A phishing message reached a Worcester family on the morning of July 30, 2026. The records request filed about it was then caught by Worcester’s own phishing filter. What followed — an appeal, a 184,407-result search, a zero-result Vault screen for a key employee, and a second search that produced 118 pages — is reconstructed here from the produced records themselves.
A phishing message reached a Worcester Public Schools parent on the morning of July 30, 2026. Within minutes, Worcester’s own security tools were investigating and deleting matching messages. Within hours, the incident had been reported to Special Education, IT, the Superintendent, members of the School Committee, the district’s Special Education Director, a reporter, and the City’s records office.
But the public record of what happened did not emerge all at once.
It came out in stages: an unanswered records request that Worcester later said had itself been caught by the City’s phishing filter; an appeal to the Massachusetts Supervisor of Records; a first search that produced more than 184,000 communications; negotiated narrowing; partial technical records showing hundreds of message-log entries and a bulk deletion operation; a Google Vault search screen that reported zero results for a key employee; a question about how that search had been constructed; and then, after Worcester conducted a second search, 118 pages of additional emails.
Those later emails contained the kind of internal incident-response communications the earlier search had not surfaced.
This article reconstructs that process chronologically. The full record set is collected on the Worcester Cybersecurity Records Project page. It distinguishes what Worcester’s own records establish, what was documented contemporaneously by Parent Data Force, what remains unresolved, and what should not be inferred from the evidence.
This is a working article. Additional responsive records were still being reviewed by Worcester as of September 30, and Records Access Officer Michael Manning said roughly 594 pages were expected in the next production. Any later records may add to or modify parts of this account.

1. THE MESSAGE
The earliest timestamp in Worcester’s later-produced campaign spreadsheet is 8:35:24 a.m. Eastern on July 30.
The suspicious email preserved by the affected family carried the subject line “Worcester Public Schools.” It displayed the sender as “Murray, Tammy” using Dr. Tammy Murray’s Worcester Public Schools address. The body told the recipient that a secure message had been sent and displayed “Expires: Never.” The “View Secure Message” link did not lead to a Worcester Public Schools domain. It pointed to:
murraytammy.netlify.app
The preserved recipient copy listed “undisclosed-recipients” in the To field and directly identified one parent as a Bcc recipient.
The message’s own Date header corresponds to 8:37:38 a.m. Eastern. Google transport headers in the preserved EML show receipt at approximately 8:38:15 to 8:38:16 a.m.
The family began forwarding the suspicious message almost immediately. a family member forwarded it at approximately 8:42 a.m. to Desiree Anderson, and it reached Parent Data Force roughly two minutes later.
That rapid forwarding mattered. It preserved a recipient copy of the original message before the linked site disappeared and before the later public-records process began.

