HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICLowContained
Kendrick Joint School District No. 283
bd_420e28d1238fcae4 · schema v1 · pii pii-v1
Full breach record for Kendrick Joint School District No. 283 →Kendrick Joint School District No. 283 (Idaho) notified the state Attorney General on January 9, 2025, of a cybersecurity incident involving its PowerSchool student information system. A threat actor used valid PowerSchool Maintenance credentials to access the server and export 523 student and 91 teacher records (614 total) on December 22, 2024. The breach has been contained by the vendor, PowerSchool.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed614 affectedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2025/01/1-9-2025-Kendrick-Joint-School-District-No.-283.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 9, 2025
- Raw hash
- cdd9d9ebc16f1d190556153996d0b0a609859f8aba4d303ef9207799506752af
Reporting entity
- Name
- Kendrick Joint School District No. 283norm: kendrick joint school district no 283
Victim entity
- Name
- Kendrick Joint School District No. 283norm: kendrick joint school district no 283
Incident
- Discovered
- Dec 22, 2024
- Materiality determined
- —
- Notification sent
- Jan 9, 2025
- Affected individuals
- 614
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Idaho Attorney General's Office Consumer Protection Division
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.