PowerSchool SIS Breach
December 2024. One stolen support credential, no MFA, and the student and teacher records of tens of millions of people walked out the door. Paying the ransom did not stop the attackers from coming back to extort individual districts five months later.
TL;DR
In December 2024, an attacker logged into PowerSchool's "PowerSource" customer support portal using a stolen support-contractor credential, then used a built-in export tool to bulk-download the students and teachers tables from districts' Student Information System databases across the United States and Canada. The Department of Justice described the haul as data on nearly 70 million students and teachers. PowerSchool paid a ransom for a video that claimed to show the data being deleted. The promise did not hold: in May 2025 attackers used the same data to extort individual districts directly. The perpetrator, 20-year-old Matthew Lane, pleaded guilty and was sentenced to four years in federal prison and $14.1 million in restitution.
What happened
This was not an exploit or malware. The attacker used legitimate credentials and a legitimate maintenance tool. CrowdStrike's investigation found no evidence of access to any tables beyond students and teachers, and no system-layer compromise. The single missing control that the Texas Attorney General's later lawsuit centers on: multi-factor authentication was not enforced on the portal credential.
- September 2024: Lane gains access using a PowerSchool contractor's credentials (per the DOJ). An earlier access window in August to September 2024 used the same credentials.
- December 19 to 23, 2024: Confirmed exfiltration window. The attacker exports the
studentsandteacherstables as CSV files through the PowerSource maintenance tool. - December 28, 2024: PowerSchool detects the activity and receives a ransom demand of roughly $2.85 million in Bitcoin.
- January 7 to 8, 2025: Public disclosure; PowerSchool notifies customers. The company pays for a video purporting to show deletion of the only copy of the data.
- May 7, 2025: Downstream re-extortion: attackers email individual districts directly with samples of the stolen data, demanding new payments. PowerSchool states this is not a new breach.
- October 2025: Matthew Lane sentenced to four years in federal prison, three years supervised release, $14.1 million restitution.
Confirmed exposed
- Names, addresses, phone numbers, email addresses, dates of birth
- Social Security numbers: PowerSchool stated fewer than 25% of registered students had an SSN stored in the affected system, and staff SSNs were also implicated
- Medical information; for some students, health records, disability accommodations, and IEP details
- Grades and GPAs, student IDs, parent and guardian contact info, and in some cases student portal passwords
Confirmed not exposed
- Data from tables other than students and teachers (per CrowdStrike, no evidence of access)
- No malware or system-layer access was found; this was credential misuse, not an exploit
Actual exposure varied district by district. SSNs and medical/IEP data were a subset of affected records, not universal.
Scale
PowerSchool serves 60+ million students and more than 90 of the 100 largest U.S. school districts. The DOJ described Lane accessing data on nearly 70 million students and teachers. The attacker claimed 62.4 million students and 9.5 million teachers, a figure repeated in the Texas AG complaint but not independently verified. Early press identified "over 100 districts"; the Texas AG complaint alleges data was stolen from 6,505 districts. Treat the higher number as a litigation allegation rather than settled fact.
Aftermath
The criminal case closed with a guilty plea and sentencing. The civil exposure did not. Multiple class actions allege negligence and inadequate security, and the Texas Attorney General sued, alleging PowerSchool failed to implement basic protections including MFA and misled customers about its security. Only about $161,000 of the roughly $2.85 million ransom was recovered.
Why it matters for districts
Your students' data is only as safe as your SIS vendor's weakest support account. One credential without MFA exposed tens of millions of children's records, and paying the ransom did not stop the attackers from returning to extort districts directly. Vendor access controls (MFA, least privilege, credential rotation) and a written breach-notification plan are not optional.
Note: a separate $17.3 million settlement over PowerSchool's Naviance platform (alleged unlawful data collection) is a different matter from this breach. Do not conflate the two.
Sources
- BleepingComputer — PowerSchool hack exposes student, teacher data from K-12 districts (2025-01-07)
- CyberScoop — PowerSchool customers hit by downstream extortion threats (2025-05-07)
- US News / Reuters — US School Districts Facing Extortion Attempt After Hack (2025-05-07)
- Infosecurity Magazine — PowerSchool Admits Ransom Payment Amid Fresh Extortion Demands (2025-05)
- BleepingComputer — Texas sues PowerSchool after massive data breach hit 62 million students (2025-09-04)
- CBS News Texas — Texas AG Paxton PowerSchool data breach lawsuit (2025-09)
- CyberScoop — PowerSchool hacker Matthew Lane sentenced to 4 years in prison (2025-10-15)
- K-12 Dive — PowerSchool hacker sentenced: lessons learned (2025)
- Security.org — PowerSchool Data Breach: What Happened and What Families Should Do (2025)
- TechTarget — PowerSchool data breach: Explaining how it happened
This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].