PowerSchool Data Breach: What Students, Parents, and Educators Need to Know

PowerSchool, the company behind the student information systems many K-12 schools use to manage grades, enrollment, and contact records, says it discovered a cybersecurity incident on December 28, 2024. According to the notice, an unauthorized party exfiltrated personal information from PowerSchool’s Student Information System (SIS) environments by going through PowerSource, one of the company’s customer support portals. In plain terms, someone got into a support system connected to the SIS and pulled out data that belonged to students, parents, and school staff.

Because PowerSchool’s SIS is used by school districts around the country, the letter notes that the exact information involved differs by individual depending on what each school district had stored. The notice was sent to the parent or guardian of a named student, or directly to an educator, whose record was part of the affected data. If you received this letter, it means PowerSchool has identified that specific person’s information as part of the incident, though the company frames some details, such as whether a Social Security number or medical alert information was included, on a person-by-person basis.

What kind of information could be in your child’s or your own record?
  • Full name
  • Contact information (such as address, phone, or email)
  • Date of birth
  • Social Security number
  • Limited medical alert information
  • Other related information stored in the school’s SIS record

PowerSchool is offering two years of free identity protection through Experian IdentityWorks to every affected student and educator, and adult students and educators also qualify for two years of complimentary credit monitoring. The version of the letter reviewed here uses placeholder fields for the actual enrollment link, activation code, and deadline, so those specific details will appear filled in on the letter sent directly to you — check your copy closely, since the code will stop working after the stated cutoff date.

Steps worth taking if your family’s information was part of this
  • Enroll in the free Experian IdentityWorks protection using the activation code and engagement number from your personal letter before the deadline listed there.
  • If a Social Security number was confirmed as involved — for a child or an adult — consider placing a free credit freeze with Equifax, Experian, and TransUnion, since minors’ SSNs are often targeted precisely because credit files aren’t checked for years.
  • Watch for unexpected mail, such as credit offers or collection notices, addressed to your child, which can be an early sign someone tried to use their SSN.
  • Review any account statements tied to the adult(s) named in the notice for unfamiliar activity.
  • For extra peace of mind, you might also sign up for a service like Aura or LifeLock, which can alert you if a name, SSN, or other personal detail turns up somewhere it shouldn’t.
  • Keep the letter and any enrollment confirmation on file in case you need to reference the incident later when disputing fraudulent activity.

PowerSchool says it has found no evidence so far that this data has been used for identity theft, and it engaged outside cybersecurity experts to investigate the scope of the incident right after it was discovered. The company also reminds recipients that it will never call or email asking for personal or account information — a good reminder given that breach notices like this one are sometimes mimicked by scammers.

Leave a Comment