Spreadsheets on the Missouri State Treasurer's website exposed the names of students receiving private school vouchers through the MOScholars programme, alongside their parents' email addresses, the schools and vendors paid, and each scholarship amount. The files sat there, downloadable, for months.
The Missouri Independent alerted the office on 16 April 2026, minutes before a monthly meeting of the organisations that administer the programme. Emails obtained under the Missouri Sunshine Law show that within two business days the office had circulated a draft statement attributing the problem to its software contractor. Removing the file from internet archive sites reportedly took several more days.
The part where everyone points sideways
The contractor disputed that account, saying it had supplied complete, unredacted exports and had no say in how the data was handled once it left their system. Reporting also notes the published file carried markers suggesting it had passed through a treasurer's office computer before going online. Who is at fault is contested — and that is rather the point.
For the families in that spreadsheet, the question of whose fault it was changes nothing. Their details were public either way.
You cannot audit the chain
This is the quiet pattern behind a large share of breaches. You dealt with one organisation. Your data lived with a chain of vendors you were never told about and could not have vetted. Every government form, insurance claim and loyalty scheme extends that chain by at least one link.
Privacy advice that amounts to "only deal with trustworthy organisations" fails here. The organisation these families chose was a state treasurer's office. The advice has nothing to say about the vendor two steps down.
Change what you can control
You do not control who ends up holding your data. You do control which address they hold. That is the only variable in this story that was ever in the hands of the families involved.
The same logic runs through the Tribeca contact leak, where the exposure came from an organisation the people involved had simply given their details to — and through the sextortion campaigns that recycle old breach data, where a leaked address stays a target for years.