2. WORCESTER’S TECHNICAL RESPONSE STARTED QUICKLY
The records Worcester later produced show that the district’s technical response began within minutes of the earliest known campaign activity.
The 4C spreadsheet produced under public-records request W094042-082626 contains 584 rows, all bearing the subject “Worcester Public Schools” and the sender address murrayt@worcesterschools.net. Those 584 rows are not 584 confirmed people. The file does not contain a unique-recipient field, and multiple rows can correspond to the same mailbox, message, or logging event.
The rows contain 36 distinct RFC Message-ID values and run from 8:35:24 through 8:45:48 a.m.
Most of the recorded activity was tightly concentrated. An earlier evidence review calculated that 557 of the 584 rows occurred between 8:36 and 8:38 a.m.
Worcester’s Google Workspace audit then shows:
8:39:46 a.m. — a security investigation was created.
8:39:58 a.m. — an administrator searched Gmail data for the sender murrayt@worcesterschools.net.
8:40:41 a.m. — email headers were viewed.
8:41:05 a.m. — message content was accessed with the stated justification “phishing investigation.”
8:41:46 a.m. — the search was narrowed using the sender and subject “Worcester Public Schools.”
8:42:42 a.m. — a MAIL_SOFT_DELETE action was launched against selected Gmail messages.
8:43:37 a.m. — that deletion action completed.
The completion record states:
Total attempted: 581 Successes: 570 Failures: 11
That is significant evidence of a fast containment effort. From the earliest row in the produced campaign spreadsheet to completion of the recorded deletion operation was a little more than eight minutes.
But the same records also impose limits on what can responsibly be said.
The 11 failures do not prove that 11 malicious emails remained visible in users’ inboxes. Worcester has not yet produced the failure reasons or follow-up remediation for each failed item.
The 584 spreadsheet rows and 581 deletion attempts differ by three. The current production does not establish why. Different query scopes, duplicate handling, timing, or later-arriving log entries are all possible.
Nine rows in the spreadsheet have timestamps later than the 8:43:37 deletion-completion time. That deserves explanation, but the spreadsheet does not contain enough delivery-status information to establish that nine live phishing emails were delivered after cleanup.
The technical evidence supports a prompt response. It does not yet answer every question about scope, recipient count, click activity, failed deletion remediation, or root cause.
The Worcester Google Workspace audit export and the 584-row campaign spreadsheet that carry these timestamps were produced to the project only through the City’s online records portal and were not part of the preserved handoff, so no image is reproduced here; the audit sequence and its completion record — 581 attempted, 570 succeeded, 11 failed — are described in the text above.
3. THE 8:53 A.M. CALL
At approximately 8:53 a.m., Parent Data Force called Worcester Public Schools Special Education at 508-799-3055.
The call was documented that same day in the original public-records request as lasting 6 minutes and 28 seconds. The caller recorded that he spoke with a woman who identified herself as “Jean,” who said the message was spam, that it had gone to multiple families, and that she had communicated with IT. The request also recorded that, when asked whether the public had been notified, no public notification had yet been issued at that point.
Minutes later, Parent Data Force amended the written record to emphasize that Jean had said she had reached out to IT.
The later Worcester production identifies the relevant employee as Jean Pray.
The call-detail records do not, however, contain one single row that cleanly matches both the reported 8:53 time and the reported 6:28 duration. They show multiple call events associated with Jean Pray around the relevant period, including an 8:49:03 transfer lasting 4:49 and an 8:57:03 call lasting 0:35.
A transferred telephone conversation can be stored in multiple call legs, so the mismatch does not disprove the contemporaneous account. It does mean the current call-detail sheet is not enough to reconstruct the entire call with precision. A PBX or VoIP call-chain export, recording, transcript, or complete call notes would resolve that question if those records exist.
What became important later was that Jean’s identity — and her contact with IT — were not merely a detail from a phone conversation. A second records search eventually produced her internal emails about the incident.
The Jean Pray call-detail sheet was part of the same portal-only production and is not reproduced here; the call legs it contained, including the 8:49:03 transfer lasting 4:49 and the 8:57:03 call lasting 0:35, are described in the text above.
4. THE FIRST WRITTEN WARNINGS
Before the forensic analysis existed, the incident was already being described in urgent terms. At 9:01 a.m., Parent Data Force forwarded the suspicious message to reporter Michael Carolan under the subject line “WORCESTER SCHOOLS HACKED,” warning him not to click the link and reporting what Jean had said about spam being sent to multiple families and the absence of public notice at that point.
That subject line was a contemporaneous characterization, not a forensic finding. At 9:01 a.m., the original EML had not yet been analyzed and the later Worcester audit records did not yet exist. The finished article therefore preserves that email as part of the chronology without adopting “hacked” as an established description of the root cause.
At approximately 9:07 a.m., Parent Data Force forwarded the suspicious message to Dr. Murray, copying district counsel and the Superintendent’s office. The email documented the 8:53 call and asked Worcester to determine the extent to which the affected family’s information or records may have been compromised.
At 9:16 a.m., Parent Data Force sent an amendment specifically preserving the statement that Jean had said she contacted IT.
At 9:19 a.m., another amendment stated that the linked page had requested multiple layers of sensitive private information and that the affected parent had clicked the link.
Those statements were made before the later public-records productions existed. They are important because they create a contemporaneous written record of what Parent Data Force believed had occurred and what information had been reported by the family and by Jean.
They should not be confused with later forensic proof. The live Netlify page became unavailable, and the later technical report expressly declined to claim the precise form fields, scripts, or data-collection behavior of the vanished site.
District counsel Paige Tobin responded at 10:08 a.m., stating that she represented the district in the Stella Gleason matter and asking that communications be directed to her rather than her clients.
The cybersecurity inquiry continued separately.
5. THE PUBLIC-RECORDS REQUEST WAS FILED THE SAME MORNING
At 10:37 a.m., Parent Data Force sent Worcester an “URGENT PUBLIC RECORDS REQUEST / PRESERVATION NOTICE.”
The request was unusually specific.
It preserved the reported 8:53 call, the 6:28 duration, Jean’s statements about IT and multiple families, the message subject, the sender address, the Netlify domain, the secure-message lure, and an RFC Message-ID.
It asked Worcester to preserve and produce records concerning:
the identity of Jean and her communications with IT;
telephone and call-detail records;
the original message and full headers;
message-trace and mail-flow records;
aggregate delivery and recipient information without family or student personally identifiable information;
internal incident-response communications;
security investigation and audit records;
containment and recovery actions;
records concerning public or affected-person notification;
communications with regulators, law enforcement, insurers, vendors, or other outside entities;
and the policies, retention rules, and preservation steps actually used.
The request specifically asked for rolling production of readily available records and told Worcester not to restore backup media solely for the request without first identifying the missing record, backup source, cost, and less expensive alternatives.
It also requested efficient electronic search and redaction and asked to be notified before fees were incurred.
At 8:18 p.m. that night, Parent Data Force sent a clarification stating that the supplement did not replace, withdraw, narrow, or restart the original request.
The later records dispute would turn, in part, on how Worcester searched this request.

6. THE ORIGINAL EML CHANGED THE TECHNICAL QUESTION
At 12:56 p.m., a family member forwarded the original “Worcester Public Schools.eml” file to Parent Data Force.
A preliminary forensic review of that EML was then completed.
The report found that the recipient’s Gmail system recorded SPF, DKIM, and DMARC as passing for worcesterschools.net. The DKIM signature used Worcester’s domain and Google selector, and an independent recalculation of the DKIM relaxed-body hash exactly matched the signed body hash stored in the message.
The signed MIME body contained the Netlify destination.
The careful conclusion in that report was not that Dr. Murray personally sent the phishing email, nor that her entire account had necessarily been “hacked.”
The report’s conclusion was narrower: the evidence supported use or misuse of an authenticated Worcester-authorized email-sending path. Ordinary unauthenticated display-name spoofing was not an adequate explanation for the preserved recipient copy.
That distinction still matters.
Email authentication can establish that a message traveled through an authorized domain-sending pathway. It does not, by itself, identify the human actor or reveal whether the mechanism was a compromised password, stolen session, OAuth token, delegated access, “send as” configuration, API, relay, insider activity, or some other authorized sending mechanism.
Those questions require Worcester’s internal logs.
The report also directly confirmed one Bcc recipient. It did not establish the total number of recipients.

