News • Breach Response • K-12

PowerSchool Data Breach: What Happened, Who's Affected, and What to Do Next

Watch on NBC10 Philadelphia

Segment courtesy of NBC10 Philadelphia. Featuring Matt Barnett, Founder & CEO, SEVN-X.

SEVN-X founder Matt Barnett joined NBC10 Philadelphia to unpack the largest theft of children's data in U.S. history - a breach that exposed more than 62 million students and 10 million teachers across thousands of K-12 districts.

The 60-second summary

Between December 19-28, 2024, an attacker used a stolen credential to log into PowerSchool's PowerSource customer support portal and exfiltrate data from its Student Information System. The breach exposed names, addresses, dates of birth, Social Security numbers, and limited medical information for 62M+ students and 10M+ teachers across thousands of K-12 districts in the U.S. and Canada. PowerSchool paid a ~$2.85M ransom - the data resurfaced anyway, and attackers later extorted individual districts directly.

What Matt covers in the NBC10 interview

  • How a single compromised credential cascaded into a nationwide breach
  • Why the absence of mandatory MFA on an admin-level portal is a textbook control failure
  • What parents of school-aged children should do today - credit freezes, IRS IP PINs, monitoring minors' SSNs
  • Why paying the ransom didn't make the data go away
  • The third-party and vendor-risk lesson every district superintendent needs to hear

Timeline of the PowerSchool breach

Date Event
Dec 19-23, 2024 Initial unauthorized access to PowerSchool's PowerSource portal
Dec 28, 2024 PowerSchool detects the intrusion and receives a ~$2.85M Bitcoin ransom demand
January 2025 Scope confirmed: 62M+ student records and 10M+ teacher records exfiltrated
May 2025 Attackers begin extorting individual school districts directly with sample data
Oct 14, 2025 Matthew D. Lane, 20, sentenced to four years in federal prison + $14.1M restitution

What parents should do right now

  • 1. Freeze your child's credit at all three bureaus (Equifax, Experian, TransUnion). It's free and takes about 15 minutes per bureau.
  • 2. Request an IRS Identity Protection PIN for any dependent who has a Social Security number - this blocks fraudulent tax returns in their name.
  • 3. Enroll in the credit monitoring PowerSchool or your district is offering. It's worth the few minutes.
  • 4. Watch for targeted phishing - texts or emails referencing your specific school district by name are red flags.
  • 5. Talk to your kids about social-engineering attempts that reference their school or teachers.

What school districts should do right now

  • Audit every vendor with admin-level access to student data and require MFA contractually.
  • Run a tabletop exercise built around vendor compromise - not just internal ransomware.
  • Map your data flow. Most districts cannot answer: "What student PII does each of our vendors actually hold?"
  • Get an independent vendor-risk assessment - your insurance carrier will increasingly demand one.

Why this matters beyond PowerSchool

PowerSchool is the canary, not the exception. K-12 districts have spent a decade aggressively adopting EdTech vendors - SIS, LMS, assessment platforms, parent-comms tools - each one a new admin-level door into the same student records. A single category-1 control failure (no enforced MFA on a support portal with cross-tenant access) propagated into the largest theft of children's data in U.S. history. The next breach will not look like ransomware on a district file server. It will look like this: one compromised vendor credential, one weekend, thousands of districts on the same notification list.

If you operate a district, run IT for a charter network, or sit on a school board, the question is no longer "are our vendors secure?" It's "do we have evidence they are - and a plan for when one of them isn't?"

Frequently asked questions

PowerSchool breach FAQ

What happened in the PowerSchool data breach?

Between December 19-28, 2024, an attacker used a stolen credential to access PowerSchool's PowerSource customer support portal and exfiltrate data from its Student Information System (SIS), exposing more than 62 million student records and 10 million teacher records across thousands of K-12 districts in the U.S. and Canada.

What information was stolen in the PowerSchool breach?

Stolen data varied by individual but included names, contact information, dates of birth, Social Security numbers, limited medical alert information, and other related personal data for students and teachers.

What should parents do after the PowerSchool breach?

Freeze your child's credit at all three bureaus, request an IRS Identity Protection PIN for any dependent with an SSN, enroll in the credit monitoring offered by PowerSchool or your district, and watch for phishing messages referencing your school district.

Did paying the ransom stop the PowerSchool leak?

No. PowerSchool paid roughly $2.85M in Bitcoin, but by May 2025 attackers were extorting individual school districts directly using samples of the stolen data - a textbook example of why ransom payment does not guarantee data deletion.

Matt Barnett, Founder and CEO of SEVN-X

Matt Barnett

Founder & CEO, SEVN-X - offensive security, incident response, and vendor-risk advisory

Connect on LinkedIn →

Achieve better cybersecurity

Worried your district is exposed?

Get a free 30-minute K-12 Vendor Risk briefing with a SEVN-X analyst. We'll review your top vendors and flag the gaps.

Request the briefing

Under attack right now?

SEVN-X runs incident response for breaches in progress. If you're actively dealing with one, reach out before anything else.

Open an IR ticket

Get breach breakdowns in your inbox

Plain-English analysis of the latest incidents, written for IT directors and executives - not researchers.

Subscribe