Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Ransomware - PowerSchool Breach Escalates: 60 Million Students, 9.5 Million Teachers Now Targets of Ransom Demands
Ransomware Attacks Data Breach Data Protection News & Analysis

PowerSchool Breach Escalates: 60 Million Students, 9.5 Million Teachers Now Targets of Ransom Demands

Kirsten DoyleBy Kirsten DoyleMay 9, 20256 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
PowerSchool Breach Escalates
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

One of the largest data breaches in U.S. educational history is worsening, as the attacker behind the December 2024 cyberattack on PowerSchool is now directly extorting affected schools, threatening to leak sensitive student and teacher data unless ransom payments are made. 

PowerSchool, a widely used student information system (SIS) platform across American K–12 institutions, confirmed that the breach compromised. Data belonging to over 60 million students and 9.5 million educators. Initially believed to have been resolved after PowerSchool paid an undisclosed ransom to the attackers in exchange for a video showing the data’s deletion, the situation has taken a dramatic turn. The data was not deleted as promised, and schools are now receiving direct threats. 

Breach Details: How It Happened 

According to PowerSchool, the breach occurred on 28 December 2024, when bad actors exploited vulnerabilities in PowerSource, the company’s customer support portal. This allowed unauthorized access and data exfiltration from multiple school environments using the PowerSchool SIS. 

The type of information stolen varies by individual but may include: 

  • Full names and contact details 
  • Dates of birth 
  • Social Security Numbers 
  • Limited medical alerts 
  • Other sensitive personal information 

What PowerSchool Is Offering 

In response to the breach and subsequent threats, PowerSchool is offering two years of complimentary identity protection and credit monitoring services through Experian for affected individuals, including minors. Enrollment must be completed by 31 July 2025, using the activation codes provided in the official notice. 

For individuals 18 and older: 

  • Activation Code: CTYU949PRK 
  • Engagement Number: B138812 

For individuals under 18: 

  • Activation Code: CEBP456TRK 
  • Engagement Number: B138813 

Both plans include monitoring for fraud, dark web surveillance, identity restoration support, and $1 million in identity theft insurance. 

Why PowerSchool Paid Up 

PowerSchool acknowledged that it initially chose to pay the ransom in the hope of protecting its users and preventing the release of data. The company expr 

The company expressed regret over its decision, saying it had few options, and was under pressure. “In the days following our discovery of the December 2024 incident, we made the decision to pay a ransom because we believed it to be in the best interest of our customers and the students and communities we serve.  

“It was a difficult decision, and one which our leadership team did not make lightly. But we thought it was the best option for preventing the data from being made public, and we felt it was our duty to take that action. As is always the case with these situations, there was a risk that the bad actors would not delete the data they stole, despite assurances and evidence that were provided to us.” 

No Evidence of Identity Theft (Yet) 

As of now, PowerSchool reports that there is no confirmed evidence of identity theft linked directly to the breach. However, security experts warn that stolen personal information, especially that of minors,  may not surface immediately but could be used in fraud schemes for years. 

Affected individuals are urged to remain vigilant, monitor financial accounts, and be wary of any suspicious communications. PowerSchool emphasized that it will never ask for personal information by phone or email. 

To Pay or Not to Pay 

Ngoc Bui, Cybersecurity Expert at Menlo Security, said while paying ransoms might incentivize threat actors, the reality is that not paying a ransom could be more damaging, particularly for entities involved in critical infrastructure. “The disruption from ransomware can be disastrous, and organizations of all sizes must prioritize protecting both operations and stakeholders. Organizations that suffer a ransomware attack should also use it as a learning opportunity to fine-tune their security measures and ensure they are using actionable intelligence to do so.” 

The brutal truth we must face is that attackers know that if an organization has succumbed to ransomware attack and paid a ransom, it is more likely to pay again to keep a data breach from becoming public, added Gareth Lindahl-Wise, Chief Information Security Officer at Ontinue. “As defenses against ransomware locking devices and data improve, I expect that we may see the predominate revenue stream from the malware reverting to data theft/extortion.” 

“When faced with a ransomware attack, organizations are faced with a difficult decision – whether or not a ransom should be paid,” said Darren Guccione, CEO and Co-Founder at Keeper Security. “Paying a ransom to release their data may seem like the simplest solution, however, it is often illegal and only fuels the explosive growth of this criminal activity. Also, in this instance and many other cases, paying a ransom doesn’t guarantee the cybercriminal’s illicit activities will end.  Cybercriminals often receive payment and subsequently leverage the stolen files to further monetize their value.” 

Generally, a payment absent proper responsive cybersecurity protection increases the probability of a future attack, as cybercriminals now know they will pay the ransom, Guccione added. 

No Guarantee of Safety 

This situation with PowerSchool is yet another unfortunate reminder that paying a ransom does not guarantee safety, it only perpetuates a cycle of criminal leverage and broken promises, added Heath Renfrow, CISO and Co-founder at Fenix24. “While I understand the emotional and operational pressure that leads organizations to pay, the PowerSchool case demonstrates why this route is fraught with long-term consequences.” 

Renfrow said he has seen multiple examples where paying the ransom resulted in either: 

  • Data being leaked anyway, sometimes months later, as extortion groups double-dip or sell the data despite prior agreements, 
  • A return visit from the same threat actor, who now knows the organization is willing to pay, 
  • Or the emergence of third-party victimization, where clients, partners, or students — in this case — are individually targeted. 

“Paying may provide a short-term illusion of control, but it undermines long-term recovery and resilience. The FBI’s advice to avoid paying ransoms exists for good reason, there is no enforceable contract in cybercrime, only hope and high risk,” said Renfrew. “Instead, the better path is investing in immutable backups, hardening identity infrastructure, and accelerating restoration timelines so organizations don’t have to choose between business survival and ethics. The PowerSchool fallout should drive home the message: trusting cybercriminals is a losing bet.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}