Student, teacher data compromised in PowerSchool hack

GONZALES — Several local school districts are believed to have been affected by a hack involving PowerSchool, an educational software platform that stores student grades, records, and personal information.

Ascension Parish Schools sent a letter to parents on Wednesday informing them of the cybersecurity incident. The district stated PowerSchool became aware of the breach on December 28.

“We are awaiting more information; however, want to ensure our community is aware that this is an ongoing situation that is being investigated at this time,” the district said.

Livingston Parish Schools also notified parents a few hours later: “We are awaiting more information on confirmation of how this cyber-attack may have impacted Livingston Parish Public Schools directly.”

PowerSchool confirmed it suffered a cybersecurity breach that compromised the personal information of students and teachers from districts using its PowerSchool SIS platform. PowerSchool is a cloud-based software provider for K-12 schools and districts, serving over 60 million students and more than 18,000 customers worldwide.

“The unauthorized party was able to use a compromised credential  to access one of our community-focused customer support portals called PowerSource,” PowerSchool said in a statement.

According to PowerSchool, the stolen data primarily includes contact details such as names and addresses. However, it may also contain Social Security numbers, personally identifiable information, medical records, and grades. The company added: “The incident is contained and we do not anticipate the data being shared or made public.”

APPS stated that it is awaiting further communication from PowerSchool to determine what specific information may have been accessed.

“While we are unaware of and do not expect any actual or attempted misuse of personal information or any financial harm to impacted individuals as a result of this incident, PowerSchool will be providing credit monitoring to affected adults and identity protection services to affected minors in accordance with regulatory and contractual obligations,” the company said.

Many other school districts in the state also use PowerSchool, though it remains unclear how many have been affected. UWK is reaching out to additional local districts for more information.

Dear Ascension Families,

Late yesterday, PowerSchool notified our Information Technology (IT) Department that Ascension Public Schools (APSB) was among PowerSchool’s many worldwide clients whose data may have been accessed during a cybersecurity incident. They became aware of the incident on December 28, 2024.

We are awaiting more information; however, want to ensure our community is aware that this is an ongoing situation that is being investigated at this time.

WHAT HAPPENED?
According to PowerSchool, someone used a compromised credential to access data stored in their Student Information System (SIS). When PowerSchool became aware of the incident, they notified law enforcement, locked down the system, and engaged the services of a professional advisor with experience in negotiating with threat actors. PowerSchool states that they have received “reasonable assurances from the threat actor that the data has been deleted and that no additional copies exist.”

WHAT DATA COULD HAVE BEEN ACCESSED?
Initial information from PowerSchool indicates that Personally Identifiable Information (PII) for staff and students may have been accessed for some districts. This may include contact information, including names and addresses, social security numbers, dates of birth, some life-safety health and grade information for current and former students, and parent/guardian names and addresses. 

Once PowerSchool lets us know what information from APSB may have been accessed, we will work with them to ensure that any impacted individuals are notified and that appropriate next steps are taken. 

WHAT HAPPENS NEXT?
PowerSchool has stated, “While we are unaware of and do not expect any actual or attempted misuse of personal information or any financial harm to impacted individuals as a result of this incident, PowerSchool will be providing credit monitoring to affected adults and identity protection services to affected minors in accordance with regulatory and contractual obligations.”

While PowerSchool is responsible for this incident and its impact, out of an abundance of caution, APSB has notified its cybersecurity contractor to direct our further response. 

IS IT SAFE TO CONTINUE USING MY POWERSCHOOL ACCOUNT?
Yes, it is safe to continue using your PowerSchool account. According to PowerSchool, “the incident is contained and we have no evidence of malware or continued unauthorized activity in the PowerSchool environment. PowerSchool is not experiencing any operational disruption, nor expects to experience any operation disruption and continues to provide services as normal to our customers.”

WHO CAN I CONTACT WITH QUESTIONS AND CONCERNS? 
We anticipate PowerSchool will be providing impacted individuals with resources for additional information, which we will share at that time.

We remain dedicated to safeguarding the data of our students, staff, and parents and will continue to provide transparent updates regarding this incident.Respectfully,

Dr. Edith M. Walker
Superintendent
Ascension Public Schools 

This is a developing story. As soon as more details are provided, the story will be updated. Check back for new information.

Download the Unfiltered with Kiran app from the Apple App Store and Google Play to stay updated on the latest news across the Capital area. 

Leave a Reply

Your email address will not be published. Required fields are marked *

Interested in advertising with us?

We’d love to have you on the team! Drop us a line and we’ll be happy to follow up. 

Categories

Let's Connect

Follow along on your favorite social media platform and get the latest updates directly in your feed!

Submit a Tip

Have a tip on a story? Send it directly to our team using the form below!
Search