HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
Notus School District No. 135
bd_dacd873a936b901e · schema v1 · pii pii-v1
Full breach record for Notus School District No. 135 →Notus School District No. 135 notified the Idaho Attorney General on January 9, 2025, of a cybersecurity breach impacting its PowerSchool Student Information System (SIS). The incident, discovered on December 28, 2024, involved unauthorized access via compromised credentials. Affected data includes student and teacher names, contact information, and Social Security numbers. The district is providing credit monitoring and identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2025/01/1-9-2025-Notus-School-District-135.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 9, 2025
- Raw hash
- 38a908d2c1f44f3ec409e02421e7d546bd546eb22d7a5b091d40328b186fdb9a
Reporting entity
- Name
- Notus School District No. 135norm: notus school district no 135
Victim entity
- Name
- Notus School District No. 135norm: notus school district no 135
Incident
- Discovered
- Dec 28, 2024
- Materiality determined
- Jan 9, 2025
- Notification sent
- Jan 9, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Idaho Attorney General's Office under IC§33-133, IC§28-51-105 and Notus School District Policy 9550
- Third party
- via PowerSchool
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 days(12 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.