More than 70 million students and teachers had their personal data stolen in PowerSchool breach

An open lock with a digital background and a cross and bones indicating a cyberattack
(Image credit: Shutterstock)

More and more details have emerged about the December 28, 2024 cyberattack of the cloud-based educational software solutions company PowerSchool. While the company had disclosed the attack on January 7th, recently the threat actor who breached the company has claimed in the extortion demand that the number of affected students and employees is over 70 million.

As reported by BleepingComputer, the personal data of 62.4 million students and 9.5 million teachers was exposed during the attack when the threat actor used stolen credentials to access the PowerSchool customer support portal. After which, they used a maintenance access tool to download the data from districts’ PowerSIS databases.

PowerSchool reportedly paid a ransom to stop the data from leaking, and the hacker claimed they deleted all of the stolen data. This data ranges per district as the types of info each district stores in the SIS database will vary depending on the policy requirements of their state and district requirements. However, it is expected that less than a quarter of the students who were impacted by the breach had their Social Security numbers exposed. A further review of the data is required though, as both cloud-based and on-premises SIS databases must be examined and that requires districts to share information for analysis.

PowerSchool, which is a cloud-based software for K-12 schools, provides tools that handle enrollment, communication, attendance, learning systems, staff management, grades, finances, analytics and more. The company has offered two years of free identity theft protection and credit monitoring services for all the students and district employees who were affected by the breach. They will also send data breach notifications to the State Attorney General’s offices of each affected school district on behalf of customers, though a timeline as to when that will happen is unclear.

The company has also promised to release an incident report based on CrowdStrike's investigations from January 17th but that has also not yet been made available; PowerSchool says that CrowdStrike is still working on finalizing a forensic report that can be made available to customers. In the meantime, there is a dedicated public website that those impacted can monitor for additional information and an update on the customer-only FAQ states that customers can receive a confidential CrowdStrike fact sheet on what is currently known.

What to do now

A woman looking at a smartphone while using a laptop

(Image credit: Shutterstock)

First, if you've received an email or notice from your school district, it should have some information about whether or not your data was affected and how to proceed. If you have been affected, follow the steps and details in the note about signing up for the identity theft protection and credit monitoring services offered by PowerSchool.

If you have questions, there should be details about how to contact your district in the email or notice or you can visit PowerSchool's SIS incident page here. If you want to make sure you and your family are already protected, you can check out our list of best identity theft protection services, which we tested using our own accounts – and includes a Best for families option.

More from Tom's Guide

Amber Bouman
Senior Editor Security

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps. 

Read more
children in school on their laptops with teacher in front of class
I'm a security editor and after the massive 70 million PowerSchool data breach — I started asking questions about how it affects my kids
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Screen graphic showing data breach warning
5 worst data breaches of 2024 — including the mother of all breaches
An open lock depicting a data breach
The top 10 data breaches of 2024
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
Globe Life insurance company logo on a cell phone in front of a monitor display the About page for the company. Shadowy hand holds the phone.
850,000 people exposed in massive insurance data breach — full names, dates of birth and SSNs
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Lewis Hamilton of Great Britain and Scuderia Ferrari looks on during Sprint Qualifying ahead of the F1 Grand Prix of China at Shanghai International Circuit in Shanghai, China, on March 21, 2025. (Photo by Song Haiyuan/Paddocker/NurPhoto via Getty Images)
How to watch Chinese Grand Prix 2025 online – stream F1 without cable, qualifying highlights