April 24, 2026
PUBLIC LETTER REGARDING A RECENT CRIMINAL CYBERSECURITY ATTACK ON THE STEWART HOME & SCHOOL’S ELECTRONIC COMPUTER NETWORK
Stewart Home & School greatly values its relationship with our students and our families. As part of that relationship and with the goal of creating and maintaining the best possible environment for our students, we recognize the importance of protecting the personal information we maintain.
We are posting this letter to provide readers with information regarding a recent criminal cybersecurity attack on our electronic computer network. Unfortunately, based on a forensic investigation conducted by outside experts, we have determined that the attack involved certain personal information that was stored on our electronic network. While our investigation is on-going, this publicly posted letter is intended to explain: (1) the nature of attack; (2) the measures we have taken in response; and, (3) importantly some steps we encourage you to consider taking in response to this event if you had personal information on our electronic network that may have been compromised.
On August 4, 2025, at approximately 1:08 a.m. EST, the Stewart Home & School’s electronic network was the subject of a criminal attack by so-called threat actors. Based on our investigation to date, it appears that the threat actors used stolen credentials to breach the protective measures the Stewart Home & School had in place at the time that were designed to protect its network. As part of its response to this cybersecurity attack, the Stewart Home & School has engaged recognized cybersecurity experts to both conduct a forensic analysis of the attack and to recommend additional safeguards we can put in place to best protect against any similar event in the future. Additionally, we have reported the event to the United States Federal Bureau of Investigation and the United States Department for Health and Human Services, Office of Civil Rights.
Based on the forensic analysis, it is the Stewart Home & School’s good faith belief that two of its internal electronic drives were impacted, and as a result at least some, and perhaps all of the personal information housed on our electronic network at the time of the attack was accessed, encrypted, and exfiltrated by the threat actor. More specifically, through the investigation, we determined that the personal information involved may have included: 1. demographic information such as your date of birth, social security number, phone number, email address, and address; 2. financial information; and, 3. protected health information covered under the Health Insurance Portability and Accountability Act (HIPAA), such as health insurance information, diagnosis and conditions, test results, and medications; and, 4. education related information, including associated evaluation and testing information.
Based on both the nature of the attack and the design of our electronic network, it has taken us a significant amount of time and effort to best ensure that we have properly identified all individuals whose protected information was stored in the affected locations within our electronic network and therefore compromised. That said, to date, we have no indication that any personal information has been used in a particular manner or for a particular purpose. This is notwithstanding, since personal information was accessed and exfiltrated by the threat actor, we are notifying publicly by posting this letter discussing the incident so that those having personal information on our electronic network can take any necessary precautions you feel appropriate.
For those affected, you will receive a letter instructing you how to receive a complimentary 24-month membership of credit monitoring and identity theft protection services by TransUnion. These services are free of charge to anyone impacted by this incident, and enrolling will not affect your credit score. If you believe you had the type of personal information listed above on our electronic network, or have any related questions, please contact Stewart Home and School, by calling 502-352-9700, Monday through Friday, between 8:00 a.m. and 5:00 p.m., Eastern Time.
For over 130 years, Stewart Home & School worked tirelessly to serve its students and their families. Our desire to provide a home and school for our students is deeply rooted in our values first established in 1893, an important part of which is the value we place on the privacy of our students and their families. We work each day to earn and maintain the trust of our students and their families, and we sincerely apologize for any concern and inconvenience this criminal attack on our network may cause those we serve. Of course, we continue to review the incident with the experts we have engaged to assist us, which includes taking any additional steps necessary aimed at preventing similar crimes against us in the future.
Sincerely,
Dr. Stewart