HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedData EncryptedPIIIDENTITY_BASICLowContained
Marsh Valley School District No. 21
bd_7d0948e8dba74d63 · schema v1 · pii pii-v1
Full breach record for Marsh Valley School District No. 21 →Marsh Valley School District No. 21 notified the Idaho Attorney General on January 9, 2025, of a data breach involving its PowerSchool Student Information System. An unauthorized party accessed student and teacher data using compromised credentials. The district engaged CyberSteward and CrowdStrike for investigation and negotiated with the attacker to destroy stolen data.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2025/01/1-9-2025-Marsh-Valley-School-District-No.-21-.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 9, 2025
- Raw hash
- b7b29e5372f4ce1987a97a162756c4fe2d1c703df2d32bbc718d1f053008cad7
Reporting entity
- Name
- Marsh Valley School District No. 21norm: marsh valley school district no 21
Victim entity
- Name
- Marsh Valley School District No. 21norm: marsh valley school district no 21
Incident
- Discovered
- Jan 7, 2025
- Materiality determined
- —
- Notification sent
- Jan 9, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Idaho Attorney General's Office Consumer Protection Division
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.