DisclosureLens
HackingTechnologyEducationInformationStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)MediumContained

PowerSchool

bd_299c4d0f82168353 · schema v1 · pii pii-v2

Severity

Medium

Discovered

Dec 28, 2024

Filed

Jan 29, 2025

To disclose

Affected

Not disclosed

Linked

16 filings

Confidence

67%
Full breach record for PowerSchool4 incidents on file

PowerSchool Group LLC disclosed a cybersecurity incident on December 28, 2024, involving unauthorized exfiltration of personal information from its Student Information System (SIS) via the PowerSource customer support portal. Affected data included names, contact info, DOB, SSNs, and limited medical alert info. PowerSchool offered two years of complimentary identity protection and credit monitoring to affected students and educators.

Incident timeline

Dec 28, 2024

Discovered

Jan 29, 2025

Filed

This filing is one of 16 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 2d gap

Showing first 10 of 15 linked disclosures.

Filing propagation · 11 filings · 10 states

View merged incident ↗
Montana State AGJan 27 · first
Iowa State AGJan 27 · first
Maine State AGJan 27 · first
Vermont State AGJan 27 · first
Idaho State AGJan 27 · first
Nebraska State AG+2d · this page

Cascade drawn from the first 10 linked disclosures of 15 — the full spread may be wider.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.