Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

McPherson superintendent: PowerSchool breach may have exposed directory data; district awaiting vendor list

2628042 · January 13, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Superintendent Dr. Gibson told the McPherson USD 418 board that PowerSchool experienced a multi‑day compromise over the holidays. The district does not yet know whether sensitive identifiers for McPherson students or staff were accessed; PowerSchool will notify affected individuals and has indicated credit‑monitoring support for those impacted.

Superintendent Dr. Gibson told the McPherson USD 418 Board of Education that the student information system PowerSchool was compromised for a roughly three‑day window around Dec. 22 and that the district is waiting for a vendor report to learn the extent of local impact.

Why it matters: PowerSchool holds directory and student records for many K‑12 districts. If the vendor's breach included sensitive identifiers for McPherson students or staff, affected people may need notification and identity protections. The district has alerted families and staff and said it will relay further information once it receives specifics from PowerSchool.

Dr. Gibson said the company’s investigators described how attackers used credentials tied to a maintenance‑level user account to run code across PowerSchool systems. That code collected data during the three‑day window, he said. "Much of the same information that can be publicly found anywhere" was collected in many accounts, he said, adding that some customers nationwide also had records containing Social Security or other sensitive identifiers accessed. "We do not know for McPherson yet whether we were a system that had that occur," Dr. Gibson said.

The superintendent said PowerSchool gave districts a notification window of roughly Jan. 17–24 to provide lists of accounts impacted. He told the board PowerSchool indicated it would notify affected individuals directly and that, for those impacted, the vendor has offered to pay for credit monitoring. "They would provide coverage for me to monitor whether my information is being used outside of the way that it should be used," he said.

Dr. Gibson said the district has already communicated to staff, students and families that the breach occurred and that the district will share additional, specific guidance once PowerSchool provides its report. He added that district passwords and logins are encrypted and, to his understanding, were not collected; nonetheless, the district may prompt users to reset passwords as an abundance‑of‑caution measure.

Board members asked whether the district’s insurance would cover cyber‑incidents; Dr. Gibson said he would follow up with the insurance broker and report back to the board.

The superintendent emphasized that the compromise began outside the McPherson system—affecting PowerSchool centrally—and that the district will rely on PowerSchool’s list to determine who was impacted locally. He closed by saying the board and public will be informed as soon as the vendor provides the detailed report.