Desk live·
ForensicPost
Ransomware/Extortion/File 25-0507

They Paid, and Got a Video of the Deletion

PowerSchool paid an extortion demand of roughly $2.85 million in bitcoin in exchange for a video purporting to show the only copy of the data being destroyed. In May 2025, school districts began receiving extortion emails containing samples of it.

Constructed geometry · not a chart of case data
TargetSchool districts
ActorUnattributed
D. Kennedy & S. Rosler13 min readConfidence: high4 sources reviewed

US Department of Justice filings made public on 20 May 2025 record that PowerSchool received an extortion demand of approximately $2.85 million in bitcoin following the December 2024 compromise, and that a payment was made. What the company received in return was a video in which the attackers claimed to be deleting the only copy of the stolen data.

By 7 May 2025, individual school districts in Canada and North Carolina were receiving extortion emails containing samples of that same data. The Toronto District School Board, which serves more than 240,000 students, confirmed receiving a demand accompanied by data linked to the December breach. PowerSchool stated that this was not a new intrusion.

The Video Is The Artefact Worth Keeping

Consider what was actually purchased. Not deletion — deletion is unobservable. Not even evidence of deletion. A recording, produced by the counterparty, of the counterparty performing an action on a system nobody else could inspect, asserting a property ("the only copy") that is unverifiable in principle.

It is not that the video was fake. It may well be a genuine recording of a genuine deletion of a genuine copy. That changes nothing, because the claim being sold was never about what happened on camera. Every ransom payment for data suppression buys exactly this and no more, and the PowerSchool case is unusually clear because the artefact is nameable.

The Second Demand Went To The Wrong People

When extortion resumed, the emails did not go to PowerSchool. They went to districts — organisations that had not been breached, had not paid, had no contractual standing in the original negotiation, and had no ability to affect the outcome.

This is a structural consequence of platform concentration that the payment decision did not account for. PowerSchool could settle its own exposure. It could not settle on behalf of 18,000 downstream organisations, each of which is independently identifiable in the data and independently reachable by email.

What It Does To The Payment Argument

The case for paying in a data-theft extortion has always rested on suppression: buying silence rather than buying decryption. Unlike a decryption key, suppression has no verifiable deliverable.

This file is the cleanest available counter-example to that reasoning, and it sits alongside 26-0501, where a payment produced shred logs. In both, the organisation paid, complied fully, received the promised artefact, and the data circulated anyway.

How we reported this

Compiled from public reporting and US court filings, listed below. The characterisation of the video is drawn from those filings as reported. We do not know whether any data was in fact deleted. Corrections: corrections@forensicpost.com.

Sources
  1. PowerSchool paid a hacker’s ransom, but now schools say they are being extortedTechCrunch
  2. School boards hit with ransom demands linked to PowerSchool cyberattackCBC News
  3. NC schools targeted for extortion again, months after PowerSchool data breachEdNC
  4. PowerSchool ransom fallout: extortion attempts hit schools months after data breachCyberInsider
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary