HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCriticalActive
PowerSchool
bd_782d885f67a40c38 · schema v1 · pii pii-v1
Full breach record for PowerSchool →PowerSchool, a technology service provider for school districts, reported a cybersecurity incident in Maryland affecting approximately 145,783 residents. The incident occurred between December 19 and December 28, 2024, involving unauthorized exfiltration of personal information (names, SSNs, DOBs, limited medical alerts) via a customer support portal. PowerSchool engaged forensic experts and law enforcement, and is offering credit monitoring through Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed145,783 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376245.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 6b5b081e7d3a2422d89017b819817e793c028a227bdc8dacd47ca1ba033b428a
Reporting entity
- Name
- ROPES & GRAY LLPnorm: ropes gray
Victim entity
- Name
- PowerSchoolnorm: powerschool
Incident
- Discovered
- Dec 28, 2024
- Materiality determined
- —
- Notification sent
- Jan 27, 2025
- Affected individuals
- 145,783
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General's Identity Theft Unit
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 46 weeks(320 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.