7. IT SAID IT WAS AWARE AND HAD “DEALT WITH IT”
By early afternoon, Parent Data Force had also called Worcester IT.
A contemporaneous 2:16 p.m. email to reporter Michael Carolan records the substance of that conversation: “The IT department told me that they are aware and have ‘dealt with it’ but I have not gotten any confirmation of their intent to notify affected families.”
That statement is evidence of what Parent Data Force reported being told by IT. It is not an IT-authored written statement, and the article should treat it accordingly.
The later Google Workspace records independently show that IT had, in fact, opened a security investigation and conducted a bulk deletion operation before 8:44 that morning.
So there are two separate points supported by different evidence: the contemporaneous account that IT said it had “dealt with it,” and the later-produced audit records showing rapid technical investigation and remediation activity.
What remained unresolved was what “dealt with it” meant beyond that initial containment work.
8. THE SUPERINTENDENT AND SCHOOL COMMITTEE WERE NOTIFIED IN WRITING
At approximately 1:51 p.m. Eastern, Parent Data Force sent Superintendent Brian Allen and Worcester School Committee members an email titled:
“Urgent Security Notice and Request for Independent Review of Authenticated Phishing Email.”
The preliminary forensic report was attached.
The email explained that the analysis did not identify the person who sent the message or establish the exact access mechanism. It asked Worcester to preserve evidence and obtain a competent security review to determine how the message was sent, all recipients and distribution sources, whether other information or Workspace resources were accessed, whether persistent access mechanisms were involved, whether additional malicious messages were sent, what containment decisions had been made, and whether affected individuals or public authorities required notification.
At approximately 2:05 p.m., a supplemental report concerning the phishing landing page and family notification was sent to the same group, with Dr. Murray and affected-family addresses copied.
At approximately 2:09 p.m., another email emphasized that the communication was a good-faith security notification and not an accusation that Dr. Murray or Worcester Public Schools had intentionally created or distributed the phishing message.
At 2:20 p.m., Parent Data Force sent both reports together and again requested notice to affected recipients — or a broader systemwide advisory if the scope could not yet be reliably limited — along with instructions for anyone who clicked, preservation of relevant records, a review of whether the incident was limited to one mailbox, and an explanation of the factual basis for any conclusion that the incident had been fully contained.
The repeated emails are important for chronology. Whatever Worcester knew internally before those messages, the Superintendent and the listed School Committee members were placed on direct written notice of the concern that afternoon.
The current source set does not yet establish the Committee’s individual responses, if any, to those July 30 emails.


8A. WHAT CAME BACK IN WRITING — AND WHAT DID NOT
The connected Gmail record shows no direct reply in any of the seven dedicated July 30 security-notice threads sent to the Superintendent, School Committee members, or Dr. Murray. Each of those threads contains the outgoing Parent Data Force message and no reply.
That does not prove that no district official discussed the matter internally, responded through another channel, or took action. The later internal production proves that WPS personnel were communicating about the incident. It means only that, in the connected mailbox reviewed for this project, no substantive written reply from those recipients appears in the dedicated external security-notice threads.
The first clear written institutional response to the advocacy track came through the School Committee process: the petition was accepted for agenda placement and the clerk’s office later confirmed speaking rights under Rule 31.
That gap between internal technical action and external written communication is one of the reasons the public-records request became central to the investigation.
8B. THE REPORTER ASKED THE QUESTION THE EVIDENCE COULD NOT YET ANSWER
The same afternoon, Parent Data Force sent the forensic report to reporter Michael Carolan.
Carolan replied with three basic questions: did the evidence mean someone inside Worcester Public Schools sent the message; could another IT professional corroborate the analysis; and could the recipients be identified?
The response correctly stated that Parent Data Force was not claiming a Worcester employee had sent the message and that the evidence showed an authorized Worcester-domain sending path.
A second follow-up used stronger wording, saying the evidence proved whoever sent the message “must have access to the sped director’s google workspace.”
That statement went beyond what the forensic report itself established.
The report’s actual conclusion was broader and more careful: an authenticated Worcester-authorized sending path had been used, but the EML alone could not determine whether the mechanism was the Murray mailbox itself, a stolen session, delegated access, OAuth, an API or relay, a send-as configuration, or another district-authorized pathway.
The later records show that Paul Johnson reset Murray’s password, but they still do not establish the final root-cause mechanism.
This distinction is retained in the article because the project is a reconstruction, not a rewrite of the past. The contemporaneous emails show how the understanding developed in real time; later analysis must not silently convert an early, stronger characterization into a proven fact.
9. THE ISSUE BECAME A FORMAL SCHOOL COMMITTEE PETITION
At 6:59 p.m. on July 30, Parent Data Force filed a public petition under Worcester School Committee Rule 31.
The petition was titled:
“Cybersecurity Review, Incident Response, and Mandatory Notification of Affected Students, Families, and Employees.”
It expressly stated that it did not accuse any particular employee of knowingly participating in the incident.
Instead, it asked the full School Committee to consider oversight measures including an independent third-party review, evidence preservation, a determination of the number and categories of people who received or interacted with the message, an assessment of whether protected information had been exposed or placed at risk, a written incident-notification policy, a process for reporting cybersecurity incidents, training and exercises, and an annual de-identified cybersecurity report.
The petition asked for an initial public report within 30 days and a proposed incident-notification policy within 60 days.
The next morning, July 31, the petition was forwarded to Kaycee Caracciolo in the School Committee office.
On August 10, Caracciolo wrote that the petitions Parent Data Force had filed had been placed on the August 13 School Committee agenda.
When Parent Data Force asked whether each petition could be addressed, Caracciolo quoted Rule 31 and confirmed on August 11 that the author could speak for three minutes on each petition submitted.
The official August 13 agenda confirms that the cybersecurity petition appeared as c&p 6-13. Its agenda description asked the full School Committee to discuss and vote on directing the administration to provide a public report and proposed corrective action concerning cybersecurity safeguards, incident response, and notification of affected members of the school community.
The agenda’s listed recommendation was “Refer to Administration.”
The official WEA-TV 11 archive contains the full August 13 meeting recording. A transcript-derived Citizen Portal summary of that official video identifies the reported phishing incident as one of the meeting’s public-comment topics. Citizen Portal expressly labels its transcript and summaries as AI-generated, so this article does not treat that secondary summary as a substitute for official minutes.
The official agenda itself listed “Refer to Administration” as the recommendation for c&p 6-13. As of this review, an official approved-minute record stating the exact motion, vote count, and final disposition of c&p 6-13 has not yet been located in the project source set. The article therefore reports the agenda recommendation and the existence of the official meeting video, but does not invent an exact vote result.
This distinction matters because an agenda recommendation is not itself proof of what a public body ultimately voted to do.
A final speech prepared for the August 13 meeting also survives in the project record. It recounts the July 30 sequence and asks for a forensic scope audit, preservation, public reporting, direct notice where appropriate, and a written notification policy. The draft article will distinguish that prepared speech from the official meeting record until delivery and final Committee action are verified.

