On December 28, 2024, PowerSchool discovered that an unauthorized party had used a compromised credential to access its PowerSource customer support portal and export Student and Teacher data tables from its Student Information System. The incident appears to have occurred between December 19 and December 28, 2024. PowerSchool stated this was not a ransomware event and no systems were encrypted.
The South Carolina Department of Education was formally notified on January 8, 2025, and confirmed that personally identifiable information including Social Security numbers of students and educators was compromised. The breach's scope spans more than 40 U.S. states and multiple Canadian provinces. The hacker claimed in an extortion demand to have stolen data on 62,488,628 students and 9,506,624 teachers across 6,505 school districts. PowerSchool would not confirm specific numbers but stated it expects more than three-quarters of impacted individuals did not have Social Security numbers exfiltrated. At least 2.7 million records were confirmed affected as of early 2025 reporting.
What data was exposed
The categories of PII exposed varied by individual but included some combination of: name, contact information, Social Security Number, date of birth, limited medical alert information, and other related information. Some districts also reported exposure of disability information, gender, race and ethnicity, parent/guardian/emergency contact names, and disciplinary notes. PowerSchool confirmed that an unauthorized party used a compromised credential tied to a maintenance account to access the management console of PowerSource and export the Student and Teacher tables. PowerSchool stated the breach has been contained, remote access for all hosted accounts has been deactivated, and it believes the data has not been shared or made publicly and was likely deleted without further replication.
All school districts in South Carolina except four were included on PowerSchool's list of impacted districts. However, inclusion on the list meant the SIS was accessed, not necessarily that data was extracted, according to PowerSchool.
Scope across states and Canada
States where schools warned students and parents about the PowerSchool breach included Alaska, Arizona, California, Colorado, Connecticut, Delaware, Illinois, Indiana, Kansas, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Dakota, Tennessee, Texas, Utah, Wisconsin, and Wyoming. Georgia estimated more than 230,000 current students may have been affected.
The Toronto District School Board, the largest school board in Canada, reported that the breach exposed sensitive information of all students enrolled between September 3, 1985 and December 28, 2024 approximately 1.5 million students. Four decades of student information and seven years of parent/guardian/emergency contact data were stolen, though Social Security numbers and financial/banking information were not included because Canadian systems do not use SSNs.
California's Menlo Park City School District reported that stolen information belonged to all current students and staff, all students enrolled since the 2009-2010 school year, and staff who worked since 2009-2010 totaling 10,662 students affected. California law requires public schools to store student data in perpetuity, which expanded the scope of exposed records.
The South Carolina Department of Juvenile Justice reported that PII of current and former teachers employed between August 13, 2009 and December 28, 2024, and current and former students enrolled during the same period, was breached.
Legal and investigative response
Texas Attorney General Ken Paxton filed suit against PowerSchool on September 3, 2025, alleging the breach exposed sensitive PII and protected health information of more than 880,000 Texas school-aged children and teachers. The lawsuit claims PowerSchool violated the Texas Deceptive Trade Practices Act and the Identity Theft Enforcement and Protection Act by failing to implement multi-factor authentication, adequate access controls, and proper data encryption.
North Carolina Attorney General Jeff Jackson issued a Civil Investigative Demand to PowerSchool as part of an ongoing investigation. The North Carolina Department of Justice stated the breach compromised the personal information of nearly 4 million teachers, students, and parents in North Carolina. The U.S. Department of Justice charged 19-year-old Matthew Lane, who pleaded guilty in May 2025 to cyber extortion conspiracy, cyber extortion, unauthorized access to protected computers, and aggravated identity theft.
PowerSchool sent formal data breach notifications to multiple state attorneys general on January 27, 2025, reporting affected resident counts: approximately 6,766 Rhode Island residents and approximately 49,921 Iowa residents later revised to 55,343 unique individuals after deduplication. Notifications to state AGs included state-specific consumer protection information as required by each state's breach notification statute.
Security failure and research findings
A CrowdStrike interim forensic report obtained by NBC News found no evidence the hackers used malware or a backdoor. Instead, the hacker obtained a single employee's password for a maintenance account that lacked multi-factor authentication. PowerSchool's CIO reportedly told customers the company paid the hacker and received a video showing the data being deleted. Cybersecurity experts cautioned there is no way to verify all copies were destroyed.
Sarah Powazek, director of the University of California, Berkeley's public interest cybersecurity program, noted that school districts have no control over whether vendors like PowerSchool implement correct security procedures, placing schools at the mercy of these educational technology products.
PowerSchool's own verification process, documented in an April 28, 2025 supplemental notification to the Iowa AG, confirmed that its initial January 27, 2025 resident count over-stated the number of impacted individuals for hosted customers due to duplicates (e.g., one child associated with multiple schools). The revised Iowa count went from approximately 49,921 to 55,343 unique residents after including on-premises customer data, indicating that early breach scope estimates may be unreliable.
Remediation offered
PowerSchool engaged Experian to offer two years of complimentary identity protection and credit monitoring services to all students and educators whose information was involved, regardless of whether their Social Security Number was exfiltrated. Adult students and educators receive both identity protection and credit monitoring; minors receive identity protection services.
