Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Henniker schools say PowerSchool breach exposed student and staff tables; district reviewing scope
Summary
PowerSchool detected unauthorized access to its support portal on Dec. 28, 2024 and an unauthorized user downloaded data tables from multiple clients, SAU 24 technology staff told the Henniker School Board on Jan. 14.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
PowerSchool detected unauthorized access to its internal customer support portal on Dec. 28, 2024 and an unauthorized individual downloaded data tables belonging to multiple PowerSchool clients, SAU 24 technology staff told the Henniker School Board on Jan. 14. "PowerSchool has stated that they believe the unauthorized user has since deleted the stolen data without further replication or dissemination," Lee said during the board meeting.
Why it matters: PowerSchool is the student information system that stores enrollment records, gradebook entries and other school data for districts nationwide. SAU 24 staff said the vendor-supplied list of affected fields is being matched to the district’s local records so officials can determine which students and employees — if any — were affected and what types of data were exposed.
What the district said it knows: Lee told the board that threat actors used stolen credentials to access PowerSchool’s internal support portal. PowerSchool engaged Cyber Steward, a third‑party extortion response service, and disclosed that the attack was financially motivated and that it paid a sum to prevent public release. The district has submitted a claim to its cyber insurer and is coordinating with PowerSchool’s privacy counsel. "We are following our District's cybersecurity and incident response plan to ensure an appropriate and effective response," Lee said.
Possible data elements and scope: District staff said there is no PowerSchool product in SAU 24 that holds financial account data, but that the exposed fields could include first and last names, dates of birth and — historically, if entered — Social Security numbers. Lee said SAU 24 is ‘‘going through every district’s fields’’ with PowerSchool to determine what, if anything, was present in the affected fields for Henniker.
Next steps and notifications: Lee said PowerSchool will issue notifications to affected parties and that the district expects PowerSchool-led notifications within 30 days. The SAU’s IT team is conducting a district-level data analysis and will provide updates as the analysis completes. Law enforcement has been notified and the district said it is working with its cyber insurance provider and PowerSchool on mitigation and communications.
Board response and context: Board members pressed for specifics about what fields were accessed and whether records included sensitive identifiers. District staff reiterated they would not release personally identifiable details publicly as they complete the field-by-field review, but pledged to inform parents and staff when the vendor’s notification is issued.
What the district asked the community to do: SAU 24 said it will post an FAQ link from PowerSchool and send a follow-up communication to families and staff when the vendor’s notice is available. The district also said it will continue to work with its insurer and outside counsel on next steps.
Ending note: The district emphasized it is following its incident-response plan and coordinating with external partners; officials said they will share definitive findings when the vendor and the SAU complete their analyses and notifications.