9A. A PARALLEL NETLIFY TRACK
The July 30 investigation did not stay inside Worcester.
At 2:33 p.m. Eastern, Parent Data Force filed a second, separate public-records request focused on whether Worcester Public Schools or the City had any legitimate prior relationship with Netlify or related domains.
That request sought records concerning Netlify use, accounts, projects, procurement, support contacts, security or abuse reports, firewall and web-filter records, WPS email addresses associated with Netlify, and records specifically concerning murraytammy.netlify.app.
The purpose was expressly framed as non-accusatory: determine whether the Netlify-hosted page had any legitimate district relationship or whether it appeared to be unauthorized.
One minute later, at 2:34 p.m., Parent Data Force sent Netlify a good-faith abuse report and preservation request concerning murraytammy.netlify.app. The message asked Netlify to preserve project, account, deployment, authentication, traffic, security, support, and takedown records. It expressly stated that it was a preservation request and did not ask Netlify to disclose nonpublic subscriber information without appropriate legal process.
No responsive email from a Netlify address has yet been located in the connected Gmail source set reviewed for this project.
By August 25, Parent Data Force also treated the Netlify-specific Worcester request as unanswered and filed a separate appeal with the Supervisor of Records.
That appeal should remain a distinct track in the article. The current source set has not yet established a separate Worcester tracking number or final Supervisor docket specifically tied to the Netlify-only request, so it should not be merged into SPR26/3372 unless a later source confirms that relationship.


10. THEN THE RECORDS REQUEST DISAPPEARED INTO A PHISHING FILTER
The July 30 public-records request did not receive a normal response within the expected period.
By August 25, Parent Data Force had located no written acknowledgment, fee estimate, exemption claim, production schedule, clarification request, time petition, or substantive production responsive to that July 30 request.
An appeal was filed with the Massachusetts Supervisor of Records.
The filing history that night was more complicated than a single email. Between approximately 11:39 p.m. and 11:44 p.m. Eastern on August 25, Parent Data Force sent several closely related appeal messages:
- 11:39:45 p.m. — the initial phishing-incident nonresponse appeal, with a complete HTML copy of the July 30 request.
- 11:41:51 p.m. — a separate appeal concerning the unanswered Netlify-specific records request.
- 11:43:50 p.m. — a “REPLACEMENT / COMPLETE EXHIBITS” version of the main phishing appeal, attaching the original July 30 request.
- 11:44:32 p.m. — an expanded main-incident appeal restating the requested categories and attaching the two technical reports.
The main July 30 phishing-request appeal ultimately became SPR26/3372. The Netlify-specific appeal remains a separate track in this project; no source reviewed so far establishes that it shared the SPR26/3372 docket.
The multiple same-night filings matter mainly for evidentiary housekeeping. They show that the appeal record was supplemented and corrected in real time, rather than existing as one pristine filing from the outset.
The next day, August 26, Worcester Records Access Officer Michael Manning gave an explanation that was unusual because of the subject of the request itself.
Manning wrote that he had not been in receipt of the July 30 request. After consulting the City’s Department of Innovation & Technology, he said he learned that the request had triggered the City’s phishing rule and had been diverted into a quarantined folder he could not access. He also said he had not been notified that the email had been diverted.
In other words, according to Worcester’s written explanation, the public-records request about a phishing incident was itself caught by Worcester’s phishing controls.
Once Manning received the request through the appeal correspondence, he opened it in the City’s system as:
W094042-082626
Parent Data Force responded positively to the explanation and noted that the safeguard appeared to be working as intended. The dispute at that stage was not framed as an accusation that Manning had deliberately ignored the July request.

