Your Kid’s Homework Could Be Your Company’s Next Breach
It’s back-to-school time! When the kids are back on laptops and tablets every night — often on the same Wi-Fi and sometimes the same devices you use for work — the line between “home network” and “business network” disappears. And attackers know it.
Back-to-school cybersecurity isn’t a topic for the school district’s IT department. For any business owner with remote or hybrid staff, it’s a real exposure that shows up in your systems, your data, and your bank account.
The truth is that the person who lets an attacker into your business is almost never trying to. It’s a distracted employee, a shared family computer, or a kid chasing a shortcut in a video game.
The breach that started with a Roblox cheat
In February 2026, an employee at a company called Context.ai went looking for Roblox “auto-farm” scripts and game cheat tools — the kind of thing a kid or a gaming parent downloads without a second thought. What actually got installed was Lumma Stealer, a piece of infostealer malware that quietly harvested corporate credentials from the machine: Google Workspace logins, plus keys for several business tools.
Those stolen credentials sat in a criminal database for over a month. Attackers then used them to break into Context.ai, steal access tokens, and pivot into the systems of one of its customers — the developer platform Vercel. By the time Vercel disclosed the breach in April 2026, a threat actor was selling the stolen data for $2 million. All of it traces back to a single game exploit downloaded onto a work-connected machine. CyberScoop reported the full chain of events.
You don’t have to be a tech company for this to matter. The pattern — a game download, an infostealer, harvested business logins — is now one of the most common ways small businesses get compromised.
Why it’s not “just a home computer”
A similar story played out at Disney. An employee downloaded what looked like a free AI image tool onto his personal home computer. It was infostealer malware. It sat undetected for five months, scraped his saved passwords, and gave an attacker the keys to Disney’s internal Slack. They walked off with more than a terabyte of company data. The employee wasn’t careless at work. He was careless at home, on a device he thought had nothing to do with his job.
That’s the core problem. Your employees’ home devices now hold corporate logins, and those devices are shared with kids, spouses, and roommates who aren’t thinking about your business at all. Verizon’s 2025 Data Breach Investigations Report found that 46% of unmanaged devices showing up in infostealer logs had corporate credentials on them. Nearly half. These are personal laptops and home machines quietly carrying the keys to a business network.
No, you don’t have to ban your kids from the internet. But a work credential on an unmanaged, shared home device is like leaving your storage room unlocked.
Four ways home risk gets into your business
The specifics vary, but back-to-school exposure tends to come through the same doors:
- Shared devices. A parent finishes work, and the kid uses the same laptop to play games or do homework. Malware doesn’t know whose turn it is.
- One flat home network. The work laptop, the smart TV, the kids’ tablets, and the gaming console all sit on the same Wi-Fi with no separation. Once one device is infected, it can see the others.
- “Free” downloads. Game mods, cheat tools, pirated software, and fake apps are among the most reliable ways to deliver infostealers — and they’re exactly what kids seek out.
- Saved passwords. When work logins are saved in a personal browser or password manager on a shared machine, one infection can hand over dozens of accounts at once.
What actually reduces this risk
You can’t supervise every household your team works from. You can make sure a mistake at home doesn’t become a breach at work. A few practical moves do most of the work:
Give employees a dedicated work device and a clear rule that it’s not the family computer. Separating work from personal use is the single highest-value step, and it’s the foundation of the basic security habits every business should have in place.
Segment the home network. A guest Wi-Fi network for kids’ devices and personal gadgets — separate from where the work laptop connects — keeps an infected tablet from reaching a work machine. Proper network and Wi-Fi configuration is straightforward to set up and easy to overlook.
Manage the devices that touch your data. Endpoint protection, automatic updates, and the ability to see and respond to threats on remote machines turn “we hope nobody clicked anything” into “we’d know if they did.” This is the heart of ongoing cybersecurity and incident response.
Turn on multi-factor authentication everywhere it’s offered. Even if credentials are stolen, MFA gives an attacker one more wall to climb.
Working with a cybersecurity expert at Eclipse Network
Assume the home network is hostile, and design your business so a single mistake there can’t reach everything. Separate work devices from family ones, split the home network, keep managed protection on anything that touches company data, and require MFA. None of it requires a lecture to your kids. It just requires treating remote work like the extension of your business it actually is.
If you’re not sure how exposed your team’s home setups leave you, that’s worth an honest look before the school year hits full stride. Eclipse Networks helps Atlanta-area businesses close exactly these gaps — securing remote devices, segmenting networks, and putting monitoring in place so a household mistake stays a household mistake. Schedule a consultation and we’ll help you find the weak points before someone else does.