SEVN-X founder Matt Barnett joined NBC10 Philadelphia to unpack the largest theft of children's data in U.S. history — a breach that exposed more than 62 million students and 10 million teachers across thousands of K-12 districts.
Between December 19–28, 2024, an attacker used a stolen credential to log into PowerSchool's PowerSource customer support portal and exfiltrate data from its Student Information System. The breach exposed names, addresses, dates of birth, Social Security numbers, and limited medical information for 62M+ students and 10M+ teachers across thousands of K-12 districts in the U.S. and Canada. PowerSchool paid a ~$2.85M ransom — the data resurfaced anyway, and attackers later extorted individual districts directly.
<script type="text/javascript" charset="UTF-8" src="https://nbcphiladelphia.com/portableplayer/?CID=1:12:4073494&videoID=2400713283770&origin=nbcphiladelphia.com&fullWidth=y&autoplay=true"></script>
| Date | Event |
|---|---|
| Dec 19–23, 2024 | Initial unauthorized access to PowerSchool's PowerSource portal |
| Dec 28, 2024 | PowerSchool detects the intrusion and receives a ~$2.85M Bitcoin ransom demand |
| January 2025 | Scope confirmed: 62M+ student records and 10M+ teacher records exfiltrated |
| May 2025 | Attackers begin extorting individual school districts directly with sample data |
| Oct 14, 2025 | Matthew D. Lane, 20, sentenced to four years in federal prison + $14.1M restitution |
PowerSchool is the canary, not the exception. K-12 districts have spent a decade aggressively adopting EdTech vendors — SIS, LMS, assessment platforms, parent-comms tools — each one a new admin-level door into the same student records. A single category-1 control failure (no enforced MFA on a support portal with cross-tenant access) propagated into the largest theft of children's data in U.S. history. The next breach will not look like ransomware on a district file server. It will look like this: one compromised vendor credential, one weekend, thousands of districts on the same notification list.
If you operate a district, run IT for a charter network, or sit on a school board, the question is no longer "are our vendors secure?" It's "do we have evidence they are — and a plan for when one of them isn't?"
Get a free 30-minute K-12 Vendor Risk briefing with a SEVN-X analyst. We'll review your top vendors and flag the gaps.
Request the briefingSEVN-X runs incident response for breaches in progress. If you're actively dealing with one, reach out before anything else.
Open an IR ticketPlain-English analysis of the latest incidents, written for IT directors and executives — not researchers.
Subscribe