the same night and remains a distinct track.
  7. August 26, 2026 — Worcester explains the nonresponse. Records Access Officer Michael Manning wrote that the July 30 request had triggered the City’s own phishing rule and been diverted into a quarantined folder he could not access, and that he had not been notified of the diversion. He opened it as W094042-082626.
  8. September 1 and 3, 2026 — SPR26/3372. The Supervisor acknowledged the appeal, then ordered Worcester to respond within ten business days, expressly preserving the right to appeal the substantive response.
  9. September 10, 2026 — first substantive response. Searching the request’s terms individually returned approximately 184,407 responsive communications. Worcester proposed combined-term searches and no more than six of them; the requester agreed to narrow. Worcester reported no responsive records for Item 4F (notification, public warning, regulatory reporting).
  10. September 11, 2026 — partial production. Items 4A and 4B produced call-detail material, technical records and search screenshots, redacted under Exemptions (a), (b) and (c). A Google Vault screen for Jean Pray reported Count 0 under a nine-term query.
  11. September 18, 2026 — the search is questioned. The narrowed 4D search produced 550 “hits” and a waived fee. The same day, the requester asked whether the Vault terms had been run conjunctively, whether the zero-result finding rested on that query alone, and whether broader searches had been run.
  12. September 29, 2026 — second search, 118 pages. Worcester stated that the September 18 inquiry led to a second search “which returned a result of 118 pages of email correspondences,” and produced them.
  13. October 12, 2026 — next production. Approximately 594 pages were reported as under review, with about one-fifth reviewed as of September 30.

Open questions for the next production

  • What was the final technical determination about the sending mechanism?
  • Did Worcester conclude that a mailbox, session, OAuth token, delegation, API access or relay had been compromised or misused?
  • How many unique recipients or mailboxes received the message, and can they be categorised without disclosing personally identifiable information?
  • What explains the difference between 584 campaign rows and 581 deletion attempts?
  • What caused the 11 deletion failures, and were all 11 remediated?
  • Were campaign-wide click or form-submission metrics available?
  • What is the complete native thread behind page 69 and the other clipped records?
  • What did Paul Johnson communicate to Bob Walt, and what followed?
  • What systems, custodians and query logic supported the September 10 no-records statement for Item 4F?
  • Was there a written incident report, root-cause analysis or after-action review?
  • What was the final School Committee disposition of c&p 6-13 on August 13?
  • Was any direct notice ultimately sent to known or potentially affected recipients, and if so when and through what channel?

Add to this record

If you hold a responsive record from this incident — a call log, a ticket, an internal email, or a copy of something Worcester produced — send it to us. Corrections to anything published here are welcome.