PowerSchool
ent_c0ef1b1b30afc6187a648485
Disclosures
14
State AG · SEC 10-K Item 1C · 12 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
314,107
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PowerSchool
- Normalized
- powerschool— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- 🦀Maryland State AGas victim2025-11-13
PowerSchool, a technology service provider for school districts, reported a cybersecurity incident in Maryland affecting approximately 145,783 residents. The incident occurred between December 19 and December 28, 2024, involving unauthorized exfiltration of personal information (names, SSNs, DOBs, limited medical alerts) via a customer support portal. PowerSchool engaged forensic experts and law enforcement, and is offering credit monitoring through Experian.
- 🌴South Carolina State AGas reporting2025-04-28
South Carolina Attorney General's office published a consolidated PDF of security breach notices involving PowerSchool, a technology provider for school districts. The filing aggregates notices from multiple SC school districts (Hampton County, Lexington School District Four, Lancaster County, Carolus Online Academy, SC DJJ School District) with notification dates ranging from January to May 2025. Total affected individuals across these districts exceed 92,000. The source document contains no narrative details regarding the cause, data types, or response actions.
- 🦬Montana State AGas victim2025-01-27
PowerSchool reported a data breach to the Montana Attorney General. The breach was reported on 2025-01-27. The breach occurred from 12/19/2024 to 12/28/2024. 41,520 Montana residents were affected.
- 🌽Iowa State AGas victim2025-01-27
Powerschool, a education sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-01-27.
- 🦞Maine State AGas victim2025-01-27
PowerSchool Group LLC, an education technology provider, reported a data breach to the Maine Attorney General. The breach, described as an external system breach (hacking), occurred between December 19, 2024, and December 28, 2024, and was discovered on December 28, 2024. The total number of affected individuals, including Maine residents, is yet to be determined. PowerSchool plans to notify affected consumers electronically on January 29, 2025, and is offering two years of complimentary identity protection and credit monitoring services through Experian.
- 🍁Vermont State AGas victim2025-01-27
PowerSchool disclosed a cybersecurity incident on December 28, 2024, involving unauthorized exfiltration of personal information from its Student Information System via the PowerSource support portal. Data types included names, contact info, DOB, SSNs, and limited medical alert info. PowerSchool engaged forensic experts and is offering two years of complimentary identity protection and credit monitoring to affected students and educators.
- 🥔Idaho State AGas victim2025-01-27
PowerSchool notified the Idaho Attorney General on January 27, 2025, of a cybersecurity incident occurring between December 19 and 28, 2024. Unauthorized actors exfiltrated personal information from the PowerSchool Student Information System (SIS) via the PowerSource support portal. Approximately 29,074 Idaho residents (students, former students, and teachers) were affected. Data included names, contact info, SSNs, dates of birth, and limited medical alerts. PowerSchool engaged forensic experts, reported to law enforcement, and offered two years of credit monitoring via Experian.
- ⛰️New Hampshire State AGas victim2025-01-27
PowerSchool, a technology service provider to school districts, disclosed a cybersecurity incident affecting approximately 9,384 New Hampshire residents. The unauthorized exfiltration of personal information (including names, SSNs, and dates of birth) occurred between December 19 and December 28, 2024, and was discovered on December 28, 2024. PowerSchool engaged forensic experts, notified law enforcement, and is offering two years of credit monitoring and identity protection services.
- 🌲Washington State AGas victim2025-01-27
PowerSchool Group LLC, a education sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2024-12-28 and filed notice on 2025-01-27. 314,107 Washington residents were affected. 30 days elapsed between awareness and notification. 9 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2025-01-27
PowerSchool Group LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-01-27. The breach occurred during 12/19/2024 - 12/28/2024. The breach was discovered on 12/28/2024. 0 individuals were affected. Notice was sent on 1/1/0001.
- 🥔Idaho State AGas victim2025-01-27
Idaho AG received supplemental notice from PowerSchool regarding a cybersecurity incident occurring between Dec 19-28, 2024. Personal information of state residents (students/teachers) was exfiltrated, including names, DOB, SSN, and limited medical alerts. PowerSchool estimates 84% of Idaho customers are hosted; on-prem customer data is excluded from this notice.
- ⛰️New Hampshire State AGas victim2025-01-14
Perkins School for the Blind notified the New Hampshire Attorney General of a data security incident involving PowerSchool, a third-party data management provider. On December 28, 2024, PowerSchool discovered unauthorized access to its Student Information System (SIS) via a compromised credential. The breach affected 3 New Hampshire residents, involving parent and student contact information and Social Security Numbers. PowerSchool contained the incident, deactivated credentials, reset passwords, and engaged law enforcement (FBI). Perkins is offering credit monitoring to affected individuals.
- 🧀Wisconsin State AGas victim2025-01-07
PowerSchool reported a data breach to the Wisconsin DATCP. The public was notified on 2025-01-07. The incident occurred on Between December 19 and December 28, 2024. Data accessed: Individuals' names, contact information, dates of birth, limited medical alert information, Social Security numbers, and other related information.
- FEDERALSEC 10-K Item 1Cas victim2024-03-01
PowerSchool's FY2023 Form 10-K Item 1C cybersecurity disclosure describes the company's risk management, ISMS governance (ISO/IEC 27001:2013), and Board/Audit Committee oversight processes. The filing explicitly states that in 2023 no cybersecurity threats materially affected the company's business strategy, results of operations, or financial condition. No specific incident, affected count, threat actor, or data exposure is disclosed.