Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy Power School Breach topic
No spam. Unsubscribe anytime.
Lorain City Schools notify families after PowerSchool data breach affecting student and staff records
Summary
District officials told the school board that a December breach of vendor PowerSchool exposed student and some staff data; the district has begun targeted notifications and is awaiting vendor-provided credit monitoring and support.
Get email alerts on the Data Privacy Power School Breach topic
No spam. Unsubscribe anytime.
Lorain City Schools officials told the school board on Jan. 13 that a December breach of the student information system vendor PowerSchool exposed large amounts of student and some staff data, and the district has begun targeted notifications and ongoing monitoring while awaiting support from PowerSchool.
District technology and communications leaders said the intrusion began Dec. 19, 2024, and that the intruder accessed servers and began exfiltrating data Dec. 22. The attacker contacted PowerSchool Dec. 28 demanding payment, according to the district. Pat Coleman, the district—s executive director of educational technology and student services, said the incident appears to be part of a global attack affecting many districts and that "a small group of social security numbers of staff members" and a larger number of student social security numbers were among the data accessed.
The district convened a small response team and began notifications the week of Jan. 8. Krista Lachich, director of communications and community relations, described the notification timeline: Jan. 8 initial staff alert; Jan. 9 targeted calls and emails to the small group of staff whose social security numbers were compromised; Jan. 10 calls and follow-up emails to families whose currently enrolled students were affected. Lachich said the district has sent step-by-step password-reset guidance and will provide ongoing updates as PowerSchool and its contractors finalize remediation and support plans.
Coleman said PowerSchool reported the incident affected as many as 18,000 districts and roughly 60 million students in approximately 100 countries. He described the vendor—s response steps: PowerSchool engaged a negotiator, Cyber Steward, and a forensic firm, CrowdStrike. PowerSchool has told the district that through negotiation and containment efforts the copied data have been deleted; district officials said they are relying on PowerSchool—s cooperation and forensic reports while continuing their own review.
District officials said they have identified the currently enrolled staff and students whose records were compromised and have contacted them directly. They said they have not yet identified all previously enrolled students who may have been affected and are awaiting further data and support from PowerSchool to complete that outreach.
Board members asked whether the district had located all names and Lachich responded that currently enrolled staff and students were identified but that previously enrolled students remain under investigation. The district said it is awaiting PowerSchool—s timeline for credit-monitoring services and other supports PowerSchool has promised.
The district urged families with additional questions to contact the communications office; officials described the situation as a developing matter and said they will post updates as more information becomes available.

