HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
PowerSchool
bd_44f09dcd18ee4d0b · schema v1 · pii pii-v1
Full breach record for PowerSchool →PowerSchool disclosed a cybersecurity incident on December 28, 2024, involving unauthorized exfiltration of personal information from its Student Information System via the PowerSource support portal. Data types included names, contact info, DOB, SSNs, and limited medical alert info. PowerSchool engaged forensic experts and is offering two years of complimentary identity protection and credit monitoring to affected students and educators.
Vermont clock⏱ VT AG >14 bday4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_14ac2c628ad65a74Montana State AGfiled 2025-01-27Candidate
- bd_2390e896c65d5b5fIowa State AGfiled 2025-01-27Verified
- bd_438ff508f653f09dMaine State AGfiled 2025-01-27Verified
- bd_56171406702909c2Idaho State AGfiled 2025-01-27Verified
Show 2 more filings ↓Show fewer ↑
- bd_9a98070b775c7a1cNew Hampshire State AGfiled 2025-01-27Verified
- bd_ec1bace9d0e95897Idaho State AGfiled 2025-01-27Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-01-27-powerschool-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 27, 2025
- Raw hash
- bb4e003d0f47e495839d85ffd609a393c905c9ef06515a14723c961c7e4b5481
Reporting entity
- Name
- PowerSchoolnorm: powerschool
Victim entity
- Name
- PowerSchoolnorm: powerschool
Incident
- Discovered
- Dec 28, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.