Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Breach topic
No spam. Unsubscribe anytime.
Palatine CCSD 15 says limited PowerSchool customer‑support breach was contained; no social‑security numbers accessed
Summary
District IT staff told the board a December compromise of a PowerSchool third‑party support account exposed limited student and staff records. PowerSchool has contained the incident and the district is monitoring; officials said no Social Security numbers, photos or parent emails were accessed.
Get email alerts on the Data Breach topic
No spam. Unsubscribe anytime.
Palatine CCSD 15 officials told the board at its January meeting that PowerSchool notified the district of a data breach involving a third‑party technical‑support account tied to the vendor's customer‑support portal.
"The breach occurred between December 19th and 23rd and was quickly contained," said the district presenter during the meeting. The district said a limited set of student and staff information was accessed; it said no student photos, parent names or parent emails were accessed and that the district does not store student Social Security numbers in its systems.
Administrators said PowerSchool contained the incident, hardened access to the customer‑support portal and is monitoring for any reuse of exfiltrated data. The district said PowerSchool's additional measures include enhanced monitoring and security changes to the portal. The presenter said PowerSchool has been transparent and is working with the district to mitigate risk.
District technology staff described internal protections the district maintains: Google single sign‑on for internal users, two‑factor authentication where possible, and continuous log monitoring to detect anomalous access. The presenter credited district staff who worked on the response, naming Steve Manka and Gorman Christian as members of the IT team handling mitigation and monitoring.
The district said it is proceeding cautiously, coordinating with PowerSchool and continuing internal security reviews. Officials said they will notify affected parties as required and continue to monitor the situation and the dark web for any dissemination of stolen data.
Ending
The district emphasized that the affected PowerSchool support account was a vendor‑side credential compromise and that district systems protected sensitive identifiers such as Social Security numbers and student photos.

