Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Weare SAU notifies families after PowerSchool data breach that affected vendor portal; district says no operational disruption

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

SAU 24 notified families that PowerSchool reported an unauthorized access to its PowerSource portal affecting hosted and non-hosted clients; the district says school operations were not disrupted and is offering credit monitoring per vendor guidance.

SAU 24 informed the school board and public that PowerSchool — the district’s student information system vendor — disclosed a cybersecurity incident in which a malicious actor obtained access to data through PowerSchool’s PowerSource portal.

District technology staff said the incident was isolated to the vendor’s portal and did not cause an operational outage: the district continues normal operations and its cloud‑hosted PowerSchool instance remained live. PowerSchool notified customers that both hosted and self‑hosted clients were impacted in the incident and that the company had been targeted in a financially motivated intrusion. PowerSchool reported it had paid a sum to the attacker to avert public release of the stolen data and said it believed the malicious actor subsequently deleted the stolen data; the district said law enforcement and data‑protection regulators have been notified.

District representatives said affected adults would be offered free credit‑monitoring services and that identity‑protection services would be provided for minors in accordance with regulatory and contractual obligations. SAU staff said they had filed a claim with the district’s cyber insurance provider and were coordinating directly with PowerSchool and other partners. The district also said it had communicated initial notices to teachers and guardians and would provide further updates as new information is available.

Board members and administrators said the attack was part of a wider pattern of large, targetted incidents of national significance and that the company is a widely used provider: PowerSchool serves more than one third of U.S. school districts. The board asked the administration to continue following the district’s incident‑response plan and to share timely updates with the community.