HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTPHICriticalContained
Maryland State Department of Education
bd_f1054e4230dfcee4 · schema v1 · pii pii-v1
Full breach record for Maryland State Department of Education →Maryland State Department of Education (MSDE) reported a breach involving PowerSchool SIS affecting 177,658 individuals (155,452 students and 22,206 teachers). The incident occurred between Dec 19-28, 2024, when a threat actor accessed the PowerSource Portal using valid credentials due to lack of MFA/VPN. Data exfiltrated included names, addresses, SSNs, EINs, and some PHI. MSDE acted as the reporting entity for seven affected school districts. Remediation included engaging CyberSteward, strengthening passwords, blocking access, and providing credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed177,658 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376816.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- 1ea44486b4f8d94a56d9d1c6f0007cc223f512693317775dda0109e8961fe807
Reporting entity
- Name
- Maryland State Department of Educationnorm: maryland state department of education
- Domain
- marylandpublicschools.org
Victim entity
- Name
- Maryland State Department of Educationnorm: maryland state department of education
- Domain
- marylandpublicschools.org
Incident
- Discovered
- Dec 28, 2024
- Materiality determined
- —
- Notification sent
- Jan 7, 2025
- Affected individuals
- 177,658
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported incident to Maryland’s SOCSubmitted consolidated report to MD PIGA via MSDE
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 months(481 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.