Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the It Security topic

No spam. Unsubscribe anytime.

Enid IT director: PowerSchool breach traced to third‑party product; district systems not accessed

2173058 · January 22, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Enid Public Schools' IT director told the board that a global PowerSchool breach originated through a third‑party product (PowerSource). PowerSchool will offer complimentary identity protection; the district says its internal network was not breached.

Enid Public Schools IT Director Jeff Herbel told the school board that a widely reported PowerSchool breach originated through a third‑party product and that the district’s internal systems were not accessed.

PowerSchool "was made aware of their breach on December 28th," Herbel said, and school districts were notified in early January. He described the vector as a third‑party service, PowerSource, which had a service account exposed on the dark web: "there was a service account that was out on the dark web and someone got it and tested it and it worked. So they logged in. They were able to access PowerSchool through PowerSource."

Herbel said the district has been notified that its data may have been among those PowerSchool reported as accessed, but Enid Public Schools has not identified specific records that were viewed. "We've been notified that our data was breached. However, we have not been able to determine any data that was accessed at that time," he said. PowerSchool has told districts it will provide "complimentary identity protection to all students and educators whose information was, accessed," Herbel said.

Herbel emphasized that the district’s own network and security were not compromised: "our systems were not accessed. The Enid Public Schools' internal, network was not accessed. This was a third party access through an external resource and did not breach any of our security measures in house." He said the district required password changes and relies on multi‑factor authentication for staff accounts, noting that "If they'd had a multi factor on that account, it wouldn't have gotten hacked."

Board members asked only clarifying questions after the update. The district said it will continue to work with PowerSchool to determine whether specific student or staff records were accessed and that PowerSchool will notify affected individuals directly.

The investigation remained open at the time of the report; officials said they expected further information and notifications in the coming weeks.