PowerSchool Student Information System Data Breach (December 2024)
Prevented by: HSF
An unauthorized party used a compromised credential with password-only access to the PowerSource customer-support portal and exported student and teacher data from PowerSchool SIS environments. Exposed information varied by customer and could include names, contact details, dates of birth, addresses, SSNs or SINs, medical information, grades, parent or guardian data, and passwords. DOJ-related reporting placed the affected population at approximately 62 million individuals, although other reported figures were not reconciled. Matthew D. Lane later pleaded guilty to conduct related to the breach, while subsequent extortion attempts indicated that stolen data may have remained available.