PowerSchool security incident

Compromised support-portal credentials, no MFA. Data on tens of millions of US/Canadian students and teachers stolen; PowerSchool paid the extortion demand, then individual school districts were re-extorted with the same stolen data months later.

Last modified

Summary

  • Environment: EdTech / K-12 student information systems
  • Operational impact: Data on tens of millions of US/Canadian students and teachers stolen; PowerSchool paid the extortion demand, then individual school districts were re-extorted with the same stolen data months later
  • Financial impact: No financial figure is established by the reviewed source evidence
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In Dec 2024 / Jan 2025, PowerSchool experienced an incident in its edtech / k-12 student information systems environment. The retained source describes the attack path as follows: Compromised support-portal credentials, no MFA. [1]

The documented consequence was: Data on tens of millions of US/Canadian students and teachers stolen; PowerSchool paid the extortion demand, then individual school districts were re-extorted with the same stolen data months later. [1]

Impact

  • Documented impact: Data on tens of millions of US/Canadian students and teachers stolen; PowerSchool paid the extortion demand, then individual school districts were re-extorted with the same stolen data months later. [1]
  • No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.

Timeline

  1. Documented public update

    The PowerSchool cybersecurity incident records the incident facts used in this briefing.

    [1]
  2. Briefing updated

    This briefing was last reviewed and updated on September 19, 2026.

Threat Group & Attack Vector

The retained source describes the attack path as follows: Compromised support-portal credentials, no MFA. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The retained source reports that identity or credit monitoring was offered to affected people. [1] The retained source describes containment action intended to limit further access or disruption. [1]

This account is bounded to PowerSchool cybersecurity incident. Details absent from that evidence are left unresolved rather than inferred. [1]