HackingData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
Cottonwood School District #242
bd_8db5783fc54e05e5 · schema v1 · pii pii-v1
Full breach record for Cottonwood School District #242 →Cottonwood School District #242 reported a data security incident to the Idaho Attorney General on March 11, 2025. The breach originated from third-party vendor PowerSchool, which provides Student Information Systems. The incident exposed Idaho residents' names and Social Security numbers. Cottonwood engaged legal counsel and a forensic firm, and PowerSchool provided notice and credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2025/03/Cottonwood120264775.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 11, 2025
- Raw hash
- b36dc13fd858357e9202f81607c038b8d0639c779b518c7967523a11e94f9929
Reporting entity
- Name
- ECKERT SEAMANS CHERIN & MELLOTT, LLCnorm: eckert seamans cherin mellott
Victim entity
- Name
- Cottonwood School District #242norm: cottonwood school district 242
Incident
- Discovered
- Mar 10, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Regulator citations
- Reporting a breach of the security of the system, pursuant to Idaho Code § 28-51-105(1)
- Third party
- via PowerSchool
- Initial access
- supply_chain
Compliance
- Time to disclose
- ≤1 day(1 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.