⚡ The Damage
62 million students. 9.5 million teachers. 40 years of data (per Bleeping Computer).
One stolen password gave hackers everything. Social Security numbers. Medical records. Special education plans. Mental health notes. Grades back to 1985.
PowerSchool paid an undisclosed ransom. Got a video of hackers "deleting" data. The data's still being sold.[1]
🔓 How One Password Destroyed Privacy for a Generation
December 2024. A hacker logs into PowerSource using a single employee password. No malware. No backdoor. Just a "Maintenance Access" account without multi-factor authentication.[2]
PowerSchool's own executive admitted: "the hackers were able to access and download the student records by logging into one account that didn't have two-factor authentication enabled."[3]
The hacker downloaded everything. PowerSchool only found out when the attacker contacted them demanding payment. They were clueless for "several days" after the breach.[4]
Your kid's data was stolen and PowerSchool didn't even know.
📊 What They Stole (Everything That Matters)
Identity Data
- Names and addresses
- Social Security numbers
- Birth dates
- Parent contact info
312,000 teachers' SSNs in North Carolina alone.[5]
Medical Records
- Disability diagnoses
- Special education plans (IEPs)
- Mental health accommodations
- Medication records
"Massively sensitive" according to education security experts.[6]
Academic History
- Every grade since kindergarten
- Attendance records
- Disciplinary actions
- Teacher comments
Toronto schools: 40 years of data stolen.[7]
🗺️ Who Got Hit (Your District Is Probably on This List)
PowerSchool has statewide contracts with:[8]
- Alabama: Every public school
- North Carolina: All districts
- South Carolina: Entire state system
Plus major districts in 35 other states:
- Toronto District School Board: 40 years of data[9]
- Rochester City Schools: 134,000 students[10]
- Los Angeles Unified: Status unknown (PowerSchool won't say)
- Chicago Public Schools: Investigating exposure
PowerSchool claims 16,000 school customers. They won't release the full list.[11]
💸 The Ransom That Didn't Work
Here's the timeline of stupidity:
- Late December: Hackers demand $2.85 million in Bitcoin[12]
- PowerSchool pays: Gets video of hackers "deleting" data
- January 2025: Data starts appearing on dark web
- May 7, 2025: Hackers still extorting Canadian schools with samples[13]
PowerSchool believed a video. Of hackers pressing delete. That's the security you're dealing with.
🚨 Why This Is Worse Than You Think
Kids Can't Change Their SSNs
Adults can get new credit cards. New passwords. Even new Social Security numbers in extreme cases.
Kids? They're stuck. That SSN follows them to college applications. Job applications. Background checks. For life.
Identity thieves love child SSNs. Clean credit. No monitoring. Parents don't check kid's credit reports.
The Special Education Nightmare
Stolen IEPs (Individualized Education Programs) contain:[14]
- Autism diagnoses
- ADHD medication dosages
- Behavioral intervention plans
- Psychological evaluations
- Family therapy notes
This data never expires. Your kid's future employer could buy their kindergarten ADHD diagnosis on the dark web.
🔍 How PowerSchool Screwed Up (Let Us Count the Ways)
Security Failures
- No multi-factor authentication on customer portal[15]
- Single credential accessed everything
- 9 days before detection
- 19 days before notifying schools
- 25 days before public disclosure
- Paid ransom to criminals (always works great)
- Believed a deletion video from hackers
NBC News obtained internal documents showing PowerSchool "failed to take basic precautions."[16] Basic. Precautions.
📱 What's Happening Now
PowerSchool's "Response"
- Hired CrowdStrike (after the breach)[17]
- Offering credit monitoring to "a subset" of victims[18]
- Identity protection for minors (undefined duration)
- Finally adding multi-factor authentication
Schools Scrambling
- Districts sending breach notices
- Parents flooding help desks
- No one knows full extent
- PowerSchool won't say which schools affected
Hackers Still Active
May 2025: Extortion emails with data samples hit schools in:[19]
- Ontario, Canada
- North Carolina
- Unknown additional targets
✅ What Parents Need to Do NOW
Immediate Actions:
- ☐ Contact your school district - demand answers about exposure
- ☐ Freeze your child's credit at all three bureaus (yes, kids can have credit frozen)
- ☐ Document everything - save breach notices, emails, dates
- ☐ Check if your state allows child credit monitoring
- ☐ Request your child's records from PowerSchool
Credit Freeze Process for Minors:
- Gather documents (birth certificate, SSN card, your ID)
- Contact Experian: 1-888-397-3742
- Contact Equifax: 1-800-685-1111
- Contact TransUnion: 1-888-909-8872
- Each requires different forms - all are free
Long-term Monitoring:
- ☐ Annual credit checks when child turns 16
- ☐ Watch for tax fraud (someone claiming your kid as dependent)
- ☐ Monitor medical insurance for false claims
- ☐ Save all documentation for potential lawsuits
🎯 The Bigger Picture
PowerSchool controls 50 million students' data. They're owned by Bain Capital (bought for $5.6 billion in 2024).[20]
Private equity owns your kid's data. They secured it with a single password.
This isn't just about PowerSchool. It's every EdTech company:
- Google Classroom tracking everything
- Zoom recording classes
- Learning apps profiling kids
- AI tutors building psychological profiles
Schools hand over student data like candy. No audits. No security requirements. No consequences.
💀 What Happens Next
The Ugly Truth
Your kid's data is gone. Forever. It's being sold, resold, and packaged into identity theft bundles.
In 5 years, when your kid applies for college loans, they'll discover someone already did. With their SSN.
In 10 years, job background checks will surface their kindergarten behavior reports.
In 15 years, their kids will ask why grandpa's childhood medical records are on the internet.
🔒 How to Protect What's Left
- Demand your school district's data retention policy - Why keep 40 years of data?
- Opt out of everything optional - Photos, directories, third-party apps
- Request data minimization - Schools don't need SSNs for lunch accounts
- Push for state laws - Illinois banned biometric collection in schools. Your state can too.
- Join the lawsuits - Class actions are forming
🎯 The Bottom Line
62 million students just became lifelong identity theft targets because PowerSchool couldn't be bothered with two-factor authentication.
The ransom is paid. The data is sold. The damage is permanent.
And PowerSchool? They're offering "identity protection services." Like putting a bandaid on a severed limb.
📚 References
- TechCrunch - What PowerSchool won't say about its data breach (March 2025)
- NBC News - PowerSchool hack: missed basic security step (2025)
- TechCrunch - PowerSchool begins notifying after breach (January 28, 2025)
- Education Week - PowerSchool Data Breach Timeline (January 2025)
- NewsNation - North Carolina teachers SSN exposure (2025)
- TechTarget - PowerSchool breach explanation (2025)
- TechCrunch - Toronto 40 years of data (2025)
- Education Week - Statewide contracts (2025)
- NewsNation - Toronto District School Board breach (2025)
- TechCrunch - Rochester 134,000 students (2025)
- TechTarget - 16,000 school customers (2025)
- TechCrunch - $2.85 million ransom payment (2025)
- NewsNation - May 2025 extortion emails (2025)
- Education Week - Special education data exposure (2025)
- TechCrunch - No MFA on PowerSource portal (2025)
- NBC News - Failed basic precautions (2025)
- TechTarget - CrowdStrike hired post-breach (2025)
- TechCrunch - Credit monitoring for subset (2025)
- NewsNation - May extortion attempts (2025)
- Proskauer - Bain Capital ownership (2025)