11. THE SUPERVISOR OF RECORDS ISSUED A FORMAL ORDER
The appeal became SPR26/3372.
The Supervisor of Records acknowledged the appeal on September 1.
On September 3, Supervisor Manza Arthur issued a determination stating that the appeal concerned Worcester’s nonresponse to the July 30 request for records concerning the phishing incident.
The determination noted that Worcester intended to provide a written response and ordered the City to do so in accordance with the Public Records Law within ten business days. Worcester was also ordered to provide a copy of its response to the Supervisor.
The determination expressly preserved Parent Data Force’s right to appeal the substantive nature of Worcester’s response.
That order is a key point in the timeline. The records process had moved from an unanswered request to a formal state public-records case.

12. THE FIRST SEARCH WAS TOO LARGE TO BE USEFUL
Worcester’s first substantive response arrived on the evening of September 10.
For Item 4D — the request for internal communications and incident chronology — Worcester reported that searching the supplied terms individually resulted in approximately:
184,407 responsive communications.
Manning suggested modifying the request so the technology team could use combinations of terms rather than searching each term independently. He gave examples such as “secure message AND Netlify,” “MFA AND incident,” and “quarantine AND purge” and recommended no more than six separate searches.
For Item 4F — notification, public warning, and regulatory-reporting records — Manning wrote that it was his understanding that there were no responsive records.
That statement should be reported precisely.
It means Worcester reported that it had identified no responsive records for that category under the search and review then performed. It is not, by itself, proof that no notification discussion ever occurred, and it does not establish which custodians, systems, or search methods supported the no-records conclusion.
Worcester also extended the response period for the balance of the request and said records would be produced on a rolling basis as they became available.
Parent Data Force agreed to narrow the search using the approach Manning proposed.
This cooperation is part of the record. The later search-method dispute did not begin because Parent Data Force refused narrowing. It arose after narrowing had already been accepted and after the first technical productions were reviewed.
13. THE FIRST PARTIAL PRODUCTION IDENTIFIED JEAN — BUT ALSO CREATED NEW QUESTIONS
On September 11, Worcester produced a partial response to Items 4A and 4B.
The production included call-detail information, technical records, and search screenshots. Worcester explained redactions under several exemptions and said additional responsive records were expected.
Manning also suggested a further narrowing of Item 4D: combine names of staff members who may have been involved with phishing-related terms and limit the date range to roughly a week before and a week after the incident.
Parent Data Force agreed.
The partial production established that the “Jean” involved in the July 30 Special Education telephone call was Jean Pray.
But the call-detail sheet did not contain one clean 6-minute-28-second row matching the original reported call.
And the Jean Pray search material contained something more consequential: a Google Vault screenshot showing a Gmail search for Jean Pray using the Terms field:
Netlify phishing spam affected families notification public IT findings
The screen reported:
Count 0 Accounts with matches 0
A companion Chat search also showed no matches.
At first glance, that could have been read to mean Jean Pray had no responsive Gmail or Chat records.
But the structure of the search itself raised a problem.
14. THE SEARCH-METHODOLOGY QUESTION THAT CHANGED THE RECORD
Google Vault documentation explains that, for Gmail searches, multiple unconnected terms are generally treated as though AND appears between them.
That matters because a query containing:
Netlify phishing spam affected families notification public IT findings
may require a message to satisfy all of those terms, rather than any one of them.
A highly relevant email could therefore discuss a “secure email,” a password reset, multiple recipients, or contact with IT and still fail to match because it did not also contain every other term in the string.
On September 18, after reviewing the Worcester search screenshots, Parent Data Force sent Manning a narrow clarification.
The email asked three questions:
Was the Jean Pray Gmail search actually run conjunctively as an AND search?
Was the zero-result finding based solely on that query?
Were separate or broader searches also run for Jean’s July 30 communications with IT?
The email expressly stated that Parent Data Force was not trying to expand the request or undo the agreed extension. The point was to determine whether responsive Item 4A records had been inadvertently excluded by the query structure.
Manning replied that he would check with WPS IT.
That exchange became the turning point in the records investigation.
The Google Vault screenshot showing the zero-result search was part of the same portal-only production and is not reproduced here; the query string it recorded and the two zero-result lines it reported are quoted in the text above.

15. AT THE SAME TIME, WORCESTER HAD NARROWED 184,000 RESULTS TO 550
Also on September 18, Worcester provided two additional spreadsheets and reported that the narrowed internal-communications search produced 550 “hits.”
Manning estimated that segregation and redaction would exceed the two free hours of labor, but said the resulting fee would be relatively minor — under $50 — and waived it because Parent Data Force had substantially narrowed the request from approximately 184,000 results to 550.
He proposed an October 12 production date.
Parent Data Force agreed.
That exchange is important because the later Jean Pray second search did not replace the pending 550-hit internal-communications production. They became parallel tracks: one broad, narrowed set still being reviewed for October, and one specific reexamination of whether the Jean Pray search had missed responsive material.
16. THE TECHNICAL PRODUCTION SHOWED BOTH FAST CONTAINMENT AND UNANSWERED SCOPE QUESTIONS
By September 18, the rolling production allowed a much clearer reconstruction of the morning of July 30.
The evidence showed a rapid security response.
The earliest campaign row was 8:35:24 a.m. The Google Workspace investigation opened at 8:39:46. The bulk deletion operation completed at 8:43:37.
That is strong evidence that Worcester’s technical staff moved quickly.
The same evidence also showed that the first recorded deletion pass reported 11 failures and that the produced campaign spreadsheet contained 584 rows while the deletion operation attempted 581 items.
The production did not yet identify the failed items, explain the three-item numerical difference, or show whether the failures were subsequently resolved.
It also did not provide a unique-recipient count.
That distinction is critical.
The number 584 should not be published as “584 people affected.” It is a spreadsheet row count.
Likewise, 581 deletion attempts are not proof of 581 people.
The current evidence also does not establish how many people clicked the phishing link or entered information.
One email-log screenshot in the production shows one specific message copy as Deleted and “Unopened and unread, Unseen.” That is useful evidence for that one message copy. It cannot be generalized to the campaign as a whole.
The public record, as of September 18, therefore supported a more nuanced conclusion than either “nothing happened” or “hundreds of people were compromised.”
There was a real authenticated phishing event. Worcester’s technical response appears to have been rapid. The size and human impact of the event remained unresolved.
16A. WHAT THE ROLLING PRODUCTION ACTUALLY CONSISTED OF
By the September 18 stage, the project source set included several distinct Worcester production files rather than one single “cyber report.”
One was a four-page IncidentIQ all-tickets PDF for July 30. It included ticket #31041, labeled “Google Mail – Request Access > Issue not listed,” shown as In Progress in the produced screenshot. The available page does not establish that ticket #31041 concerned the phishing incident, because its body, comments, requester details, and complete history were not produced clearly enough to make that connection.
Another file, Public_Records_Request-_W094042-082626__4B_Remediation.xlsx, contains the seven-row Google Workspace audit sequence underlying the technical timeline: investigation creation, sender search, header review, content access with “phishing investigation” justification, sender-and-subject query, MAIL_SOFT_DELETE, and the 581-attempt/570-success/11-failure completion record.
A third file, Public_Records_Request-_W094042-082626_4C.xlsx, contains 584 data rows with Subject, Message ID, Date, and Sender. It is the basis for the campaign timing analysis, but it does not contain the unique-recipient, click, form-submission, or per-row remediation fields needed to convert those rows into a count of affected people.
The mixed 4A material also contained Jean Pray call details, Gmail/Chat Vault search screenshots, IncidentIQ search material, and email-log screens.
Two of those screens illustrate why “zero results” had to be interpreted cautiously.
One IncidentIQ search was limited to Created Date July 30 and Requestor = Jean Pray and returned “No items match these conditions.” That shows only that no matching ticket appeared with Jean configured as the requestor under that filter. It does not exclude a phishing ticket opened by IT, another employee, or a different workflow.
A separate email-log search returned zero results for an external recipient while the same screen warned: “The given recipient is not a user in your domain.” That zero cannot safely be treated as proof that the external person never received the message.
These details matter because the dispute was never simply about whether Worcester “searched.” The question became whether each search was capable of answering the factual question for which it was being cited.
17. SEPTEMBER 29: WORCESTER RAN A SECOND SEARCH
On September 29, Worcester issued a formal Records Center response that directly linked the second search to the September 18 questions.
Manning wrote:
“Based on inquiries raised in your correspondence to this Office on September 18, 2026, the Worcester Public Schools conducted a second search for additional responsive email correspondences which returned a result of 118 pages of email correspondences.”
Those 118 pages were then produced.
This is one of the clearest cause-and-effect points in the entire records timeline.
An earlier Jean Pray search screenshot reported zero results.
Parent Data Force questioned the search construction.
Worcester conducted a second search.
That second search returned 118 pages.
The safe conclusion is not that Worcester intentionally hid the records. The evidence currently available does not establish intent.
The supported conclusion is that the earlier search did not exhaust the responsive Jean Pray material, and the later search materially changed the evidentiary record.

18. THE 118-PAGE PRODUCTION CONTAINED THE INTERNAL EMAILS THE STORY HAD BEEN MISSING
Several pages in the September 29 Jean Pray production are central to reconstructing the incident.
On page 72, under the subject “SECURE EMAIL from Tammy Murray,” Jean Pray wrote to Paul Johnson that a secure email from Tammy Murray had been BCC’d to “alot of people in the district as well as other districts,” based on information she had received from Deanna C.
On page 71, Paul Johnson replied that he had reset Tammy’s password, notified her, and emailed “Bob Walt.”
On page 68, Jean replied “Thank you!” in that chain.
Those records independently corroborate several elements that had previously existed only in contemporaneous accounts: that Jean was communicating with IT about the incident, that the message was understood to have reached people beyond a single recipient, and that at least one password-reset response occurred.
They also add details that were not known from the original call account, including Paul Johnson’s reference to emailing Bob Walt.
Another key record appears on page 69.
Jean emailed Tammy Murray in a thread titled “Important Update Re: Advocate Email/Phone Calls.” She wrote that Joey Ford had just called, that Jean Grady had texted Tammy, that the secure email had gone to other districts and calls were coming from other districts, and that the parent Joey was involved with had received and forwarded the message to him.
The page then ends mid-sentence after:
“I did let him know that Paige Tobin would be acting”
That abrupt ending became the next records issue.



18A. WHAT THE FULL 118 PAGES ACTUALLY CONTAIN
A page-by-page review of the entire Jean Pray production changes the way the 118-page number should be understood.
The production is not 118 pages of cybersecurity evidence.
The clearest incident-specific material is concentrated on eight pages: 66, 68, 69, 71, 72, 76, 87, and 104.
Pages 66, 68, 71, and 72 form the “SECURE EMAIL from Tammy Murray” chain involving Jean Pray and Paul Johnson.
Page 69 is Jean’s “Important Update Re: Advocate Email/Phone Calls” message to Tammy Murray.
Page 76 is a rendered copy of the phishing email itself.
Page 87 is Deanna Carlson’s reply to Tammy Murray in the “Important Update” thread.
Page 104 is Deanna Carlson’s later reply to attorney Paige Tobin in that same subject chain.




Most of the balance consists of ordinary administrative material: student-records processing, releases, ESY payroll and mileage, timesheets, conference-room calendar messages, transportation requests, staffing/leave messages, and other office workflow. Several later pages concern a separate BSEA/DESE matter and are not evidence about the phishing incident.
That distinction is important in both directions.
It prevents the article from exaggerating the significance of the phrase “118 pages.” The second search did not uncover 118 pages of damaging cyber correspondence.
But it also sharpens the significance of the records it did uncover. Buried inside an otherwise routine administrative production were direct incident-response messages that answered questions the original July 30 request had specifically asked about: Jean’s contact with IT, the reported breadth of distribution, a password reset, and additional people pulled into the incident-response chain.
The page-by-page review also strengthens the completeness concern surrounding page 69. The produced page ends after “I did let him know that Paige Tobin would be acting,” and page 70 begins an unrelated student-records spreadsheet thread. In other words, the continuation is not simply sitting on the next page of the PDF.
A second apparent clipping occurs on page 100, where an unrelated records-processing email from Jean ends “Done! All special educati…”. Because two different messages appear cut off in the same production, the possibility of a conversion/export problem is more concrete than it would be from page 69 alone.
A separate review index has been created for the full 118-page production so that the article can distinguish key incident pages from unrelated administrative material without repeatedly re-reading the entire file.



