Supply chain
β Supply Chain
94 K-12 Schools Third-Party Breach (January 2025)
Primary Source βIncident Details
PowerSchool hack exposes student, teacher data from K-12 districts. Education software giant PowerSchool has confirmed it suffered a cybersecurity incident that allowed a threat actor to steal the personal information of students and teachers from school districts using its PowerSchool SIS platform. School districts known to be impacted by the PowerSchool breach are listed the bottom of the article. PowerSchool is a cloud-based software solutions provider for K-12 schools and districts that supports over 60 million students and over 18,000 customers worldwide. The company offers a full range of services to help school districts operate, including platforms for enrollment, communication, attendance, staff management, learning systems, analytics, and finance. Third-party company: PowerSchool.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- PowerSchool
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-01-01 Breach occurred
- 2025-01-07 Publicly disclosed