HackingStolen CredentialsData ExfiltratedSupply Chain (3P Vendor)PIIIDENTITY_BASICLowContained
Buhl School District #412
bd_95eba3eee5e9dd3b · schema v1 · pii pii-v1
Full breach record for Buhl School District #412 →Buhl School District #412 notified the Idaho Attorney General on January 10, 2025, of a cybersecurity incident involving its SIS provider, PowerSchool. An unauthorized party accessed student and teacher data using compromised credentials. The district notified employees and families, engaged forensic investigators (CyberSteward, CrowdStrike), and negotiated the destruction of stolen data.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2025/01/1-10-2025-Buhl-Joint-School-District-No.-412.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 10, 2025
- Raw hash
- f1c6ce823bfa806ca28bc02d3cbe9235789cc3b93ca817ce766bd5a39f601b55
Reporting entity
- Name
- Buhl School District #412norm: buhl school district 412
Victim entity
- Name
- Buhl School District #412norm: buhl school district 412
Incident
- Discovered
- Jan 7, 2025
- Materiality determined
- —
- Notification sent
- Jan 10, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Idaho Attorney General's Office Consumer Protection Division
- Third party
- via PowerSchool
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 3 days(3 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.