Sensitive Data on 21,000 Special Education Students Leaked From Israeli Ministry of Education
Translated & summarized from Calcalist by baba
Israel's Privacy Protection Authority found the Ministry of Education violated privacy laws after sensitive data on 21,000 special education students was leaked online. The leak, which occurred around May 2024 and was discovered in March 2025, included personal and medical details. The ministry cited a potential permissions error, but the authority identified multiple security and procedural failures. The ministry has since taken steps to address the breach.
The story in 5 lines · by baba
- Sensitive personal and medical data of 21,000 special education students was leaked from Israel's Ministry of Education.
- The leak included identifying details, residential information, religious affiliation, and specific disability information.
- The Privacy Protection Authority determined the ministry violated privacy and security laws.
- The data was compiled in May 2024 and the leak was discovered in March 2025.
- The ministry stated it has since blocked access, conducted an investigation, and improved procedures.
Israel's Privacy Protection Authority has determined that the Ministry of Education violated privacy protection laws and information security regulations, leading to a leak of sensitive personal data concerning approximately 21,000 Haredi (ultra-Orthodox) special education students. The leaked information included identifying details, residential and educational information, religious affiliation, and medical data, detailing each student's disability. The authority characterized the use and transfer of this information to unauthorized parties as a severe security incident.
The investigation by the Privacy Protection Authority followed a leak of sensitive personal and medical information from the Haredi sector of the Ministry of Education, which was subsequently disseminated online to unauthorized entities. Findings revealed that in May 2024, ministry employees sought to create a digital form to streamline the placement process for these students. To achieve this, they extracted data from a ministry system, compiling a file with sensitive personal information on about 21,000 students and linking it to a form for educational institutions to complete.
The Ministry of Education claimed the data file was intended for information collection and was therefore accessible for viewing and downloading by anyone with its link. This link was distributed in May 2024 to relevant personnel in Haredi educational institutions via both organizational and private email addresses. However, in March 2025, it became known that data from the main file had been leaked to unauthorized parties and widely distributed.
The ministry suggested a specific malfunction in the permissions settings of one of the forms likely allowed an external party to use search mechanisms to locate the data file after clicking a link. The authority's review uncovered numerous deficiencies in the Ministry of Education's data protection and security practices. The data was extracted by an employee not authorized to access it, transmitted via an open link without standard encryption, and the ministry lacked a compliant information security procedure at the time. Furthermore, the ministry had not conducted a required information security risk assessment for the system.
The Privacy Protection Authority reiterated the obligation of public bodies and database holders to ensure the security of personal information, especially sensitive data concerning minors. The Ministry of Education stated that upon learning of the incident, it blocked access and removed the data. A subsequent investigation led to lessons learned, clarified procedures, and strengthened control and security mechanisms.
