SUNDAY, OCTOBER 4, 2026
Beyond the headline
FORMATIVESPACES.COM

PowerSchool breach exposed millions of student and educator records, prompting lawsuits and federal charges

A compromised credential without multi-factor authentication let a hacker steal personal data from the student information system used by more than 40 states, triggering state investigations, a Texas lawsuit, and a guilty plea in federal court.

A large, light-colored stone building with classical architectural elements, including columns and a pediment, stands under a clear blue sky. Cars are parked and driving on the street in front of the building, and a few pedestrians are visible on the sidewalk.
The U.S. Department of Justice headquarters in Washington, D.C. Shown for institutional context. Photo: APK / Wikimedia Commons. CC BY 4.0. Resized for display; social preview adds branding.

On December 28, 2024, PowerSchool discovered that an unauthorized party had used a compromised credential to access its PowerSource customer support portal and export Student and Teacher data tables from its Student Information System. The incident appears to have occurred between December 19 and December 28, 2024. PowerSchool stated this was not a ransomware event and no systems were encrypted.

The South Carolina Department of Education was formally notified on January 8, 2025, and confirmed that personally identifiable information including Social Security numbers of students and educators was compromised. The breach's scope spans more than 40 U.S. states and multiple Canadian provinces. The hacker claimed in an extortion demand to have stolen data on 62,488,628 students and 9,506,624 teachers across 6,505 school districts. PowerSchool would not confirm specific numbers but stated it expects more than three-quarters of impacted individuals did not have Social Security numbers exfiltrated. At least 2.7 million records were confirmed affected as of early 2025 reporting.

62,488,628Number of students the hacker claimed to have stolen data for, across 6,505 school districts. [6]
9,506,624Number of teachers the hacker claimed to have stolen data for. [6]

What data was exposed

The categories of PII exposed varied by individual but included some combination of: name, contact information, Social Security Number, date of birth, limited medical alert information, and other related information. Some districts also reported exposure of disability information, gender, race and ethnicity, parent/guardian/emergency contact names, and disciplinary notes. PowerSchool confirmed that an unauthorized party used a compromised credential tied to a maintenance account to access the management console of PowerSource and export the Student and Teacher tables. PowerSchool stated the breach has been contained, remote access for all hosted accounts has been deactivated, and it believes the data has not been shared or made publicly and was likely deleted without further replication.

All school districts in South Carolina except four were included on PowerSchool's list of impacted districts. However, inclusion on the list meant the SIS was accessed, not necessarily that data was extracted, according to PowerSchool.

Scope across states and Canada

States where schools warned students and parents about the PowerSchool breach included Alaska, Arizona, California, Colorado, Connecticut, Delaware, Illinois, Indiana, Kansas, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Dakota, Tennessee, Texas, Utah, Wisconsin, and Wyoming. Georgia estimated more than 230,000 current students may have been affected.

The Toronto District School Board, the largest school board in Canada, reported that the breach exposed sensitive information of all students enrolled between September 3, 1985 and December 28, 2024 approximately 1.5 million students. Four decades of student information and seven years of parent/guardian/emergency contact data were stolen, though Social Security numbers and financial/banking information were not included because Canadian systems do not use SSNs.

California's Menlo Park City School District reported that stolen information belonged to all current students and staff, all students enrolled since the 2009-2010 school year, and staff who worked since 2009-2010 totaling 10,662 students affected. California law requires public schools to store student data in perpetuity, which expanded the scope of exposed records.

The South Carolina Department of Juvenile Justice reported that PII of current and former teachers employed between August 13, 2009 and December 28, 2024, and current and former students enrolled during the same period, was breached.

Legal and investigative response

Texas Attorney General Ken Paxton filed suit against PowerSchool on September 3, 2025, alleging the breach exposed sensitive PII and protected health information of more than 880,000 Texas school-aged children and teachers. The lawsuit claims PowerSchool violated the Texas Deceptive Trade Practices Act and the Identity Theft Enforcement and Protection Act by failing to implement multi-factor authentication, adequate access controls, and proper data encryption.

North Carolina Attorney General Jeff Jackson issued a Civil Investigative Demand to PowerSchool as part of an ongoing investigation. The North Carolina Department of Justice stated the breach compromised the personal information of nearly 4 million teachers, students, and parents in North Carolina. The U.S. Department of Justice charged 19-year-old Matthew Lane, who pleaded guilty in May 2025 to cyber extortion conspiracy, cyber extortion, unauthorized access to protected computers, and aggravated identity theft.

880,000Number of Texas school-aged children and teachers whose sensitive PII was allegedly exposed, per the Texas Attorney General's lawsuit. [8]

PowerSchool sent formal data breach notifications to multiple state attorneys general on January 27, 2025, reporting affected resident counts: approximately 6,766 Rhode Island residents and approximately 49,921 Iowa residents later revised to 55,343 unique individuals after deduplication. Notifications to state AGs included state-specific consumer protection information as required by each state's breach notification statute.

