Desk live·
ForensicPost
Breaches/Education/File 26-0113

PowerSchool Breach Reached 62 Million Student Records Across 18,000 Schools

The PowerSchool breach reached roughly 62 million student and 9.5 million educator records across more than 18,000 schools, through a customer-support portal without multi-factor authentication. The fallout ran through 2026.

Constructed geometry · not a chart of case data
TargetPowerSchool
ActorUnattributed
D. Kennedy13 min readConfidence: high2 sources reviewed

The December 2024 breach at PowerSchool exposed approximately 62 million student records and 9.5 million educator records across more than 18,000 North American schools. The route in was a customer-support portal that lacked multi-factor authentication. The company entered 2026 under new leadership with the consequences still working through.

The Control Was Absent, Not Defeated

This desk spends a good deal of its time on techniques that get around multi-factor authenticationvishing, consent phishing, session token theft. It is worth pausing on a case where there was nothing to get around.

A support portal is exactly the sort of system that acquires an exemption. It is not the main product, it is used by a small number of staff, enabling a second factor on it means configuring it for people at thousands of school districts, and every one of those is a support call.

Children Cannot Mitigate

Every standard remedy assumes an adult with financial agency. Credit monitoring requires a credit file. Fraud alerts require an account to place them against. A child has neither.

The exposure also has an unusually long tail. A record describing a nine-year-old remains an accurate identity document for decades, and the harm typically surfaces when that person first applies for credit — at which point the breach is a decade old and untraceable as a cause.

Districts Had No Leverage And No Alternative

A school district selecting a student information system is choosing from a small market, migrating is a multi-year project, and the district has no capacity to audit a vendor’s authentication configuration.

This is the concentration pattern filed at Conduent in 26-0731 and Instructure in 26-0501, in the sector least equipped to manage it. The affected population is compulsory: no child chose to attend a school running this software.

How we reported this

Compiled from public reporting, listed below. Figures are as reported. We did not review the affected records. Corrections: corrections@forensicpost.com.

Sources
  1. PowerSchool in 2026: new CEO, data breach fallout, and $285K contract winsCivic IQ
  2. Education cybersecurity statistics 2026: school breaches, ransomware, and student data riskDeepstrike
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary