HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowActive
Madison School District No. 321
bd_26685469147a5603 · schema v1 · pii pii-v1
Full breach record for Madison School District No. 321 →Madison School District No. 321 (Idaho) notified the Idaho Attorney General on January 10, 2025, of a cybersecurity incident involving its third-party vendor, PowerSchool. The incident resulted in unauthorized access to student and teacher contact information (names and addresses). The district blocked IP addresses and notified law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2025/01/1-10-2025-Madison-School-District-No.-321.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 10, 2025
- Raw hash
- 6311292f46036eebb11c00de0cbce3f9e67eb3079558c50f236ded04098553c2
Reporting entity
- Name
- Madison School District No. 321norm: madison school district no 321
Victim entity
- Name
- Madison School District No. 321norm: madison school district no 321
Incident
- Discovered
- Jan 9, 2025
- Materiality determined
- —
- Notification sent
- Jan 10, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified Idaho Attorney General's Office
- Third party
- via PowerSchool
- Initial access
- supply_chain
Compliance
- Time to disclose
- ≤1 day(1 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.