The published records identified students who received vouchers for private schools, but Missouri blamed their technology partner.

 

What happened

In April of 2026, the Missouri State Treasure’s Office discovered they had accidentally posted a directory filled with private information about Missouri students and their families. The post included a directory of students enrolled in the state’s private school voucher program and had been available online for almost a year.

The data covered three years of the MOScholars program, a state-sponsored voucher initiative, and included student names, parent contact information, scholarship funding amounts, and the schools they attended. The records date back to at least May 2025.

At the time, the office blamed one of their software contractors, ClassWallet, which is a digital financial management platform used to help states disburse and track funds for various voucher programs. The software is used to different capacities in 37 states, often managing vouchers, teacher stipends, education savings accounts (ESAs) and state scholarship programs.

 

What’s new

Newley released emails, according to the Missouri Independent, show that the Treasurer’s Office greatly understated the data leak and also blamed ClassWallet for the incident, despite no proof that the software had made a mistake. No other states, as far as we know, faced a similar breach.

ClassWallet has recently disputed the claims and shared evidence suggesting that the file that was ultimately published online had passed through an employee’s computer before it became public. It’s now believed that the leak originated on the Treasurer’s website, rather than ClassWallet’s interface. Despite the dispute, this isn’t the first time ClassWallet has been under critique. In 2025, the company was investigated by the Arizona Department of Homeland Security for an error that allowed a parent to view payment requests of other users.

State Treasurer Vivek Malek confirmed in June 2026 that they would no longer be using ClassWallet as a vendor for their voucher program, and their contract has experied.

 

Going deeper

The private data was not obviously available, but rather could be revealed if a spreadsheet published online was manipulated. The treasurer’s office also said that the vulnerability was “fully resolved immediately upon notification,” but the data sat available for several days before it was finally pulled from the archives.

The data leak comes at a time when the program has received increased scrutiny, as the program now receives $50 million in state funding but raises concerns from public school advocates.

The law that governs the program states that public reporting on some aspects of the program is required, but “no personally identifiable information of any student” should be published online.

 

What was said

At the time of the breach, a Treasurer’s Office spokesperson said, “The spreadsheet was compiled by the third-party application and fiscal management platform that houses and maintains the data and is contractually obligated to provide expenditure information for publication.”

In response, ClassWallet’s spokesperson said that they provided the office with “complete, unredacted reports” that clients could use “at their discretion.”

 

Why it matters

Regardless of whose fault the breach may have been, ultimately, it’s difficult for any organization, including the office of the Missouri Treasurer, to completely avoid blame or reputational harm. Each organization has an obligation to make sure that the vendors they use are meeting all state and federal privacy laws and not revealing information inadvertently or unnecessarily. Even if a vendor holds some responsibility for the data it provides an organization, organizations should always do a final check on what information they will be posting.

The incident comes at a time of increased breaches in the education sector. This year, Paubox has already reported multiple data breaches against education companies like Kaplan, McGraw Hill, and Instructure, most of which are vendors that handle student data for the schools or institutions they work with. These breaches differ from the one in Missouri, which seems more closely linked to a government error than a vendor mistake. Nevertheless, the increased frequency of these breaches show that educational organizations need to pay close attention to how their vendors maintain privacy and store data.

 

FAQs

What is a private school voucher?

These are vouchers that help offset the costs of private or religious schools. The idea is that money that would go toward a public education instead goes towards a family’s private education. There are both critics, who say these vouchers take away needed money from public schools, and proponents, who argue that vouchers create healthy competition in education.

 

How do we know ClassWallet is not responsible for the breach?

In many respects, responsibility is shared, because both organizations have a vested interest in keeping data safe. However, the contract is what ultimately outlines who will be responsible, which is why it is critical for any contract to outline their privacy expectations with their vendors.