PowerSchool awell-known educational software provider, has begun notifying individuals in the US and Canada whose personal information was affected by a cyberattack – a data breach in late December 2024.

The company has not yet disclosed the exact number of people affected by the incident. A detailed report on exactly what happened is expected to be released by CrowdStrike, which is participating in the investigation.
The cyberattack that hit PowerSchool
PowerSchool is a K-12 software provider. It serves over 60 million students and 18,000 customers worldwide, offering enrollment, communication, monitoring, personnel management, learning, analytics, and financial solutions.
See also: ENGlobal: November attack led to data breach
In December, the company suffered a breach, and attackers gained unauthorized access to one of customer support , PowerSource, and were able to steal sensitive data from 6,505 school districts.
The PowerSchool data breach affects various information (depending on the district):
- full names
- physical addresses
- contact information
- social security numbers (SSN)
- medical data
- grades
Although PowerSchool says the data breach affected only a subset of customers, a hacker claimed to have stolen data of 62.488.628 students and 9.506.624 teachers.
In an update posted on PowerSchool's website yesterday, the company says it has begun notifying those affected by the data breach. This includes current and former students, their parents and guardians, and educators in the US.
See also: TalkTalk investigates data breach allegations
PowerSchool has already shared a sample notification with the Maine Attorney General's office, which says 33,488 people were affected in that state. However, it does not include the total number of victims.
Depending on the school district, they will notify individuals if their Social Security Numbers and medical information have been stolen, which does not appear to be the case for Maine residents.

The company offers affected students and teachers free identity theft protection services and credit monitoring for two years.
Educational sector: Cyberattack protection strategies
One of the most effective strategies is to educate staff and students about cyberattacks. This can include learning the basics of cybersecurity, understanding the most common attack techniques, and learning best practices for protecting personal and institutional data. For example, it is essential to use strong and unique logins and enable MFA on accounts wherever and whenever possible.
See also: UnitedHealth: 2024 data breach ultimately affected 190 million people
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, the use of advanced security solutions, such as intrusion protection systems (IPS), intrusion detection systems (IDS), and antivirus software, can provide significant protection against cyberattacks. These tools can detect and repel attacks before they cause significant damage.
Network segmentation can also help protect educational institutions by preventing a potential attack from spreading to all systems.
Implementing a least privilege policy, which limits access to systems and applications to only those who truly need that access, can reduce the risk of cyberattacks.
Updating all software and applications is also essential, as it fixes potential security vulnerabilities that hackers can exploit.
Finally, regularly backing up important data and implementing disaster recovery plans can ensure that, even if a cyberattack occurs, data can be recovered.
Source: www.bleepingcomputer.com
