Nashville public school student records discovered at area Goodwill store
A Nashville Goodwill store uncovered more than good deals in one of its items for sale – a treasure trove of public-school records, which would have gone unnoticed except for a customer’s…
A Nashville Goodwill store uncovered more than good deals in one of its items for sale – a treasure trove of public-school records, which would have gone unnoticed except for a customer’s honesty.
“The customer reached out to WSMV4, saying they found stacks of Metro Nashville Public Schools records with private student information at the Goodwill store on Cockrill Bend Boulevard,” reported Gray Media’s WSMV.com. “The documents included student names, dates of birth, teacher and parent information and behavior plans.”
The customer also told journalists they had wanted to purchase the item containing the documents to give them to the state’s education department, but the store intervened.
“We are very thankful to the customer who brought this item to our attention,” a spokesperson noted. “Per Goodwill policy, our outlet team removed this item from the sales floor and turned it over to the Goodwill Asset Protection Department.”
The records appear to be 10 years old, the news outlet said in a video describing the incident.
Meanwhile, the district – which enrolls more than 80,000 students across grades pre-K through 12 – released a statement confirming its knowledge of the situation and subsequent investigations.
“We take the protection of student information seriously and will continue investigating this matter in consultation with legal counsel,” said Sean Braisted, the district’s chief of communications and technology. “We will take any appropriate steps based on what that review determines.”
Schools increasingly targeted for ‘sensitive information’
As previously reported by Heartlander News, schools nationwide have been wrestling with challenges in securing confidential student data.
“The trove of sensitive information stored on an educational institution’s servers makes it a prime target for cybercriminals,” concluded a March 2025 report by cybersecurity group KnowBe4. “While they may not be the most lucrative victims, there are several factors that make intrusion and extortion for ransom easier than organizations or institutions that are financially stronger and better-equipped sectors.”
In December, a Detroit district required all students to change their account passwords after a phishing email was sent appearing to come from staff members.
Broken Bow Public Schools in Nebraska also fell victim last year to a phishing email, which appeared to come from a trusted vendor.
“We are committed to keeping our community informed and to taking every possible step to safeguard public funds,” the district wrote in a statement. “Broken Bow Public Schools takes full responsibility for the fact that these safeguards were not in place, as well as full responsibility for this unfortunate circumstance.”
The district lost $1.8 million because of the scam.


