CyberSecurity updates
2025-01-19 14:25:56 Pacfic

PowerSchool Breach Exposes Student Teacher Data - 10d
Read more: databreaches.net

A significant cyberattack on PowerSchool, an education technology software company, has resulted in the compromise of historical student and teacher data. Multiple companies have confirmed that hackers were able to access and steal all data, going back as far as they had been using PowerSchool’s services. The breach occurred in late December 2024 when an unidentified threat actor gained unauthorized access to the PowerSchool Student Information System (SIS) using stolen credentials. They then utilized the “export data manager” customer support tool to extract the “Students” and “Teachers” database tables, obtaining sensitive information in a CSV file.

The compromised data includes names, postal addresses, and in some cases, Social Security numbers, personally identifiable information, medical information, and grades. Although PowerSchool has not released the exact number of impacted schools, TechCrunch reports multiple affected school districts where hackers accessed "troves of personal data belonging to both current and former students and teachers," as far back as when they first used PowerSchool. The company stated that the attack wasn't a ransomware incident, although it paid the attackers. The impacted system lacked basic security measures, such as multi-factor authentication, leaving a huge amount of student and teacher data vulnerable to exposure.