The December 2024 breach at PowerSchool exposed approximately 62 million student records and 9.5 million educator records across more than 18,000 North American schools. The route in was a customer-support portal that lacked multi-factor authentication. The company entered 2026 under new leadership with the consequences still working through.
The Control Was Absent, Not Defeated
This desk spends a good deal of its time on techniques that get around multi-factor authentication — vishing, consent phishing, session token theft. It is worth pausing on a case where there was nothing to get around.
A support portal is exactly the sort of system that acquires an exemption. It is not the main product, it is used by a small number of staff, enabling a second factor on it means configuring it for people at thousands of school districts, and every one of those is a support call.
Children Cannot Mitigate
Every standard remedy assumes an adult with financial agency. Credit monitoring requires a credit file. Fraud alerts require an account to place them against. A child has neither.
The exposure also has an unusually long tail. A record describing a nine-year-old remains an accurate identity document for decades, and the harm typically surfaces when that person first applies for credit — at which point the breach is a decade old and untraceable as a cause.
Districts Had No Leverage And No Alternative
A school district selecting a student information system is choosing from a small market, migrating is a multi-year project, and the district has no capacity to audit a vendor’s authentication configuration.
This is the concentration pattern filed at Conduent in 26-0731 and Instructure in 26-0501, in the sector least equipped to manage it. The affected population is compulsory: no child chose to attend a school running this software.
Compiled from public reporting, listed below. Figures are as reported. We did not review the affected records. Corrections: corrections@forensicpost.com.