On October 2, BleepingComputer reported that Frontline Education is notifying school districts of a data breach. Attackers exploited a vulnerability in third-party software, reached Frontline systems, and stole employee information including Social Security numbers. That article is the source I used.
Frontline sits in the middle of thousands of districts that never picked that third-party component. The hole was in a dependency, not the district's own server. District IT will still own the staff phone calls.
School-district HR data is a quiet path into tax fraud. If I worked at a district on Frontline, I would wait for the official notice, freeze credit if my SSN is in scope, and ignore random payroll emails that show up this week.