Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Nashoba officials notify families after PowerSchool account compromise

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Nashoba Regional School District told the school committee it alerted families in early January after a PowerSchool account was accessed; the district says primarily contact fields were exposed and it is working with legal counsel and the vendor’s investigation.

Superintendent Kirk Downing told the Nashoba Regional School committee on Jan. 15 that the district alerted families in early January after receiving notice that hackers had accessed the PowerSchool student information system used for enrollment, attendance and grades.

"We remain extremely concerned about this breach and the initial lack of transparency by PowerSchool," Downing said. He said PowerSchool has promised to share a completed third-party investigation "by the end of next week." The district is continuing to press the vendor for details about which data sets were exposed.

Why it matters: PowerSchool houses records used daily by families and staff; uncertainty about what specific fields were copied or downloaded affects the district’s notification and mitigation options. Downing said the company told them the stolen data "primarily contains contact details such as names and addresses" but that some alert fields — including pickup, accommodation, medical and discipline alerts — could contain identifying information.

Downing also told the committee the district’s standard practice is not to collect Social Security numbers in PowerSchool. "That being said, we did have just a handful of Social Security numbers reaching all the way back to 2006," he said, adding that the district has identified roughly "around the range of 40 individuals" whose Social Security numbers may be present from the system’s early implementation and that the district is notifying those people directly.

District attorneys have been involved since the incident became public and the legal team has contacted PowerSchool on the district’s behalf, Downing said. In response to a committee question, he said the district’s counsel reached out to the vendor promptly after the company’s initial public webinar about the incident.

Questions from committee members centered on what specific fields and records were exposed, whether Social Security numbers were affected and what next steps the vendor would take. Downing said the district will share the vendor’s investigation when it is received and will continue to update families and committee members.

The committee did not take any formal action on the breach during the meeting. The report to the committee came during a workshop focused primarily on the FY26 budget.