Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
District discloses PowerSchool cybersecurity breach; vendor reports data deletion after ransom payment
Summary
Administrators told the board the district received notice of a PowerSchool data breach. PowerSchool notified customers that a malicious actor accessed student information and that the company paid a ransom and stated the actor deleted the stolen data without further dissemination.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The John Stark Regional School District informed the school board that PowerSchool — the district’s student information system — experienced a cybersecurity breach.
District staff said the breach notification arrived on Jan. 7. According to the district’s summary of the vendor communication, PowerSchool characterized the attack as financially motivated and disclosed it had paid an amount to prevent public release of stolen data. The district reported PowerSchool’s statement that it believes the malicious actor deleted the stolen data and that there has been no further dissemination.
PowerSchool stores attendance, grades, schedules, report cards, contact information and other student records. District staff said PowerSchool is used widely statewide and nationally and that they are coordinating with the vendor, the district’s cyber‑insurance provider and other partners to manage the situation. Officials said they will provide updates to the school board, teachers, parents and guardians as more information becomes available.
Ending: District leaders said they will continue to monitor the incident and provide updates as vendor and investigative information develops; no evidence of public dissemination was reported by PowerSchool according to the vendor notice summarized to the board.