Security failure and research findings

A CrowdStrike interim forensic report obtained by NBC News found no evidence the hackers used malware or a backdoor. Instead, the hacker obtained a single employee's password for a maintenance account that lacked multi-factor authentication. PowerSchool's CIO reportedly told customers the company paid the hacker and received a video showing the data being deleted. Cybersecurity experts cautioned there is no way to verify all copies were destroyed.

Sarah Powazek, director of the University of California, Berkeley's public interest cybersecurity program, noted that school districts have no control over whether vendors like PowerSchool implement correct security procedures, placing schools at the mercy of these educational technology products.

PowerSchool's own verification process, documented in an April 28, 2025 supplemental notification to the Iowa AG, confirmed that its initial January 27, 2025 resident count over-stated the number of impacted individuals for hosted customers due to duplicates (e.g., one child associated with multiple schools). The revised Iowa count went from approximately 49,921 to 55,343 unique residents after including on-premises customer data, indicating that early breach scope estimates may be unreliable.

Remediation offered

PowerSchool engaged Experian to offer two years of complimentary identity protection and credit monitoring services to all students and educators whose information was involved, regardless of whether their Social Security Number was exfiltrated. Adult students and educators receive both identity protection and credit monitoring; minors receive identity protection services.

Analysis

By the Formative Spaces Newsroom, written after the reporting above was filed.

The breach window may be wider than PowerSchool told parents.

PowerSchool's own CrowdStrike final report, published after the initial notifications, found that the same compromised maintenance credentials were used to access the PowerSource portal between August 16 and September 17, 2024, four months before the December exfiltration. CrowdStrike could not determine whether student data was accessed during that earlier window because the SIS log data did not go back far enough. Parents who were told the incident ran December 19 to 28 were never told the credential was live and used months earlier. The true scope of exposure is unknowable from PowerSchool's own records.

Two years of credit monitoring does not match the lifespan of a stolen child's Social Security number.

PowerSchool is offering two years of complimentary identity protection through Experian. For children whose Social Security numbers were exfiltrated, this window is badly mismatched to the risk. A minor's SSN is especially valuable to identity thieves because it carries a clean credit file, and misuse often goes undetected until the child applies for credit years later. The enrollment deadline for Canadian residents has already closed, and parents who missed it have no recourse through PowerSchool's remedy program. This is our read of the gap between the offer and the exposure timeline.

One vendor's single password failure exposed records in 40-plus states.

PowerSchool holds 23 percent of all identified K-12 student information system implementations in the U.S. and Canada, and roughly 80 percent of students in both countries are exposed to at least one PowerSchool product. A single maintenance account password without multi-factor authentication gave one hacker access to student and teacher tables across 6,505 districts. Market concentration of this size turned a basic security failure into a national-scale breach. Parents cannot shop around for a more secure SIS vendor; in most districts, that decision was made at the district or state level.

Sources

  1. Rhode Island Attorney General's Office. PowerSchool Data Incident Notification to RI AG (January 27, 2025) View
  2. South Carolina Department of Education. SCDE responds to PowerSchool Data Breach View
  3. South Carolina Department of Education (via MyConnectSuite document). PowerSchool Data Breach: Clarity, Updates, and Support (January 9, 2025) View
  4. Iowa Attorney General's Office. PowerSchool Supplemental Notice to Iowa AG (January 27, 2025) View
  5. South Carolina Department of Education. SCDE provides update to school districts on PowerSchool data breach (January 9, 2025) View
  6. BleepingComputer. PowerSchool hacker claims they stole data of 62 million students View
  7. NBC News. PowerSchool hack: missed basic security step resulted in data breach View
  8. Texas Attorney General's Office. Attorney General Paxton Sues Big Tech Company for Catastrophic Data Breach View
  9. North Carolina Department of Justice. Attorney General Jeff Jackson Demands Accountability from PowerSchool over 2024 Data Breach View
  10. Iowa Attorney General's Office. PowerSchool Supplemental Update to Iowa AG (April 28, 2025) View
  11. Ars Technica. Data breach hitting PowerSchool looks very, very bad View
  12. South Carolina Department of Juvenile Justice. PowerSchool Breach of SCDJJ School District Data View
  13. PowerSchool / CrowdStrike. CrowdStrike Final Investigation Report (PowerSchool SIS Incident) View
  14. PowerSchool. Notice of Data Breach For Individuals in Canada (enrollment deadline July 31, 2025) View
  15. ListEdTech. The 2025 K-12 SIS Market: Steady Leaders, Emerging Shifts View
  16. Reuters. Massachusetts man behind PowerSchool hacking gets 4 years in prison View