Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Breach topic
No spam. Unsubscribe anytime.
Campbell County schools: PowerSchool breach exported basic student and staff records, district says
Summary
District staff told trustees a December security breach of PowerSchool exported student and teacher tables containing names, birthdates, contact details and certain alert fields; social‑security numbers were not present in the student table and four former/current staff had SSNs in the teacher table, district officials said.
Get email alerts on the Data Breach topic
No spam. Unsubscribe anytime.
Campbell County School District officials told trustees that PowerSchool, the vendor that hosts the district's student information system, experienced a security breach that exported basic student and staff records.
District Director of Educational Technology (Mister Knox) said the district received notice from PowerSchool on Jan. 7 that someone had used credentials on or about Dec. 22 to access PowerSchool support systems and from there exported tables that included the district's student and teacher records. “Unfortunately, I'm not here with positive news, but I do have some good news to go with it,” Knox told the board.
The district said it downloaded and reviewed the exported files. The student table covers more than 39,000 students and the teacher/staff table covers about 8,800 records, the district said. Knox said social‑security numbers were not present in the student table; four staff records in the teacher table included social‑security numbers. Other protected fields such as passwords were encrypted, the district reported.
Knox described several categories of fields that were present in the exported student records beyond names and basic demographics, including “medical alerts” (used to flag basic needs such as wearing glasses or asthma), family alerts that flag pickup restrictions, and disciplinary alerts used to note probation/parole status where parents have given permission to share that information with school staff. Knox emphasized that the medical alerts “does not, and I get to repeat, does not contain specific medical information,” and said detailed medical records are stored in a separate system.
The district said it notified the Wyoming Department of Education and Wyoming Homeland Security, attended two vendor briefings hosted by PowerSchool, documented the vendor sessions and is maintaining a record of its review. Knox said the district also independently confirmed the export and has been trying to contact the four staff members whose records contained social‑security numbers; three have been reached so far and one has not responded to repeated outreach.
Asked what PowerSchool is doing to prevent a recurrence, Knox told trustees PowerSchool has conducted an internal audit, is tightening access controls and has hired an external company the district identified as “Clouds” to validate the vendor's fixes. Knox added the district has limited its ongoing connections to PowerSchool temporarily and will re‑enable links only with additional safeguards in place.
Superintendent Dr. Ayers thanked district staff for their work and apologized to anyone impacted. He said the district's insurer and cyber team are being engaged and that further notification information may follow.
The district said it issued a press release to the community and staff last week and had not, as of the board meeting, received reports from parents or staff raising new concerns. Knox said the district is evaluating whether additional identity‑protection services will be offered to affected staff if the vendor's remedies prove insufficient.
District officials asked that community members with concerns contact the district directly for records or clarifications; officials said they will continue coordinating with state officials and PowerSchool as investigations and remediation proceed.