19. THE SECOND SEARCH PRODUCED RECORDS — AND EXPOSED NEW COMPLETENESS PROBLEMS
The production itself arrived after another small exchange. On the morning of September 29, Parent Data Force emailed Manning because the expected records had not appeared in the inbox. After a phone call later that day, Manning wrote that the email correspondences they had discussed should have been received and that additional responsive records were expected no later than October 12.
Parent Data Force reviewed the 118-page production and immediately raised several specific concerns with Manning.
Page 69 appeared to stop in the middle of a sentence.
Another record around page 100 also appeared clipped.
The “Important Update Re: Advocate Email/Phone Calls” thread appeared to contain replies without the originating message or instruction that had prompted them.
The newly produced “SECURE EMAIL” chain referenced Paul Johnson emailing Bob Walt, but the referenced follow-up was not visible in the same production.
Jean’s email also referenced Jean Grady texting Tammy.
Parent Data Force asked Worcester to check the native/source messages and determine whether the production contained incomplete exports or whether additional responsive records existed.
The email did not accuse Worcester of intentional withholding. It framed the problem as a completeness issue that could arise from export or search methodology.
Manning responded that he would review the concerns and, where necessary, contact Worcester Public Schools for completed extracts.
For the referenced incident-response chain, he asked to first review the approximately 500 email correspondences already expected in the larger October production, so WPS IT would not need to perform a duplicate search for records Manning might already have.
The records investigation had therefore entered another stage: not just “find the emails,” but “determine whether the produced thread is complete.”
20. BY SEPTEMBER 30, ANOTHER LARGE PRODUCTION WAS STILL COMING
On September 30, Manning wrote that his quick count indicated approximately 594 pages of responsive records for the upcoming production.
He said he had reviewed only about one-fifth of them at that point. Many of the records he had seen appeared administrative or duplicative, but he expressly cautioned that this could change as the review continued.
He also acknowledged a new narrow request for specific communications and said he had not yet checked with WPS IT about how easily those records could be pulled.
That means this reconstruction is not the end of the Worcester story.
As of September 30, the record already establishes substantially more than was visible in July or even in the first September production. This project joins the settlement-records work tracked at the Massachusetts Student Settlement Records Project; both are listed on the projects index. But another large body of records remained under review.
21. WHAT THE RECORDS ESTABLISH NOW
The strongest current findings can be stated without speculation.
First, the phishing campaign was real, and the preserved recipient copy was not ordinary unauthenticated display-name spoofing. Gmail recorded Worcester-domain SPF, DKIM, and DMARC passes, and the independently recomputed signed body hash matched the body containing the Netlify phishing link.
Second, the technical response was fast. Worcester’s Google Workspace audit shows an investigation beginning within minutes of the earliest produced campaign row and a bulk deletion operation completing by 8:43:37 a.m.
Third, that first recorded deletion operation was not reported as 100 percent successful: 581 attempts, 570 successes, 11 failures. The current records do not establish what happened to each failed item afterward.
Fourth, the human scope remains unknown. The 584 spreadsheet rows are not a unique-person count. The current production does not establish a campaign-wide click count or submission count.
Fifth, Jean Pray was in fact communicating about the incident. The second search produced emails in which she alerted Paul Johnson about the secure email and described broad BCC distribution.
Sixth, Paul Johnson wrote that he reset Tammy Murray’s password and emailed Bob Walt.
Seventh, the initial Jean Pray zero-result search did not exhaust the responsive records. Worcester itself stated that the September 18 inquiry led to a second search that returned 118 pages.
Eighth, the public-records process materially changed the factual picture. The later evidence did not merely add volume. It produced internal communications that directly addressed questions posed in the original July 30 request.
22. WHAT THE RECORDS DO NOT ESTABLISH
Several claims remain unsupported and should not be published as fact.
The current evidence does not establish that 584 people received the phishing message.
It does not establish that 581 unique people or mailboxes were targeted.
It does not establish that nobody clicked the link.
It does not establish that anyone submitted credentials or other information.
It does not establish that the 11 failed deletion attempts remained in inboxes.
It does not establish that the nine later-timestamped spreadsheet rows were successfully delivered after the deletion operation.
It does not establish that Dr. Murray personally sent the message.
It does not establish the precise technical mechanism that allowed the authenticated Worcester-domain message to be sent.
It does not establish that Dr. Murray’s Google Drive, contacts, student records, Google Vault, or other Workspace resources were accessed.
It does not establish why the original Jean Pray search was constructed using the particular string shown in the Vault screenshot.
And the present record does not establish intentional withholding by Worcester or any particular employee.
Those distinctions are not technicalities. They are the difference between documenting what the evidence shows and building a story around assumptions.
23. THE NOTIFICATION QUESTION REMAINS SEPARATE FROM THE CONTAINMENT QUESTION
One of the central issues raised on July 30 was whether potentially affected families should receive notice.
The technical records later showed that Worcester moved quickly to investigate and remove matching messages.
That does not, by itself, answer the notification question.
On September 10, Worcester reported no responsive records to Item 4F, which sought records concerning public warning, affected-person notification, regulatory reporting, and reasons for issuing or not issuing notice.
The current production does not establish the exact search methodology behind that no-records position.
Nor does the absence of responsive 4F records prove that Worcester had a legal duty to issue a particular notice.
Whether a legal breach-notification obligation exists can depend on facts that remain unresolved: what information was accessed or acquired, what systems were affected, what recipients did, and what the investigation ultimately determined.
The factual question for this project is therefore narrower and answerable through records:
What investigation was completed, what did it determine about scope and risk, what notification analysis was performed, and what records document that decision?
That is the question the July 30 request, the School Committee petition, and the later records follow-ups have continued to pursue.
24. WHY THE SEARCH PROCESS MATTERS
Public-records disputes can seem procedural when separated from the underlying event.
Here, the procedure is part of the substance.
The first request was quarantined.
The appeal caused it to be opened as W094042-082626.
The Supervisor ordered a response.
The first internal-communications search produced more than 184,000 results.
The requester agreed to narrow.
The narrowed search produced 550 hits.
The first Jean Pray Vault screenshot showed zero Gmail results.
The requester questioned the query logic.
Worcester conducted a second search.
The second search produced 118 pages.
Those pages contained Jean’s emails to IT and Paul Johnson’s password-reset response.
The requester then found clipped or apparently incomplete threads.
Worcester agreed to review the completeness concerns while another approximately 594 pages remained under review.
That sequence is why the records process belongs in the main story. Every record cited above is catalogued, with its disposition, on the Worcester Cybersecurity Records Project page.
Without it, readers would see a collection of emails and technical logs without understanding how they surfaced — or why some of the most important records were not present in the first search results.
25. THE STORY SO FAR
The July 30 phishing incident is not a story in which Worcester did nothing.
The records show the opposite on the technical side: IT appears to have recognized the malicious mail quickly, opened an investigation, inspected the message, narrowed the campaign, and launched a bulk deletion operation within minutes.
But rapid containment did not answer every question about what happened.
It did not determine for the public how the authenticated sending path was misused.
It did not establish the unique number of recipients.
It did not establish whether any recipient submitted information.
It did not explain the 11 recorded deletion failures.
It did not, in the records produced so far, supply a final root-cause or scope determination.
And it did not make the public-records process straightforward.
That process moved from a quarantined request, to a state appeal and order, to an enormous 184,407-communication search, to negotiated narrowing, to a zero-result search for a key employee, to a challenge over query construction, to a second search yielding 118 pages of internal emails.
Those internal emails are now part of the record because the search was questioned.
The next production may answer some of the remaining questions. It may also create new ones.
For now, the evidence supports two conclusions at the same time: Worcester’s technical staff moved quickly against the phishing campaign, and the full public account of the incident has taken months of requests, appeals, narrowing, search review, and follow-up to assemble.
26. OPEN QUESTIONS FOR THE NEXT PRODUCTION
The next records pass should focus on issues that remain unresolved in the present source set:
- What was the final technical determination about the sending mechanism?
- Did Worcester conclude that Dr. Murray’s mailbox, session, OAuth access, delegation, API access, relay, or another authorized sending path had been compromised or misused?
- How many unique recipients or mailboxes received the message?
- Can recipients be categorized — for example, district staff, families, external districts, or other recipients — without disclosing personally identifiable information?
- What explains the difference between 584 campaign spreadsheet rows and 581 deletion attempts?
- What caused the 11 deletion failures, and were all 11 later remediated?
- Were campaign-wide click or form-submission metrics available, and if so what do they show?
- What is the complete native thread behind page 69 and the other clipped records?
- What did Paul Johnson communicate to Bob Walt, and what follow-up occurred?
- What was the substance of Jean Grady’s text to Tammy Murray, if preserved and responsive?
- What systems, custodians, and query logic supported Worcester’s September 10 statement that there were no responsive records to Item 4F?
- Was there a written incident report, root-cause analysis, after-action review, or security-incident closeout record?
- What was the final School Committee disposition of c&p 6-13 on August 13?
- Was any direct notice ultimately sent to known or potentially affected recipients, and if so when and through what channel?
- Were any state or federal agencies, law enforcement entities, insurers, vendors, or outside forensic specialists notified or consulted?
Until those questions are answered, this article should remain a living reconstruction rather than a final forensic conclusion.
If you have a responsive record from this incident, or a correction to anything above, write to Parent Data Force.

Leave a Reply
You must be logged in to post a comment.