Supply chain ⛓ Supply Chain

PowerSchool SIS data breach — 62 million students and 9.5 million educators

📅 2024-12-19 🏢 PowerSchool Student Information System (SIS) / PowerSource customer portal
Primary Source ↗

Incident Details

Attacker (later identified as Massachusetts college student Matthew D. Lane, 19) used compromised credentials to access PowerSchool’s PowerSource support portal on 19 December 2024; detected 28 December. Data exfiltrated for 62 million students and 9.5 million educators globally — largest breach of children’s data in US history. Data: names, contact info, dates of birth, limited medical alerts, SSNs (for <25% of students), and other student records. PowerSchool paid a ransom of $2.85 million demanded by Lane. Payment did not prevent re-extortion: by May 2025 individual school districts received separate ransom demands from the same dataset. Lane charged and sentenced to 4 years in federal prison. Supply chain impact as thousands of school districts had no direct relationship with PowerSchool.

Technical Details

Initial Attack Vector
CWE-287: Improper Authentication (stolen/compromised credentials for PowerSource customer support portal; no mandatory MFA)
Vendor / Product
PowerSchool Student Information System (SIS) / PowerSource customer portal
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-12-19 Breach occurred
  2. 2024-12-28 Publicly disclosed
  3. 2025-01-07 Customers notified