Third-party risk · 4 min read

The Missouri Voucher Leak: You Are Only as Safe as the Weakest Contractor

A state office published student names and parents’ email addresses for months, then pointed at its software contractor. You cannot audit every vendor — but you can make your address disposable.

YeyMail Team ·

Spreadsheets on the Missouri State Treasurer's website exposed the names of students receiving private school vouchers through the MOScholars programme, alongside their parents' email addresses, the schools and vendors paid, and each scholarship amount. The files sat there, downloadable, for months.

The Missouri Independent alerted the office on 16 April 2026, minutes before a monthly meeting of the organisations that administer the programme. Emails obtained under the Missouri Sunshine Law show that within two business days the office had circulated a draft statement attributing the problem to its software contractor. Removing the file from internet archive sites reportedly took several more days.

The part where everyone points sideways

The contractor disputed that account, saying it had supplied complete, unredacted exports and had no say in how the data was handled once it left their system. Reporting also notes the published file carried markers suggesting it had passed through a treasurer's office computer before going online. Who is at fault is contested — and that is rather the point.

For the families in that spreadsheet, the question of whose fault it was changes nothing. Their details were public either way.

You cannot audit the chain

This is the quiet pattern behind a large share of breaches. You dealt with one organisation. Your data lived with a chain of vendors you were never told about and could not have vetted. Every government form, insurance claim and loyalty scheme extends that chain by at least one link.

Privacy advice that amounts to "only deal with trustworthy organisations" fails here. The organisation these families chose was a state treasurer's office. The advice has nothing to say about the vendor two steps down.

Change what you can control

You do not control who ends up holding your data. You do control which address they hold. That is the only variable in this story that was ever in the hands of the families involved.

The same logic runs through the Tribeca contact leak, where the exposure came from an organisation the people involved had simply given their details to — and through the sextortion campaigns that recycle old breach data, where a leaked address stays a target for years.

The YeyMail takeaway
You cannot audit their vendors. You can make your address disposable.

Hand each programme, form and account its own alias and the blast radius of somebody else’s weakest contractor shrinks to one address. When the breach notice arrives you already know precisely what leaked and who lost it, and the fix is a toggle rather than the job of changing your email address everywhere you have ever used it.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

What data was exposed in the Missouri MOScholars leak?

Student names, parents’ email addresses, the schools and vendors paid through the programme, and each scholarship amount — in downloadable spreadsheets on the treasurer’s website.

Who was responsible for the Missouri voucher data leak?

It is disputed. The treasurer’s office attributed the problem to its software contractor; the contractor said it supplied complete, unredacted exports and had no control over how the data was handled afterwards. Reporting notes the published file carried markers suggesting it passed through a treasurer’s office computer.

How do I protect myself when a government contractor leaks my data?

You cannot vet the vendors, so reduce what a leak is worth. Give each organisation a separate email alias: a breach then exposes one disposable address, tells you exactly who lost it, and can be switched off without touching your real inbox.

Keep reading

Scam watch
Sextortion Scammers Are Recycling the ShinyHunters Leaks
Breach analysis
Even Celebrities Get Leaked: Lessons From the Tribeca Contact Dump