HomeSecurityPowerSchool hacker now blackmailing other school districts

PowerSchool hacker now blackmailing other school districts

PowerSchool is warning that the hacker behind the December cyberattack is now blackmailing individual schools, threatening to release previously stolen student and teacher data unless a ransom is paid. PowerSchool apologized for the ongoing threats stemming from the security breach and said it will continue to work with its customers and law enforcement to address the blackmail.

See also: Hacker tried to breach Kraken platform via job application

PowerSchool hacker

The company also recommends that students and teachers take advantage of its free two-year credit profile monitoring and identity protection service to protect themselves from fraud and identity theft. More information is available in the company's FAQ regarding the security incident.

PowerSchool also addressed its decision to pay the ransom, describing it as a difficult one but expressing hope that it would protect its customers. Among the school districts now being individually blackmailed by the attacker are districts in North Carolina and the Toronto District School Board (TDSB), which is the largest school district in Canada.

In January, PowerSchool revealed that its PowerSource customer support portal was compromised through compromised credentials. Using this access, hackers used a PowerSource remote maintenance tool to connect to and download school district databases from systems .

See also: TerraStealerV2 & TerraLogger: The new malware from the Golden Chickens hackers

The databases contained different information depending on the district, such as full names of students and teachers, home addresses, phone numbers, passwords, parent and contact information, Social Security numbers, medical data, and grades.

PowerSchool hacker now blackmailing other school districts

The PowerSchool breach was initially detected on December 28, 2024, but the company later revealed that the hacker's access had begun months earlier, in August and September 2024, through the same compromised credentials.

Cybersecurity experts and ransom negotiators have repeatedly advised companies not to pay ransoms to avoid data leakage, as cybercriminals increasingly fail to keep their promise to delete stolen data.

See also: Romania elections: Russian hackers carried out DDoS attacks

A related and worrying element emerging from these types of cyberattacks is that educational organizations – such as schools and universities – are becoming increasingly common targets, due to the large amounts of personal data they handle and their typically limited cybersecurity. Furthermore, because they often want to protect students and staff, they may be more easily swayed by ransom demands, which encourages further attacks.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS