PowerSchool disclosed in early January 2025 that an unauthorised party had used a single compromised credential to enter its customer support portal in December 2024, and from there reached PowerSchool SIS — the student information system used by more than 18,000 schools to hold student records, grades, attendance and enrolment data for around 60 million students across North America.
In an extortion demand, the attacker claimed to have taken data on 62.4 million students and 9.5 million teachers. Reporting has consistently noted that the account used was not protected by multi-factor authentication.
A Support Portal Is A Production System
The route here is the one this desk keeps filing: not the customer-facing application, but the operational tooling behind it. Support portals exist so that staff can reach customer environments to fix things, which means by construction they hold the access that makes fixing things possible.
They are also, routinely, classified as internal tooling rather than as production, and inherit a weaker control set as a result. The same shape appears at 25-0826, where API tokens sat in support tickets, and in the platforms ShinyHunters claims to have drawn from at 26-0714 — a service catalogue, a document store, an analytics workspace and a procurement system, none of which is customer-facing.
The Affected Population Could Not Have Consented
A district selects a student information system. Parents and children are not party to that decision, cannot decline it without withdrawing from the school, and in most cases will not know the vendor’s name until a notification arrives.
And the records are of minors, which forecloses the usual remediation. A child has no credit file to freeze — the argument this desk set out at 26-0113. Identity data belonging to a seven-year-old has a useful life to a fraudster measured in decades, and no monitoring product is written for that horizon.
The Concentration Was The Point Of The Product
It is worth resisting the easy conclusion. Eighteen thousand schools did not make eighteen thousand bad decisions. A shared platform gives a small district professional-grade software it could never build, and the alternative — every district running its own — would produce worse security in aggregate, not better.
The problem is not that concentration happened. It is that the security investment did not scale with it. A vendor holding one district’s records and a vendor holding 18,000 districts’ records were, in December 2024, protecting a support account to the same standard.
Compiled from public reporting, listed below, and from figures made public in US court filings. The 62.4 million and 9.5 million figures originate in the attacker’s extortion demand and are recorded here as claims. Corrections: corrections@forensicpost.com.
- PowerSchool hacker claims they stole data of 62 million studentsBleepingComputer
- What PowerSchool won’t say about its data breach affecting millions of studentsTechCrunch
- PowerSchool hack: missed basic security step resulted in data breachNBC News
- PowerSchool data breach: explaining how it happenedTechTarget