Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

A calmer back-to-school login: keeping school portals safe in 2026

School messages, parent groups, urgent payments and new login links. A simple family plan that improves safety without turning home into an IT department.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
2 September 2026
READING TIME
8 min read
TOPIC
Human Security
A calmer back-to-school login: keeping school portals safe in 2026

The first week of September has its own rhythm: the timetable changes three times, parents join new group chats and the school sends more messages than it did all summer. That is precisely when another login link, payment request or “important document” feels believable. Not because people are careless, but because everything arrives at once and fits the moment.

Poland also has a new development this year. On 26 August 2026, the Ministry of Digital Affairs described work on a pilot public eDziennik service. The pilot depends on the relevant legal changes taking effect and is intended for a limited group of schools. That distinction matters: the announcement does not mean every parent should create a new account today from a link received in a message.

What was actually announced

According to the Ministry of Digital Affairs, the public eDziennik is to be tested by selected schools once the legal and organisational conditions are met. Heads, teachers and authorised staff are expected to use edziennik.gov.pl through Poland’s national identity gateway. Parents are expected to see their child’s information in the “Szkoła” service in the mObywatel app, while pupils use mObywatel Junior.

If your child’s school has not confirmed that it is in the pilot, keep using its existing portal and official instructions. Do not find the login through an advert, and do not assume that a web address containing the word “edziennik” is a government service. A familiar name is not enough; the complete address and the channel used by the school both matter.

The likeliest trap will not look alarming

Imagine a message saying: “Update your parent account before the first meeting. Access to grades will be suspended if you do not confirm.” The link opens a page that resembles the familiar portal. It asks for an email address and password, then a code from the phone. A criminal does not need to breach a school. They only need to exploit a week when everyone expects change.

Another version concerns money: a class contribution, insurance, a trip or textbooks. The request may come from a compromised parent account or a new group with an almost identical name. The most reliable defence is not spotting every typo. It is a rule that every new payment and every change of bank details is confirmed through a second channel.

A five-minute family plan

Agree four simple rules:

  1. Open the school portal from a saved bookmark or its app, never from a link in a text, advert or parent-group message.
  2. Confirm every new payment with the teacher or school office using a number you already know.
  3. Use a unique password for the school portal. Do not reuse it for email, shopping or a child’s account. Enable a second login factor if the service offers one.
  4. Make it safe for a child to show you a suspicious message. Fast reporting matters more than finding someone to blame.

Those rules interrupt most pressure-based scams. A shared password spreadsheet and a family phone audit are unnecessary. One sentence is worth agreeing instead: “We do not pay or share a code until we have checked.”

What a school can do

A school can make safe behaviour easier by publishing one permanent page with its current portal address and access-recovery instructions. A login-change notice should not demand an immediate click. Parents should be able to call the office, and staff should be able to confirm quickly whether a message is genuine.

Poland’s Ministry of National Education has already highlighted the need for stronger authentication following reports of unauthorised access to teacher accounts. Breachroad’s view is that account protection and clear communication must work together. Strong authentication cannot help someone who has been sent to a fake login page.

If someone has already entered a password or code

Open the genuine service from your saved bookmark, change the password and end active sessions if the option is available. If the same password was used elsewhere, change it there too, starting with email. Tell the school, because other parents or teachers may have received the same message.

A link-based message can be reported to Poland’s national incident-response team through incydent.cert.pl. A suspicious SMS containing a link can be forwarded to 8080 under the CERT Polska reporting guidance. If money has been sent, contact the bank immediately and report the fraud to the police. Preserve the messages, page address and transaction record.

Source facts and Breachroad conclusions

The planned pilot’s scope, access channels and dependence on legislation come from the two ministry announcements. The fake-login and payment scenarios, along with the family verification plan, are Breachroad recommendations based on common phishing patterns. We are not claiming that the public eDziennik has been breached or that a campaign impersonating it is currently under way.

A good start to the school year does not require fear of every notification. It needs one calm habit: pause, open the channel you already trust and check. Our guides to children’s online safety and recognising phishing offer more practical conversations for home.

If you want teachers, administrators or company staff to rehearse these decisions, explore our cybersecurity training and phishing simulations. We build scenarios around real conversations and choices, not a technical quiz.

SHARE / COPY